"Workstyles" Dashboard in Endpoint Privilege Management Reporting

The Workstyles report displays how the Workstyles you deployed are used within the specified time period.

The Workstyles Dashboard has the following charts:

Chart Description
All Workstyles over the time period

A table showing the number of Workstyles that matched, the number of hosts, the number of users, and the applications affected by those Workstyles. Workstyles are shown as a percentage of the total in the database, irrespective of any filters apart from Time Range.

Click the count for Workstyles, users, or hosts to display a list of the entities. Click the count of applications affected to open the Target Types > All table.

Summary by process activity (top 10)

Shows the top 10 most active Workstyles filtered by the type of action.

The types of actions are:

  • Elevated
  • Blocked
  • Enforce default token
  • Custom
  • Canceled
  • Sandboxed
  • Passive
  • Drop admin Rights

Click the chart to open the Events All report with the Action and Workstyle (may include wildcard match) filters applied.

% Coverage by Workstyle (Top 10)

A chart showing the percentage of users and hosts that the most active Workstyles cover. The Workstyles are ordered by the total number of users and hosts affected.

Click this chart to display a list of users or hosts affected by the Workstyle.

Process Coverage by Workstyle

A chart showing the process activity by Workstyle.

Click this chart to open the Events All report with the Filter by Event Category and Workstyle filters applied.

Process Coverage by Group Policy Object

A chart showing the process activity filtered by policy.

Click this chart to open the Events All report with the Filter by Event Category and GPO Name filters applied.

Top 10 Elevating Workstyles

A chart showing the Workstyles responsible for the most individual applications being elevated.

Click the chart to open the Target Types All report with the Filter by Action filter applied.

Top 10 Blocking Workstyles

A chart showing the Workstyles responsible for the most individual applications being blocked.

Click the chart to open the Target Types all report with the Filter by Action filter applied.

Top 10 Passive Workstyles

A chart showing the Workstyles responsible for the most individual applications being passively audited.

Click the chart to open the Target Types All report with the Filter by Action filter applied.

Top 10 Custom Token Workstyles

A chart showing the Workstyles responsible for the most individual applications having a Custom Token applied.

Click the chart to open the Target Types All report with the Filter by Action filter applied.

Workstyles All

This table lists all Workstyles by actions in the time period, grouped by the Workstyle name.

The following columns are available for the Workstyles All table:

  • Workstyle Name: The name of the Workstyle.
  • GPO Name: The Group Policy Object name.
  • Elevated: The count of the Elevated events.
  • Passive: The count of the Passive events.
  • Blocked: The count of the Blocked events.
  • Sandboxed: The count of the Sandboxed events.
  • Canceled: The count of the Canceled events.
  • Custom: The count of the Custom events.
  • Drop Admin: The count of the Drop Admin events.
  • Enforce Default: The count of the events enforced by default.
  • Total: The total number of events.
  • Policy Name: The name of the policy that includes the Workstyle.

Some of these allow you to drill down to additional information:

  • The i icon opens a Workstyle report.
  • Click any of the numbers to see the list of events in Events > All.
For more information on the available quick filters, see the following: