NAC Posture Drift Detector
Baseline diff
Snapshot today's posture vs the last known-good baseline. Per-endpoint diff covers OS patch level, AV/EDR state, disk encryption, cert validity, MDM enrollment and NAC profile.
Severity + blast radius
Each drifted endpoint is scored info / warn / critical and tagged with the segments it can still reach, so you can triage by exposure not just count.
Prescriptive remediation
AI prescribes the minimal fix — re-enroll MDM, push patch, rotate cert, quarantine VLAN, or open a NetGitOps PR — with rollback notes per action.
Run a posture-drift scan
Pick a baseline window. AI returns drifted endpoints with severity, blast radius, and a ranked remediation plan.
Endpoint remediation workflow
Each ranked fix from the drift scan becomes an actionable task with an owner and an execution timeline. Assign a team, advance through queued → assigned → in-progress → verifying → done, or block if a change window is needed.
- No tasks match this filter.