GFI LanGuard is software used to manage and maintain end-point protection across a network. It provides visibility into all the elements in the network, helping to assess where there may be potential vulnerabilities, and enables the administrator to patch them. It is a patch management and network auditing solution.
N/A
ManageEngine Endpoint Central
Score 9.0 out of 10
N/A
Desktop Central from ManageEngine is a client desktop management with patching, remote control, and configuration.
-To track the vulnerability level of a windows network. -To push windows and other application updates from a central location. -Produce reports to highlight work being done to protect a network. In some organizations, you may have to prove for audit reasons you are enforcing policies put into place around cyber-security. This software can help you track work done on an ongoing basis for such purposes.
It provides highly secure protocols for Encryption and is also very easy to recover the Encryption code at the administrator level if needed. Remote support for users and workstations is very smooth, with no connection lag between entities. Monitoring Monthly security updates and implementing them in your server environment is very easy. The layout makes it very easy to understand what is where, and if you missed something, it will indicate it.
We set alerts when a devices gets low on disk space. That is automatic and creates a ticket in ME SDP. We are then able to Add space to a VM Desktop, and then go thru ManageEngine Endpoint Central to extend the drives so the entire process can be done without interruption to the end user.
Using the patch scans we can easily see what patches have been installed for all manufacturers not just Microsoft, without having to physically go to the device. It also allows us to choose which patches we want to push out and automate the process so we can be hands off, freeing up out time for other things.
Remote access to devices. This allows us to remotely make changes, not just via remote control but also make registry changes and clean up space without going to the device and without interruption to the end user.
Alerts. We have set up to get email alerts when new hardware is plugged into any computers. This lets us know if someone is bringing in un-authorized equipment (thumb drives, hubs, etc) to better manage what is/is not on our network.
It could be a bit of information overload which some things are shown can become noise. Maybe different levels of "security" for lack of a better term may be better where you have a summary vs detailed level when it comes to rating the vulnerability of the entire network.
I find I sometimes have issues with PCs on a different network accessed across a VPN where timeouts often occur with very large updates. This aspect can be improved.
The remote CLI/PowerShell interfaces should support tab completion and command history like the real-world versions
Remote control could work better
Having a standalone application, even if just a Java app or something for the remote control/remote command line versus running it out of a web browser
ManageEngine is considered an excellent product due to its comprehensive suite of solutions for IT management, with ManageEngine Endpoint Central specifically excelling in endpoint management. The platform stands out for its user-friendly interface, robust features, and versatility in addressing diverse IT needs. It offers organizations a centralized solution for endpoint security, patch management, software deployment, and asset management
I'm very satisfied with this product, but there's definitely room for improvement. As I mentioned earlier, remote system management tools like the Task Manager could be greatly improved with new features, cleaner UI, and better optimization/responsiveness. Their remote Task Manager gives access to the Processes and Startup tabs of your standard Windows Task Manager, but it's missing useful tabs like Performance. Sometimes software deployments do not begin right away. When inspecting the task you may notice that the status is empty, or the status reads "Waiting on [X task] before beginning deployment". Even if that other task is paused and never began, your new task still might take its time deploying. This behavior can make it frustrating to deploy software when you're trying to fix something urgent.
I only tried to access there support once and it was a relatively pain-free process. They also have a lot of documentation available online which can be used to learn and tailor the software to suit your needs. It just takes time and effort to plan, execute and monitor going forward.
The immediate chat support is great and very helpful. However, if you need escalated support or have a deeper need that the chat tool can't help with, you will experience significant wait times and slow responses. The time zone difference becomes painful to the point of often just giving up.
It seems that the services offered with the purchase change from what is covered to what is an additional cost. Somethings I thought we had ended up requiring an additional purchase if we wanted to continue using the feature.
WSUS was the other alternative I considered but I believe GFI takes updates, reporting, and functionality to a different level for an enterprise/medium-size business environment.
This works great. It is super easy to setup automated patching and the patching actually works. When using Solarwinds, we would have to regularly troubleshoot machines and figure out why they were not patching. This is not the case with ManageEngine Endpoint Central. We have seen a significant decrease in number of troubleshooting hours since moving.
Certainty. It allows you to know where on your network needs attention.
Peace of mind. As security professionals, we can only put the necessary things in place to prevent malicious persons from exploiting a network. The software allows you to know whether or not your risk of exploitation is high or low. and if high what to do with it.
We have been able resolve and complete any requests which include things like software deployment or issues that include troubleshooting, much faster and more efficiently. This has had a sharp decrease in our response times and also time it takes to complete these requests or incidents.
The mobile device management features have allowed us to be able to have a much tighter grip on security. This means we have dramtically decreased our device vulnerabilities and risk of data breaches. This has saved us lots of time and money.
The remote features that are available have helped a lot with user's being able to work remotely and allow our organisation to sustain hybrid work. It means user's can still be as productive and IT support is as efficient no matter where the user is working.