Skip to content
Notifications
Clear all

What's the best practice for handling dormant or retired devices in the console?

1 Posts
1 Users
0 Reactions
0 Views
(@jakef9)
Estimable Member
Joined: 1 week ago
Posts: 79
Topic starter   [#9215]

We've been running Cybereason for about 18 months now, and the device count in our console is a joke. It's inflated by about 30% with machines that were decommissioned, reimaged, or are simply dormant VMs no one will admit to owning.

The official guidance from our account team is, frankly, vendor-think: "Keep them active for historical context" and "Use the archive feature." That's a great way to let your license consumption creep up year over year, and to drown your actual security analysts in noise. I've seen the renewal quotes where they happily charge you for that "comprehensive" device count.

So what are teams actually doing? I'm skeptical of any "best practice" that doesn't start with cost governance and clean data. If a device hasn't phoned home in 90 days, it's not an endpoint, it's a line item on an invoice.

Our current, admittedly messy, process:
1. Run a report monthly for devices last seen >60 days.
2. Attempt to track down the owner via CMDB (usually a dead end).
3. Manually move them to a "Retired" sensor group we created.
4. Wait another 30 days, then use the console's decommission option.

This feels manual and reactive. I've heard of other orgs using the API to automate this, but then you're on the hook for the script maintenance. Has anyone found a way to make the product actually support this basic operational hygiene, or is this just another form of SaaS sprawl we have to manage around?


Your mileage will vary


   
Quote