Managed EPP protects your devices against malware, ransomware, and other threats with round-the-clock monitoring and expert analysis. Deel IT's security team continuously monitors your environment, detects threats, and works with you to respond appropriately.
- Service: Managed Endpoint Protection (EPP)
- Availability: US / CA / UK / EEA
- Platform: CrowdStrike - Falcon Pro / Falcon Enterprise
- Type: Ongoing managed service
What's Included
- Setup and tenant configuration
- Device policy management and enforcement
- 24/7 threat monitoring and analysis
- Threat triage and recommendations
- Network containment of threats on your approval
- Device reporting and compliance insights
In this article
Scope of Service
Setup and Onboarding
Deel IT configures the customer's EPP tenant, organizes devices into host groups, and stages the sensor rollout, bringing prevention up gradually to full enforcement.
Where the customer also has Managed MDM, Deel IT deploys the sensor through the MDM. Otherwise, deployment is the customer's responsibility, with the installer and guidance provided by Deel IT.
Policy Management
Deel IT configures and maintains fleet-protection policies, prevention, sensor updates, and others the EPP provider natively supports, assigned to host groups and set to the customer's requirements or recommended best practices. Adjustments (protection levels, exclusions, exceptions) are made on request; custom implementations beyond the provider's native set are not supported.
Monitoring and Triage
Deel IT monitors the customer's EPP environment around the clock. Security engineers analyze and triage each detection, determining whether it is a genuine threat, a false positive, or something needing the customer's input.
Threat Response
For genuine threats, Deel IT emails the customer's named point of contact with its findings and a recommended action. Deel IT does not act without the customer's approval, with one exception: a verified critical threat where containment is clearly needed to prevent data loss, in which case Deel IT contains the device immediately, then notifies the customer.
The only device action under Managed EPP is network containment. Further remediation, such as credential resets, or device wipe or restore, is recommended but carried out by the customer, unless covered in the section below.
Integration with Managed MDM and 24/7 Tech Support
Beyond containment, what Deel IT can do depends on the customer's other Deel IT services:
- Managed EPP alone - analysis, reporting, and network containment on approval
- With Managed MDM - device-side actions through the MDM, such as locking, wiping, or resetting the affected device
- With Managed MDM and 24/7 Tech Support - the full security lifecycle: detection, triage, containment, device wipe or reset through the MDM, and end-user support to get the user set back up
Reporting
On request, Deel IT provides reports on device status and detections, using data from the Deel IT and EPP platforms.
What's Not Included
- Full incident remediation and liability assumption
- Device actions beyond containment (unless Managed MDM is purchased)
- Additional CrowdStrike packages (SIEM, SOAR, etc.)
- Custom policy implementations beyond platform capabilities
- Direct end-user support (unless 24/7 Tech Support is purchased)
- On-premise or hybrid deployments