Device attributes collected by Endpoint Verification

This document describes the details of device attributes that are collected by Endpoint Verification from the devices accessing your organization's resources. Endpoint Verification collects device attributes, device identity attributes, configurable device attributes and Chrome browser attributes.

Device attributes

The following table describes the attributes that are collected by Endpoint Verification that you can use to create access levels.

Attribute name Description Supported OS Example of using the attribute in the CEL expressions
is_secured_with_screenlock A boolean value that indicates whether the screen lock function is enabled on a device.
  • macOS
  • ChromeOS
  • Windows
  • Linux
device.is_secured_with_screenlock == true
encryption_status

The encryption status of a device. Possible values:

  • ENCRYPTION_UNSPECIFIED = 0 indicates that the encryption status of the device is not specified or not known.
  • ENCRYPTION_UNSUPPORTED = 1 indicates that the device does not support encryption.
  • ENCRYPTION_UNENCRYPTED = 2 indicates that the device supports encryption, but is not encrypted.
  • ENCRYPTED = 3 indicates that the device is encrypted.
  • macOS
  • ChromeOS
  • Windows
  • Linux
device.encryption_status == DeviceEncryptionStatus.ENCRYPTED
os_type

The operating system running on a device. Possible values:

  • OS_UNSPECIFIED = 0 indicates that the operating system of the device is not specified or not known.
  • DESKTOP_MAC = 1
  • DESKTOP_WINDOWS = 2
  • DESKTOP_LINUX = 3
  • DESKTOP_CHROME_OS = 6
  • macOS
  • ChromeOS
  • Windows
  • Linux
device.os_type == OsType.DESKTOP_MAC
os_version The version of the operating system running on a device.
  • macOS
  • ChromeOS
  • Windows
  • Linux
  • device.os_version == "MacOS 13.4.0"
  • device.os_version == "ChromeOs 14541.0.0"
  • device.os_version == "Windows 10.0.19045"
  • device.os_version == "Linux rodete"
verified_chrome_os A boolean value that indicates whether the request comes from a device with a verified ChromeOS. ChromeOS (only for enterprise-enrolled devices) device.verified_chrome_os == true
model The model of a device.
  • macOS
  • Windows
  • Linux
device.model == "MacBookPro16,1"
is_managed_browser_profile A boolean value that indicates whether the Chrome content area account associated with a device matches its Chrome profile account.
  • macOS
  • ChromeOS
  • Windows
  • Linux
device.is_managed_browser_profile == true
certificates Attributes of the certificates associated with a device. For example, Enterprise certificates.
  • macOS
  • ChromeOS
  • Windows
  • Linux
device.certificates.exists(cert, cert.is_valid && cert.root_ca_fingerprint == "SOME_ROOT_CA_FINGERPRINT")
windows_domain_name The domain name of a Windows machine. Windows device.clients["bce"].data["windows_domain_name"] == "GOOGLE"
is_os_native_firewall_enabled

A boolean value that indicates whether the operating system's built-in firewall is enabled on a device.

  • macOS
  • ChromeOS
  • Windows
  • Linux
device.clients["bce"].data["is_os_native_firewall_enabled"] == true
is_secure_boot_enabled A boolean value that indicates whether the secure boot option is enabled on a device. Windows device.clients["bce"].data["is_secure_boot_enabled"] == true
av_installed

A list of antivirus software products that are installed on a device.

Windows device.clients["bce"].data["av_installed"].exists(x, x == "mcafee") == true
av_enabled

A list of antivirus software products that are installed and enabled on a device.

Windows device.clients["bce"].data["av_enabled"].exists(x, x == "mcafee") == true
hotfixes

A list of hotfixes that are applied on Windows systems.

Windows device.clients["bce"].data["hotfixes"].exists(x, x == "KB0001") == true

Device identity attributes

The following table describes the attributes that are collected by Endpoint Verification that you can use to identify devices. These attributes cannot be used for creating access levels.

Attribute name Description Supported OS
Serial number The serial number of the device.
  • macOS
  • ChromeOS (only for enterprise-enrolled devices)
  • Windows
  • Linux
Hostname The hostname of the device.
  • macOS
  • Windows
  • Linux
Device ID The unique identification number associated with the device.
  • macOS
  • Windows
  • Linux
Wifi MAC Address The MAC address of the device.
  • macOS
  • ChromeOS
  • Windows
  • Linux

Configurable device attributes

Endpoint Verification provides an option to collect granular device attributes called configurable device attributes, such as metadata attributes of files, folders, and binaries; registry entries; and properties in a plist. You can use these device configuration attributes to create access levels.

This option is not enabled by default. To collect these granular configurable device attributes, configure Endpoint Verification settings.

The following table describes the file, folder, and binary attributes.

Attribute name Description Supported OS Example of using the attribute in the CEL expressions
presence

Indicates the presence of a file, folder, or binary. Possible values:

  • VALUE_UNKNOWN = 0 indicates that the presence is not known due to a failure that occurred before the assessment.
  • VALUE_INACCESSIBLE = 1 indicates that the organization does not have access to the signal's resource.
  • VALUE_NOT_FOUND = 2 indicates that the resource was not found.
  • VALUE_FOUND = 3 indicates that the resource was found.
  • macOS
  • Windows
  • Linux
device.clients["bce"].data["file_config"]["config_name"]["presence"] == PresenceValue.VALUE_FOUND
is_running Indicates if a binary is running. It is always false for a file or folder.
  • macOS
  • Windows
  • Linux
device.clients["bce"].data["file_config"]["config_name"]["is_running"] == true
sha256_hash

Provides SHA-256 hash of a file or binary. It is always an empty string for a folder.

  • macOS
  • Windows
  • Linux
device.clients["bce"].data["file_config"]["config_name"]["sha256_hash"] == ""
public_key_sha256

Provides a list of SHA-256 hash values of the public keys that are used to sign the executable. It is always an empty string for a file or a folder.

  • macOS
  • Windows
device.clients["bce"].data["file_config"]["config_name"]["public_key_sha256"].exists(x, x == "")
product_name

The product name of the executable. It is always an empty string for a file or folder.

  • macOS
  • Windows