For the complete documentation index, see llms.txt. This page is also available as Markdown.

Endpoints - Device List Page

Overview

The Device List page is the fleet view for the Nightfall endpoint agent. It shows every macOS and Windows device that has checked in to your Nightfall tenant, along with the agent state, MDM profile state, browser-extension state, and any active policy exceptions for each device.

Use this page to:

  • Confirm a fresh rollout reached every device you targeted.

  • Find devices that need attention (agent in error, macOS permissions missing, MDM profile out of date, extension not installed).

  • Confirm the Nightfall browser extension is loaded and enabled on the browsers your users actually run.

  • Triage a single device by opening the side panel for full status detail.

  • Remove a device that is decommissioned or no longer in scope.

Where to find it. Configuration → Integrations → Mac or Windows Endpoints.


2. Page summary

At the top of the page you will see:

  • Device Information heading, with the line "The Nightfall endpoint agent has been deployed to the following devices. After installation, the agent automatically receives updates to ensure it stays secure and up to date."

  • A 60-day cleanup notice: "Devices that have been disconnected for more than 60 days are automatically removed from this list." Once a device is removed, the only way to bring it back is for that device to reconnect and check in.

  • Total device count. Shown immediately above the table as N devices (or 1 device). This number reflects all filters and search applied to the page.

  • Search. A search box, placeholder "Search devices". When any filter is active, the placeholder changes to "Search filtered devices". Search matches against the device ID prefix.

  • Export to CSV. Opens an "Export as CSV" modal. The full export is delivered by email to your signed-in address. The modal reads "A download link for your report will be sent to your-email-address." The primary action is "Send Download Link."


3. MDM Profile Update Required banner (macOS only)

When a new macOS agent version ships with new security features that require an updated MDM profile, an orange button labeled MDM Profile Update Required (Mac Only) appears in the filter row.

Clicking the button opens the MDM Profile Update Required modal:

  • Headline: "Profile update required for devices."

  • Body: "Agent version X.Y.Z includes new security features that require an updated MDM profile. Devices will continue to function but may have limited capabilities until the profile is updated."

  • Devices Requiring Update count, sourced from the agent's profile-version handshake against the latest published profile.

  • What's New in This Profile lists the capabilities the new profile enables.

  • How to Update lists four steps: download the profile, upload it to your MDM (Kandji, Jamf, Intune, and so on), push it to affected devices, and let the agent re-apply on next check-in.

  • Primary action: Download Updated Profile.

If you do not see this banner, your fleet's profiles are at the expected version and no action is needed.


4. Quick filters

Four single-click chip filters sit in the filter row. Click a chip to apply, click again to clear. Clicking a chip replaces any other filters you have set.

Chip

What it matches

Needs Attention

Any of: connection status is Error; any required macOS permission is missing (Full Disk Access, Screen Recording, or Accessibility); MDM profile is Not Installed; the Nightfall extension is not installed on Chrome, Edge, Firefox, Safari, Arc, or Brave.

Stale Devices

Connection status is Disconnected or Offline.

Update Available

Agent is on a version older than the latest published version for that OS.

No MDM Profiles

MDM profile status is Not Installed or Out of Date. (macOS only.)


5. Add Filters

The Add Filters dropdown gives you the full filter set. Filters compose with AND across types.

Filter

Values

Notes

OS

macOS, Windows

Agent Status

Online, Disconnected, Error, Offline

Agent Version

Up to Date, Out of Date

Compared against the latest published version per OS.

Stealth Mode

Active, Inactive

Profile Status

Up to Date, Out of Date, Not Installed

macOS only. Hidden on Windows.

Missing Permissions

Full Disk Access, Screen Recording, Accessibility

macOS only. Hidden on Windows. Multi-select.

Agent Errors

User Agent Not Connected, Driver Missing, Driver Not Loaded, User Data Missing, Browser Extension Not Connected, ES Client Unauthorized

Multi-select.

Browser Extensions

Chrome, Edge, Firefox, Safari, Arc, Brave, each with "Installed" or "Not Installed"

Multi-select. Pairs of browser + installed state.

Filter selections are stored in the URL so you can bookmark or share a filtered view.


6. Column reference

Columns appear in this order. Click the header tooltip (the small info icon) to see the in-product description.

6.1 OS

  • Tooltip: "Operating system reported by the device at last check-in."

  • Renders the OS logo (Apple or Windows). Hover the cell to see the OS version reported by the device.

