About Field Effect MDR
Learn more about Field Effect and our solution
For Partners
Understand the role of a Partner, manage licenses, clients and brand your portal
For Client Administrators
Deploy the MDR service, setup your appliance sensors and deploy agents to your endpoint devices
-
Agent Install Guide - Windows
-
Agent Uninstall Guide - Windows 11
-
Agent Uninstall Guide - Windows 11, Command Line
-
Agent Install Guide - macOS
-
Agent Uninstall Guide - macOS
-
Best Practices: Automated Agent Deployments
-
Sensor-Hosted Endpoint Agent Installers: Overview
-
Uninstalling the Endpoint Agent in Bulk
-
Windows Install PowerShell Script for RMM/MDM
-
Deploying the macOS Agent via Intune
For Users
Using the MDR service
Using the MDR Portal
Use the my.fieldeffect.net portal to monitor your threat surface
-
Access Your Account Settings
-
Add a Mobile Number to Your Profile
-
Change the MDR Portal's Default Language
-
View & Manage Notifications
-
Multi-Factor Authentication (MFA): Overview
-
Getting to Know AROs
-
The Anatomy of an ARO
-
Working with AROs
-
ARO Comments & the Activity Feed
-
The AROs Page
-
Cloud Monitoring: Overview & Setup
-
Microsoft 365
-
Authorizing Microsoft 365 Cloud Monitoring
-
Google Workspace
-
AWS
-
Active Response: Overview
-
Response Policies: Overview
-
Response Actions: Overview
-
Configure Active Response
-
Enable Active Response for Cloud Services
-
DNS Firewall: Overview & Setup
-
Adjusting DNS Firewall Categories
-
Using the Custom Allowlist or Blocklist
-
Partners: Setting Up a Default DNS Policy
-
Mapping Safe Networks
-
The User Management page
-
Inviting Users
-
Editing User Permissions
-
Searching and Filtering for users
-
Managing users
Using the MDR SIEM Portal (Appliance Dashboard)
Look beyond the portal and explore the data held in your MDR SIEM
Mobile App
Setup and use our Mobile app
Connect a 3rd party
Connect your PSA tool or use the Field Effect API
Troubleshooting & FAQs
Answers to some commonly asked support questions
-
What events are collected by Field Effect?
-
Audit Policy Requirements for Field Effect MDR
-
Can Field Effect ingest application logs?
-
Does Field Effect protect against log tampering by the originator?
-
Can Field Effect store (retain) logs for a required period?
-
Why was an ARO notification late?
-
What is an "Impossible Travel" scenario?
-
ARO: Suspected Typosquat Domain Detected
-
What's the difference between Resolving and Dismissing an ARO?
-
ARO: Removable Drive Detected
-
Will users be able to login if a computer is isolated?
-
Can Field Effect MDR send an automated email to our ticketing systems when a computer is isolated?
-
What is the process to remove isolation and restore network connectivity to affected system in case of false positive? Can I do it myself?
-
How long would Field Effect take to notice an end point was infected with RansomWare?
-
What if my organization has another EDR service or solution with blocking capabilities?
-
My DUO 2FA code isn't working
-
How does cloud monitoring work?
-
What is detected with the Cloud Monitoring service?
-
Where are the cloud sensors deployed?
-
Is there an account limit on Office 365 domains?
-
Does the DNS firewall work with Chromebooks?
-
Do I need to worry about attacks on our Firewall?
-
Troubleshooting DNS Firewall
-
Looking Up Domains for the DNS Firewall
-
Error: The organization name already exists in the DNS Firewall Service
-
Troubleshooting the Endpoint Agent
-
What Endpoint agents are currently available?
-
Troubleshooting manual endpoint installation issues for Windows
-
Troubleshooting manual endpoint installation issues for QNAP
-
Why am I getting the error "Missing License File"
-
Does Field Effect do any type of Windows Event Log archiving or collection?
-
Where are the logs stored?
-
What’s the price to store logs for longer than 90 days?
-
How will I be charged?
-
Which data types can be retained?
-
Why cant I log into the physical appliance?
-
Troubleshooting Physical Appliances
-
Can I have confidence that my data is safe on an appliance?
-
We need to move the Appliance, what do I need to consider?
-
How does Network Monitoring Work?
-
PSAs - How can I quickly Navigate to the MDR Portal from my Integration?
-
Autotask - The integration card is missing on the Integrations page?
-
Autotask - What happens if I delete an ARO task in Autotask?
-
Autotask - Why was I was notified that my thread threshold is exceeded?
-
ConnectWise - My companies aren’t available for mapping in the MDR Portal?
-
Why am I seeing TOR Project exit nodes in my report?
-
Can I breakdown the Security Events summary in the Weekly Report?
-
Why am I seeing logins from unexpected countries on my Monthly Report?
-
Can I find out more about the Most Resolved Domains listed in the Monthly Report?
-
Can I find out more about the My Network Summary graph?
-
Is there an alternative to using the SEAS plugins
-
Why did my SEAS submission come back as Inconclusive?
-
Do I need to use DMARC?
-
Resolving the "This add-in had previously been uploaded" error
-
Recovering an Email Removed by SEAS