Find files and classify them
Review what a station found. The file stays on the station. Classification is the next article.
Find files and classify them
Discovery looks on the station, in Documents, Desktop, and Downloads, including the copies OneDrive keeps in those folders. It does not scan Windows, Program Files, the agent folder, or network shares.
It reads plain text, Word, Excel, PowerPoint, and PDF text. On Windows it also reads pictures and scanned PDFs. On Linux, pictures are skipped and documents are still read.
A confident match — a card number that checks, a private key, or a cloud key — can propose the label Sensitive with no audience, unless an operator has already locked that file. Every other match stays a finding until someone classifies it.
Review findings
Open FileGuard → What stations found.
- Needs a decision lists files that are not classified yet. Needs a look on that row means the match itself was not certain.
- Classified lists files an operator has labeled. The uncertain-match bubble is no longer shown there.
- Connected means the station checked in during the last 5 minutes. Filter by a device group from Managed devices when the fleet is large. That filter does not change the FileGuard policy, which stays organization-wide.
- Look now asks a current station to scan once, outside the night window.
When a scan runs
The regular pass waits for the discovery window and for the station to be idle. Look now ignores that window, the idle wait, and battery, for a single pass. It does not mark the night window as already finished, so the scheduled pass can still run later.
A station that has not checked in during the last 5 minutes is shown as offline. Look now is for a connected station whose agent includes FileGuard.
From a finding to a label
Setting the label, choosing who may open the file, and asking for a masked excerpt are the next step. See Classify a file and choose who may open it.