6.2 Device Name & ID

  • Tooltip: "Hostname and unique device identifier."

  • Two-line cell: device hostname (bold) above the unique device ID. Hover to see both spelled out. This column is sortable.

6.3 User Email

  • Tooltip: "Primary user signed in to this device (from MDM or directory sync)."

  • The user-account email Nightfall received from your MDM or directory sync. Shows when no user is associated.

6.4 Agent Status

  • Tooltip: "Connection state and last-seen timestamp."

  • Pill badge plus a relative timestamp below it (for example, "3 minutes ago"). Hover the cell to see the absolute timestamp.

Status

Color

Meaning

Online

Green

The agent is heartbeating to Nightfall normally.

Disconnected

Red

The agent has not sent a heartbeat for more than six hours. The device may be powered off, asleep, off-network, or the agent service may be stopped.

Error

Red

The agent is reachable but has reported one or more runtime errors (see the Permissions / MDM column for the specific error codes).

Missing full disk access

Amber

macOS-only. The agent is running but cannot scan files because Full Disk Access has not been granted in System Settings.

Starting

Gray

The agent is in the middle of starting up. This state is brief and usually resolves on the next check-in.

Offline

Gray

Reserved status. Treat the same as Disconnected for action.

NA

Gray

The status was not reported. Usually means an older agent build that pre-dates the current status fields.

6.5 Agent Version

  • Tooltip: "The agent updates automatically - no manual action required. If a device hasn't been online recently, the version shown here may be outdated."

  • The version string the agent last reported. If the version is older than the latest published version for that OS, an amber warning triangle appears next to it. Hover the triangle to see "Outdated version. Latest: X.Y.Z."

6.6 Permissions / MDM

  • Tooltip: "macOS system permissions and agent runtime errors detected on this device."

  • Two states:

    • All granted (green check). No missing macOS permissions and no agent runtime errors. Hovering reveals what was checked: on macOS, the three permissions (Full Disk Access, Screen Recording, Accessibility) plus "No agent errors"; on Windows, "No issues detected" plus "No agent errors."

    • N issue(s) (amber alert triangle). One or more missing permissions, agent errors, or both. Hovering reveals each item.

For each missing permission, the tooltip shows:

The three macOS permissions tracked here are:

  • Full Disk Access. Required to scan files outside the user's home directory.

  • Screen Recording. Required for screen-based exfiltration detection.

  • Accessibility. Required for thick-app and clipboard monitoring.

For each agent error, the tooltip shows "Agent error: name." The six error codes are:

  • User Agent Not Connected. The user-space agent component is not running or cannot reach the system extension.

  • Driver Missing. The Nightfall kernel or system driver is not present on the device.

  • Driver Not Loaded. The driver is installed but did not load. Usually a reboot or an MDM payload approval is needed.

  • User Data Missing. The agent could not resolve the logged-in user's identity.

  • Browser Extension Not Connected. The agent expects a browser extension that is not currently reporting in.

  • ES Client Unauthorized. macOS denied the Endpoint Security client. Reapprove the system extension through your MDM.

Profile status sub-line (macOS). When MDM profile state is available, it appears under the permissions summary as one of: Up to Date, Out of Date, or Not Installed. This pairs with the MDM Profile Update Required banner described in 3 above.

6.7 Browser Extensions

  • Tooltip: "Browsers with the Nightfall extension installed and any attached profiles."

  • Shows up to three browser icons inline, each with a status dot. A +N chip appears when more than three browsers report state.

Dot color

State

Green

Extension installed and connected.

Amber

Browser installed but the Nightfall extension is not installed yet.

Red

Error reading extension state.

Gray

Browser not installed on this device, or status unknown.

Hover the cell for the full list. Each row pairs the browser, the status text, and the status dot.

Supported browsers. Chrome, Edge, Firefox, Safari, Arc, Atlas, Brave, Chrome Beta, Comet, Vivaldi. Safari and Atlas were added in agent v1.2.13.x on macOS and v1.4.35.x on Windows.

6.8 Stealth

  • Tooltip: "Whether the agent runs without end-user UI."

  • Green On badge: the agent is running in stealth mode (no tray icon, no notifications).

  • Gray Off badge: the agent runs visibly to the end user.

  • Not Available: the device runs an older agent build that does not report stealth state.

6.9 Policy Exceptions

  • Tooltip: "Active policy overrides currently applied to this device."

