Understand Status Checks

Prev Next

Zscaler MDR strives to deliver the highest quality security operations in the industry. This is coupled with our commitment with being completely transparent in communicating how Zscaler MDR and your other security products are performing in comparison to expectations.

While few information security companies post even a basic status page for their cloud-delivered security applications, Zscaler MDR has set an entirely different standard by continually checking the status of the various EDR/EPP configurations and the performance of those platforms to ensure they’re working as expected.

You can monitor the results on the Zscaler MDR Status page, which reports the overall status of our operations, including an aggregation of statuses from the Endpoint Detection & Response (EDR) or Endpoint Protection Platform (EPP) platforms we retrieve data from, underlying cloud services such as Amazon Web Services (AWS), and infrastructure channels including Twilio and SendGrid for voice, SMS, and email.

Viewing Status Checks

In addition to the overall system status available on the Zscaler MDR Status page, you can view detailed status checks for your environment from within the Zscaler MDR portal. These checks are an important way we identify misconfigurations that might result in threats not being detected in your environment.

Note: To view the Status Check page, you'll need the Admin role assigned.

To view the status checks:

  1. Click the icon near your profile.

    Note: The Status Checks screen is filtered to show failed checks by default.

  2. Click the title of any status check to review what it checks, how to remediate any failures, and whether it passed or failed.

Examples of Status Checks

  • The EDR/EPP platform is configured to collect as much telemetry as possible.

  • The EDR/EPP platform has tamper checking / identification features enabled to identify adversaries who are tampering with the sensor.

  • The EDR/EPP platform is not configured to send sensitive information to third parties (a frequent unexpected surprise of cloud security products).

  • The EDR/EPP platform is configured to handle sensor upgrades in an orderly and predictable fashion, rather than automatically upgrading sensors to the latest version whenever it is released.

  • The EDR/EPP platform is collecting telemetry from endpoints and sending it to Zscaler MDR in a timely fashion.

FAQ


What happens when a status check fails?

When a status check fails, an email is sent to all users who’ve set status check notifications in their profile. You won’t be flooded with messages because the notification is only issued the first time a previously passing check fails. Learn more about enabling and disabling these notifications.

What happens when a status check is remedied?

In a similar fashion, when a failing status check recovers, an email notification is triggered to all of your users who have enabled status check recovery notifications in their profile.

What status checks are available?

The status checks active for your organization are specific to your underlying EDR/EPP platforms. You can find a list of those active for your organization by clicking the icon near your profile.

How often are status checks executed?

Status checks are executed every four hours.

What if I intentionally configure a setting against Zscaler MDR’s guidance?

While certain status checks verify crucial configuration settings required for Zscaler MDR to defend your company, others are better defined as best practices or strong recommendations.

Your organization may choose to deviate from those recommendations and accept the risk associated with that deviation. If so, you’ll receive a notification that the relevant status check failed, but no more alerts will be sent to your inbox.

Examples of the risks you’re accepting by deviating from common status checks include the following:

Status check

Risk accepted when failing

The EDR/EPP platform is configured to collect as much telemetry as possible.

Both Zscaler MDR and your team will be limited in detecting and investigating threats due to less data being available.

The EDR/EPP platform has tamper checking / identification features enabled to identify adversaries who are tampering with the sensor.

Adversaries can tamper with your EDR/EPP sensor without your or Zscaler MDR’s knowledge.

The EDR/EPP platform is not configured to send sensitive information to third parties (a frequent unexpected surprise of cloud security products).

You may unintentionally share sensitive corporate information such as usernames, endpoint hostnames, and binaries with unknown or unvetted third parties.

The EDR/EPP platform is configured to handle sensor upgrades in an orderly and predictable fashion, rather than automatically upgrading sensors to the latest version whenever it is released.

New sensor versions will be installed across your fleet at any time, potentially causing system conflicts, instability, or performance impacts.