Skip to main content

DRV Frag Monitoring - Alert Only [Workstations]

Summary​

View-only group for workstations configured with Alert Only mode in the DRV Fragmentation Monitoring solution. This group is intended for reporting and visibility only; it does not receive the DRV Frag Monitoring Configuration Writer task, the DRV - Frag Monitoring monitor, or the DRV Frag Autofix automation task. Because Alert Only mode never triggers automatic remediation, no suspension policy is applied to this group. Its sole purpose is to provide a filtered view of workstations that are in Alert Only mode, regardless of whether the setting comes from the endpoint, site, or company level.

Dependencies​

Group Setup Location​

  • Group Path: ENDPOINTS ➞ Groups
  • Group Type: Dynamic Group

Group Summary​

  • Group Name: DRV Frag Monitoring - Alert Only [Workstations]
  • Category: Monitoring
  • Description: View-only group for workstations configured with Alert Only mode. Used for reporting and visibility; no automation is applied to this group.

Image1

Criteria​

The group is defined by the following criteria blocks, joined by an OR. Each block uses AND logic between its conditions.

BlockCriteria NameOperatorValue(s)
1DRV_Frag_ModeContains any ofEnabled - Alert Only
1OS TypeContains any ofWindows
1Endpoint TypeNot EqualServer
2DRV_Frag_Mode_Wks_SiteContains any ofEnabled - Alert Only
2DRV_Frag_ModeDoes Not Contain any ofDisabled
2OS TypeContains any ofWindows
2Endpoint TypeNot EqualServer
3DRV_Frag_Mode_WksContains any ofEnabled - Alert Only
3DRV_Frag_Mode_Wks_SiteDoes Not Contain any ofDisabled
3DRV_Frag_ModeDoes Not Contain any ofDisabled
3OS TypeContains any ofWindows
3Endpoint TypeNot EqualServer
  • Block 1: Targets Windows Workstations (devices not equal to "Server") where the feature is explicitly set to Enabled - Alert Only directly at the individual endpoint level (DRV_Frag_Mode).
  • Block 2: Targets Windows Workstations where the site-level workstation setting (DRV_Frag_Mode_Wks_Site) is explicitly set to Enabled - Alert Only, provided that it has not been overridden and disabled at the individual endpoint level (DRV_Frag_Mode).
  • Block 3: Targets Windows Workstations where the primary workstation setting (DRV_Frag_Mode_Wks) is set to Enabled - Alert Only, provided that the feature has not been explicitly disabled at the site level (DRV_Frag_Mode_Wks_Site) or the individual endpoint level (DRV_Frag_Mode).

Logic:
A machine matches the group if it meets ALL criteria in Block 1, OR ALL criteria in Block 2, OR ALL criteria in Block 3.

Image2

Completed Group​

Image3

Changelog​

2026-08-26​

  • Initial version of the document