  • None when zero active exceptions exist.

  • N active (violet) when one or more exceptions are scoped to this device. Click the link to jump to the Policy Exception tab in the side panel.

This column is visible only when policy exceptions are enabled on your tenant.

6.10 Delete

  • A trash icon at the end of each row. Click to open the single-device delete confirmation. See 7.


7. Sorting, selection, and bulk actions

  • Sort. Click the Device Name & ID column header to toggle ascending or descending sort. This is the only sortable column on this page.

  • Row select. A checkbox in each row. A header checkbox selects every row on the current page. The header checkbox shows a partial-select indicator when some rows on the page are selected.

  • Bulk delete. When at least one row is selected, a red Delete N Device(s) button appears in the filter row. Clicking it opens the bulk delete confirmation.

Single-device delete confirmation

  • Are you sure you want to remove this device?

  • Removing this device will take it off the monitored list. If the device reconnects to your Nightfall tenant, it will automatically reappear.

  • What happens next?

    • This device will no longer appear in the monitored list.

    • If the device reconnects, it will be added back automatically.

  • This action does not block, disable or uninstall the Nightfall agent from the device.

  • Primary: Remove Device. Secondary: Cancel.

Bulk delete confirmation

  • Are you sure you want to remove these N devices?

  • Removing these devices will take it off the monitored list. If the devices reconnect to your Nightfall tenant, they will automatically reappear.

  • Disclaimer: This action does not block, disable or uninstall the Nightfall agent from the devices.

  • Primary: Remove Devices.

Bulk delete is capped at 100 devices per call. If you need to remove more, do it in batches.


8. Device detail side panel

Click any row to open the side panel. It has three tabs in this order: Summary, Browser Extension, Policy Exception. The Policy Exception tab is visible only when policy exceptions are enabled on your tenant. Navigate between devices on the current page using the arrows at the top of the panel.

8.1 Summary

Nine fields in this order:

  1. Operating System. OS logo plus version.

  2. User Email. Or if not associated.

  3. Agent Status. The same pill described in §6.4.

  4. Last Connection. Relative time since last heartbeat, or if never connected.

  5. Agent Version. Current reported version.

  6. Missing Permissions. None when complete, or the list of missing macOS permissions in amber.

  7. Profile Status. Up to Date, Out of Date, Not Installed, or Unknown.

  8. Stealth Mode. On, Off, or Not Available.

  9. MAC Addresses. Every MAC address the device reports. Hidden if the device reports none.

8.2 Browser Extension

Lists every browser on this device that has the Nightfall extension installed.

For each browser:

  • Browser icon and name.

  • Connected (green dot) or Disconnected (red dot). Disconnected typically means the browser is closed; reopen the browser and the extension reconnects.

  • Per-profile count (for browsers that support profiles, like Chrome). Green dot = every profile has the extension enabled; amber = some profiles do; red = none do.

  • Click the row to expand the per-profile table: Profile name, profile email, Enabled or Disabled state.

If the device has no browser-extension data yet, the tab reads "No browser extension data available." If it has data but no extensions are installed, it reads "No browser extensions detected."

8.3 Policy Exception

Lists every active policy override scoped to this device, with policy name, scope, and expiration. From here you can view or revoke an exception. This tab is available when policy exceptions are enabled on your tenant.


9. What to do when…

Symptom

What to check first

Status is Disconnected.

The device may be off, asleep, or off-network. If it has been disconnected for under six hours, wait. If longer, confirm the device is online and that the Nightfall agent service is running. If the device is decommissioned, delete it from the list.

Status is Error.

Open the side panel, look at the agent error code under Permissions / MDM, and follow the matching action (driver reload, reapprove system extension, restart the agent service).

Status is Missing full disk access (macOS).

Guide the user to System Settings → Privacy & Security → Full Disk Access → enable Nightfall. The agent re-checks within one heartbeat.

N issue(s) with missing permissions.

macOS permissions cannot be force-enabled by the agent itself. Either guide the user through System Settings, or push the permission via your MDM payload.

Profile not installed (macOS).

Use the MDM Profile Update Required banner to download the latest profile and push it via your MDM.

Profile out of date (macOS).

Same path: pull the latest profile and push it to the affected devices. The agent works with the old profile but may lack newer capabilities.

Extension not installed on a supported browser.

