Appearance
Groups
Groups collect endpoints into reusable targets for jobs, variables, configuration profiles, alert rules, and reporting.
Open Groups from the top navigation.
Group Types
Ordyn supports groups that are scoped globally, to a tenant, or to a folder.
Groups can be:
- static, where endpoints are assigned directly
- dynamic, where endpoints match rules
Dynamic group rules can use endpoint properties and inventory fields. The query tab shows the configured rule logic.
Firmware inventory fields are grouped under Firmware. Rules can match the selected vendor and the collected Secure Boot, Wake-on-LAN, virtualization, IOMMU, TPM, capsule update, BIOS downgrade, and AC power recovery values. A firmware field is null rule also matches endpoints that have not collected firmware inventory or did not report that particular setting.
Windows security posture fields can match VBS, Credential Guard, Memory Integrity, LSA protection, UAC, cached logons, NTLM, Remote Desktop, Windows Firewall, and Microsoft Defender inventory. SMB fields cover separate client and server protocol, signing, encryption, guest logon, NTLM blocking, dialect, auditing, service, and authentication-delay values.
Boolean security fields support is true, is false, is null, and is not null. Use the null operators to identify endpoints that do not support a setting or have not reported it. Numeric fields such as cached logon count and SMB invalid-authentication delay support numeric comparisons.
Uptime Rules
Select the Uptime field to group endpoints by how long their operating system has been running. Configure a positive whole-number duration in minutes, hours, days, or weeks, and use one of these comparisons:
- greater than
- greater than or equal to
- less than
- less than or equal to
- is null
- is not null
Ordyn advances the effective uptime while an endpoint is connected. When an endpoint disconnects, its effective uptime freezes at the last time the endpoint was seen. A later inventory update corrects the value after the endpoint reconnects or reboots.
Dynamic group memberships are refreshed periodically. An endpoint that crosses an uptime threshold without sending new inventory can take approximately ten minutes to enter or leave the group.
Group Detail
A group detail page can show:
- overview
- endpoints
- assigned jobs
- automations
- configuration profiles
- alert rules
- variable overrides
- query definition
- audit history
Use groups when the same set of endpoints should receive the same automation, configuration, or reporting treatment.