Skip to content
Open app
Open app

RMM — devices, updates, backup

Daily technician work: device list, update scans, alerts, backups and scripts.

The device list shows PCs with the agent installed. Online/offline comes from the agent heartbeat — if the PC is off or the agent is down, you will see offline. The LED next to the host is green = online, red = powered off / offline. The list refreshes status in the background (the LED changes colour without reloading the page). The agent usually heartbeats about once a minute.

Open device details for metrics, history, updates and actions (restart, scan, script).

Summary and Backup have two technician notes. This company is shared (how backups work, which databases and programs). This computer is only this machine (what is installed here and what to update on this PC). The computer note is the same one in the ☰ menu on the endpoint list. Do not store passwords or keys here — they belong in the vault. On My companies, the company note is on the expanded company card.

  1. Open RMM → Endpoints / Devices.
  2. Use the search box (host, company, CRM user) and filters (status, OS, location) to narrow the list. Fixing a typo or clicking X in the field refreshes results without reloading the page.
  3. Click a device to open its detail card and available actions.
  4. A single endpoint: row ☰ menu → Delete endpoint.
  5. After selecting: Update OS, Restart, Add to / Remove from group, owner — plus More (script, maintenance window, backup, delete).
  • A new device appears after agent install and the first connection to the server.
  • Assign devices to groups (e.g. servers, endpoints) to simplify policies and maintenance windows. A device can be in several groups; “Add to group” does not remove the others.
  • Bulk actions: narrow filters first; Delete cannot be undone in the panel.
  • Delete only when the PC should leave the fleet. There is no “mute monitoring for now” — a maintenance window is a patch calendar, not a pause in coverage.
  • Workbench → Relations: the CRM equipment or vault entry name opens that record; Cancel returns to the workbench. The count tile opens a filtered CRM list, not a specific record.
  • USB, drivers, disks, network and system info on the hardware card are the agent’s current snapshot (last scan), not a history of every scan. SMART on the card is also the latest reading; rows older than about 30 days are dropped, but the newest row per disk stays.
  • Inventory (Endpoints → Inventory) compares the fleet: hardware, disks, network, system. The CRM user column is the contact assigned to the computer — who works on it. The same contact is on the endpoint list. When nobody is linked, Link opens Workbench → Relations.

On the device workbench → Summary, the CPU/RAM chart is the whole machine over time (6 / 24 / 72 h). The classic chart also has 7 and 30 days. The last 7 days stay full resolution; older points are 15-minute peaks — “max CPU/RAM” reports still see the peak. It is not a history of a specific application.

Just under the chart is Top 5 processes (now) — the latest agent scan (about every 5 minutes), the same pattern as Ninja and N-able. That table does not match a Tuesday point on the chart. Clicking a process opens Operations → Processes, sorts by CPU or RAM, and highlights that process in the current top list (not a one-row filtered card). Ending a process lives there, not on the chart.

When a high CPU/RAM alert fires, “who did it” is on the alert card (At alert time). That is a frozen top-process snapshot from the threshold moment — a different instant than the list under the chart.

Updates: from the device card or the Updates module, run a scan, review pending patches and install selected ones. On sensitive machines you can force manual-only restart (no auto-reboot) via group settings. On Patch OS per device, the KB queue, the count badge (red = Critical severity, yellow = pending with no critical; Security alone does not turn the badge red) and History panel refresh on their own — the page does not jump. The fleet strip counts critical/security separately. After an install, KBs leave the queue only after the agent’s follow-up scan; the job stays in History (a log, not the queue).

Alerts: rules detect problems (e.g. missing heartbeat, backup failure). On an alert you can Acknowledge, Resolve, Fix (sends a prepared fix from Automation → Remediation templates, if one exists) or Delete. Active alerts and tickets refresh in the background.

Other live technician queues (dashboard, operations history, Software, CVE, backup Runs, automation, inventory, workbench) also refresh status in the background — the page does not jump. A hidden browser tab pauses. History (/rmm/operations) hides routine collector SNMP scans and backup-file housekeeping (reconcile / delete) — SNMP lives on SNMP and network devices, retention on Runs. The Other filter still shows them.

  1. On a device, run an update scan and review the pending list.
  2. Open Alerts — acknowledge new items and assign a technician (if you have RMM user accounts).
  3. After the fix, mark the alert resolved so the list matches reality.
  • Alert assignees are RMM users, not CRM contacts.
  • Maintenance windows limit when patches may install or machines may reboot.

On the device card → Protection you see Bitdefender quarantine (threat, path, date, status) — like Atera or Ninja, not only EDR incidents.

  • The Malware Status report in the Bitdefender console shows active threats. Cleaned files (for example old mail archives) stay in quarantine and here in the panel.
  • Quarantined means the file is already isolated. Bitdefender is not waiting for remove or restore. It does not mean “no threat”.
  • The list shows items that need attention first (removing / restoring). The full path, for example PST → attachment, is in the tooltip. Beyond about 100 items the rest is in the Bitdefender console.
  • The alerts hub does not alert on every isolated file. One card per PC only when remove or restore is pending or failed.
  • cmd.exe / PowerShell without encryption is not a row on the events list (like Atera / Ninja). The Recent detections tile stays at 0 — detections are Bitdefender (quarantine / EDR), ransomware with impact, and phishing from 60 points. Auto ticketing is in device Settings. The panel may still keep about 100 agent traces per PC in the database (audit); they do not appear on Protection.
  • The GravityZone API key needs the Quarantine permission. The EDR list is a separate block on the same tab.
  • On Starter / trial turn Bitdefender on in Settings → Company (or on the PC card). RMM tries to create a separate GravityZone company so reports are not mixed in one partner bucket. After the MSP license is activated: Retry GZ, save company policy, or request the Windows installer. My companies is MSP+ only. A partner on an expired Bitdefender trial cannot create companies — you need a paid MSP monthly subscription.
  • Restore and delete files in the Bitdefender console — the panel is read-only.
  1. Open the device → Protection.
  2. Scroll to Bitdefender quarantine.
  3. If the list is empty but Bitdefender shows items: check the API key permission and Sync with GZ.