Force-install via Google Workspace policy (Chrome) or your MDM's browser-extension payload (Edge, Firefox, Brave, Arc, Atlas, Comet, Vivaldi). Safari is manual install only.

Extension installed but Disconnected in the side panel.

Usually the browser is closed. Reopen the browser; the extension reconnects on launch. If it persists with the browser open, reinstall the extension.

Stealth = Off on a device you expected to be stealth.

Stealth mode is set at agent install time and is not flipped by a config push. Re-deploy the agent with stealth selected to convert.

Agent version is outdated.

No action needed. The agent self-updates on its next check-in. The amber triangle clears automatically.


10. Platform support matrix

Most columns work the same on macOS and Windows. The ones that do not:

Surface

macOS

Windows

OS column

Apple logo

Windows logo

Agent Status: Missing full disk access

Yes

Not applicable

Permissions / MDM column: macOS permissions

Full Disk Access, Screen Recording, Accessibility tracked

Not tracked

Permissions / MDM column: agent errors

All six error codes

All six error codes

Permissions / MDM sub-line: profile status

Yes

Not applicable

Stealth column

Reported (On / Off)

Reported (On / Off)

Browser Extensions: Safari

Yes (added in v1.2.13.x)

Not applicable

Browser Extensions: authoritative install state

Agent reports

Agent uses an on-disk scan to verify the extension is actually loaded (since v1.4.22)

MDM Profile Update Required banner

Yes

Not applicable

Profile Status filter

Yes

Hidden

Missing Permissions filter

Yes

Hidden

The Phase 2 Windows parity for the Device List page shipped in Windows agent v1.4.35.x.


11. Frequently Asked Questions (FAQ)

How long until a device shows up after I install the agent?

On the agent's first successful heartbeat, the device appears. Heartbeats run on a short interval after install, so a device that completes install while online typically appears within a minute.

When does a device flip from Online to Disconnected?

When no heartbeat has been received from the agent for more than six hours. The threshold is set tenant-wide and applies equally to macOS and Windows.

When is a device removed from this list?

After 60 consecutive days disconnected. The agent record is deleted from the page; if that device comes back online and checks in, it reappears with a fresh record.

A user changed Mac. Will the old device still appear?

Yes, until 60 consecutive disconnected days pass. If you want to remove the old device sooner, delete it from this page. The agent on the new Mac will appear once it checks in.

Does deleting a device uninstall the agent?

No. Delete only takes the device off the monitored list. The agent keeps running on the device, and if it heartbeats again, the device reappears. To remove the agent itself, run the uninstall through your MDM or follow the manual uninstall steps.

Why can a removed device come back automatically?

Delete sets the device record to "removed" in the Nightfall backend. The agent on the device does not know about the deletion. On its next heartbeat the backend creates a new record, which causes the device to show up again. If you want a permanent removal, uninstall the agent through your MDM or device management workflow.

How many devices can I delete at once?

Up to 100 per bulk delete. If you have more, run a few batches.

Why does the "Disconnected" filter chip include Offline too?

The "Stale Devices" chip is meant as a one-click view for any device that is not actively reachable. Offline is a reserved status today; selecting Stale Devices covers both states so you do not miss anything when the platform expands.

Why is the Agent Errors filter showing six options but the Permissions / MDM column says "N issues"?

"N issues" counts every missing macOS permission and every active agent error code on that device. The Agent Errors filter only filters on the agent error side; if you need to filter on missing permissions, use the Missing Permissions filter instead.

A device has an error code like "ES Client Unauthorized" and stays in Error after a reboot. What now?

This usually means the system extension or kernel driver was denied at the OS layer. On macOS, that is typically a missing Allow Endpoint Security Client approval in your MDM configuration profile. Push the corrected profile via your MDM. If you do not run macOS through MDM, approve manually in System Settings → Privacy & Security.

The MDM Profile Update Required banner appeared, but the devices I patched still show "Profile out of date."

The agent re-reports profile version on its next heartbeat. If the profile reached the device but the column has not updated, wait one heartbeat cycle. If it still shows out of date after that, confirm in your MDM that the profile is delivered and approved on the affected device.

Why does Stealth show "Not Available" on some devices?

Older agent builds do not report stealth state. Update the agent to the current build; the column populates on the next heartbeat.

I see a browser as "Disconnected" in the side panel even though the extension is installed. Why?

Browser extensions only heartbeat when the browser is open. A closed browser shows as Disconnected. Open the browser and the status returns to Connected within a few seconds.

Why is Safari extension state showing up on some devices but not others?

Safari extension tracking was added in macOS agent v1.2.13.x. Devices on older agent builds will not report Safari state until they update.

Can I force-install the extension from this page?

The Device List page reports state; it does not push the extension. Force-install runs through your browser-management mechanism (Google Workspace policy for Chrome, MDM-delivered policy for Edge, Firefox, Brave, Arc, Atlas, Comet, and Vivaldi). Safari is manual install only.

The Permissions / MDM column shows "All granted" but the user can't paste in Claude. What gives?

"All granted" only confirms macOS system permissions and agent runtime health. If a paste is blocked, the cause is usually a Detection & Response policy match, not a permissions issue. Open the Detection & Response page and filter by that user to find the violation.

Where does the CSV export go?

The "Export to CSV" button generates a CSV reflecting the current filters and search, then emails a download link to the address you are signed in with. The link expires after the standard Nightfall report retention window.

Can I export only the devices I have selected?

The CSV export reflects the current filters and search, not the per-row selection. To export a subset, filter to that subset first, then export.

Why does the column tooltip mention "from MDM or directory sync" for User Email, but my device shows ?

A device shows when Nightfall has not received a user mapping. The two paths that populate this field are: MDM-pushed user assignment in the install payload, and identity-provider sync (Okta, Microsoft Entra ID, Google Workspace). If you have neither configured for that device, the column stays blank.

Why is the Stealth column populated for some devices and not others?

The agent only reports stealth state from v1.2.12.x onward. Devices on older builds will show "Not Available" until they update to the supported version range.

What is the Nightfall Diagnostics tab I sometimes see in the side panel?

That tab is gated to Nightfall support staff. If you see it, it is because your account is impersonating into a support session. There is no customer-facing configuration in it.


12. Field reference

For power users:

Proto field

UI label

Notes

os

OS

MAC_OS, WINDOWS.

device_name

Device Name

Hostname.

device_id

Device ID

Unique device identifier assigned by the agent.

user_email

User Email

From MDM or directory sync.

connection_status

Agent Status

CONNECTED → Online; DISCONNECTED → Disconnected; ERROR → Error; MISSING_FULL_DISK_ACCESS → Missing full disk access; STARTING → Starting; OFFLINE → Offline; unspecified → NA.

last_connection

Last Connection

Used to render the relative time below the status pill.

agent_version

Agent Version

Compared to latest published version per OS to drive the outdated triangle.

os_version

OS Version

Shown on hover over the OS column.

extension_installation_statuses

Browser Extensions

One entry per browser. BROWSER_INSTALLED (browser present, no extension), EXTENSION_INSTALLED (extension present), ERROR, BROWSER_NOT_INSTALLED, UNKNOWN.

BrowserExtensionStatus.extension_connected

Per-browser Connected/Disconnected

True when at least one profile in that browser is heartbeating.

BrowserProfile.name / .email / .enabled

Per-profile row in the side panel

policy_overrides_count

Policy Exceptions

0 → None; >0 → "N active" link.

stealth_mode

Stealth

STEALTH_MODE_STATUS_ACTIVE → On; STEALTH_MODE_STATUS_INACTIVE → Off; STEALTH_MODE_STATUS_UNKNOWN → Not Available.

profile_status

Profile Status

PROFILE_STATUS_UP_TO_DATE, PROFILE_STATUS_OUT_OF_DATE, PROFILE_STATUS_NOT_INSTALLED, PROFILE_STATUS_UNKNOWN. macOS only.

missing_permissions

Missing Permissions

AGENT_PERMISSION_FULL_DISK_ACCESS, AGENT_PERMISSION_SCREEN_RECORDING, AGENT_PERMISSION_ACCESSIBILITY. macOS only.

errors

Agent Errors

USER_AGENT_NOT_CONNECTED, DRIVER_MISSING, DRIVER_NOT_LOADED, USER_DATA_MISSING, BROWSER_EXTENSION_NOT_CONNECTED, ES_CLIENT_UNAUTHORIZED.

mac_addresses

MAC Addresses

One per row in the Summary tab.


Supported Browsers

The following browsers are recognized: Chrome, Firefox, Edge, Safari, Edge, Arc, Brave, OpenAI Atlas, Perplexity Comet, Vivaldi.

Last updated

Was this helpful?