Backup needs a destination plus a job assigned to a device. During the 14-day trial, cloud backup is blocked — test with a local disk, USB, NAS or SMB. Darnet Cloud unlocks after you move to a paid plan — you pay for stored GB.

On the device workbench → Backup, the destination list shows occupied space. A local disk/USB on this PC also shows used and free space on the volume. 0.00 GB is a real reading (this company’s cloud is empty or has no backups yet); Not measured means there is no store listing and no estimate from successful runs.

Cloud jobs show a usage estimate (GB) — enter an expected size to gauge upload and retention before saving.

A ZIP job stages the archive on the PC first. The agent picks a local disk with enough free space (not always C:). Pin a data volume in device settings → Backup temporary folder, or use “Files only (no ZIP)” when no local disk can hold the copy. In files-only mode the run card can stay at 0 B until the first large file (for example a VHDX) finishes — that does not mean nothing is uploading.

  1. RMM → Backup / Recovery. Above the tabs you can narrow the view to a company or a device (jobs and history). Darnet Cloud is one destination for every company you manage — you pay for stored GB. A platform admin on Destinations (Company: all) sees who uses the cloud and how many GB (company + owner email), not every firm’s USB/NAS. An MSP account is one row; pick a company to open its destinations. MSP/technician: the card has a Platform badge. A copy from a client PC goes to that company’s isolated store (separate bucket). Add your own S3 / USB / NAS in the company context. The left nav keeps the current scope. On Starter (one company) the company picker is hidden.
  2. On Starter the Darnet Cloud destination is already listed — you do not add your own S3 and you cannot delete the platform destination. You pay for stored GB according to the price list. Optional disk / USB / NAS: + Disk / NAS. During trial: local disk or SMB. MSP: add your own S3 if the plan allows, or open the workspace from a device card / My companies. The last health-check error shows on the tile only when the store is not healthy. The panel keeps recent checks, not the full history.
  3. Create a backup job: scope, schedule, retention, optional encryption. The schedule can be daily, weekly, or Interval (every N) — then set Every and the unit (hours / days / weeks / months); start time uses the company timezone. A local destination needs a selected device (scope or preview agent) — otherwise the panel cannot show paths on the PC. Starter: Standard or RAKS source. Business+: also MSSQL and Veeam. MSSQL: one base path (e.g. C:\Backups\MSSQL) — the agent appends an instance subdirectory. RAKS: data folder (Data or Data4 — see config.ini DB_PATH) plus a .fbk staging folder (not the live data folder). All firms is the default. Selected firms and Discover firms on the host (Windows agent 1.0.345+) limit the dump; F00002 also includes Z00002. The job card shows “RAKS · All firms” or the selected aliases. The Windows agent runs gbak; files are named F00002_arch_yyyy-MM-dd.fbk (Administrator wizard pattern). Restore the firm in RAKSSQL Administrator → Restore. The panel (Windows agent 1.0.343+) places .fbk files in a folder, without ZIP restore and without gbak.
  4. On the Jobs list the schedule is written in plain language (for example every day at 02:00), not as cron. The job that runs next is at the top. The card also shows the last run result. While that run is in progress, the card updates to success or failure on its own — you do not reload the page. Full history is on the Runs tab — the jobs list loads only the latest.
  5. Run a test and check the run history (success/fail). The Runs card shows status, size and error; the full Veeam/MSSQL dump is on the run detail.
  6. From the dashboard, Backup failures opens those failed runs from the last 24 hours. When the count is only an open alert (no recent run), it opens the alert hub filtered to backup failures.

The A task was canceled message on a Runs card is not a Cancel click. The agent reports a broken upload that way (HTTP/S3 timeout of about 100 s per part on older agents, service restart, or a newer run of the same job). Re-run the job; agent 1.0.304+ uses a longer upload timeout.

  • Restore test runs a real restore with validation — you can target another device.
  • Starter uses Darnet Cloud (platform cloud storage, no customer S3 keys). You pay for stored GB.

Scripts: pick from the library, run on a device, check stdout/stderr and exit code. Cancel is best-effort. The script list does not include source — open Edit to see the body.

An RMM ticket is technical work on a device. For customer reporting you usually also create a CRM Case — see the CRM guide.

  • Automation → scripts and repeatable actions without manually logging onto the PC.
  • From a device you can create a ticket, then link it to a CRM case.

Reports, evidence, and significant incidents

Section titled “Reports, evidence, and significant incidents”
  • RMM → Reports: first search for a company (type the name — do not scroll a long list), then client PDF, internal KPI, and a security evidence pack (PDF/CSV) — not a NIS2/KSC certificate.
  • Scheduled client PDF email goes to the company owner. The subject is “Periodic IT report” plus the company name. Delivery on the 1st covers the previous full month; Monday delivery covers the previous week (Mon–Sun).
  • The client PDF stays in Polish until you choose English for that company. Critical means a service failure (servers, failed backups, critical patches blocked on approval). A new patch and the vulnerability register are Needs attention at most.
  • On an alert or ticket you can mark a significant incident; the alert timeline shows 24h/72h deadlines. The panel does not file with CSIRT.