WithSecure (Beta)

👍

Quick Details

Recommended Agent: On-Demand
Supported Agents: On-Demand and Self-Managed
Is Auto-Discovered By: N/A
Can Auto-Discover: Yes — discovers one child launchpoint per WithSecure customer organization
Parent/Child Type Inspector: Yes
Inspected via: API
Default Frequency: Daily. (max every 8 hours)
Data Summary: WithSecure Inspector Summary

Overview

The WithSecure Inspector brings WithSecure Elements endpoint security (EPP/EDR) into Liongard's CMDB and change-detection platform. A single partner-level API credential enumerates an MSP's customer organizations and, for each customer, inventories protected devices, endpoint-security posture, EDR incidents, and recent security events — surfacing endpoint risk and configuration drift across every managed client.

WithSecure (formerly F-Secure Business, rebranded in 2022) is a Finnish cloud security vendor. WithSecure Elements is its modular, multi-tenant platform (Elements Endpoint Protection, Elements EDR, Collaboration Protection, and Vulnerability Management). MSPs operate a partner organization with one child "company" organization per customer.

Inspector Setup Preparation

Before you begin: You need an EPP administrator account in WithSecure Elements Security Center. For MSPs, perform these steps from the partner organization.

  1. Sign in to WithSecure Elements Security Center as an EPP administrator.
  2. Select Management in the left navigation.
  3. Open Organization Settings.
  4. Select the API clients menu.
  5. Select Add new.
  6. Enter a description (for example, "Liongard"), keep Read-only selected, and select Add.
  7. Copy the Client ID and Client Secret shown in the confirmation dialog. The secret is displayed only once — store it securely, since it cannot be retrieved again.

Liongard Inspector Setup

Step 1: Parent Inspector Setup

Since WithSecure is a multi-tenant system where a single MSP partner account manages many customer organizations, you will set up a single "Parent" Inspector with the WithSecure partner-level API credentials, which will then auto-discover a "Child" Inspector for each customer organization.

In Liongard, navigate to Admin > Inspectors > Inspector Types > Navigate to the WithSecure Inspector > Select Add System.

Fill in the following information:

  • Type of Inspector: Parent
  • Environment: Select your MSP's Environment
  • Friendly Name: Suggested Naming: Environment Name [WithSecure] Parent
  • Agent: Select an On-Demand or Self-Managed agent
  • API Client ID: Paste the Client ID copied during Inspector Setup Preparation
  • API Client Secret: Paste the Client Secret copied during Inspector Setup Preparation
  • Inspector Version: Latest (Auto-Update)
  • Scheduling: The Inspector will default to run once a day at the time the Inspector is set up. Here you can adjust the schedule.

Select Save. The Inspector will now be triggered to run within the minute.

Step 2: Child Inspector Setup

After the first run of the Parent Inspector, your client WithSecure customer organizations will be Auto-Discovered and surfaced on the Discovered Systems page.

Navigate to the Discovered Systems tab in your Inspectors > WithSecure page.

  • Activate your Discovered Systems by ensuring they're mapped to the correct Environment > Select the checkbox to the left of Inspector(s) > Select the Actions drop-down menu > Activate Launchpoints.
  • Users may also Archive Discovered Systems by selecting the checkbox to the left of the Inspector(s) > Select the Actions drop-down menu > Archive Launchpoints.

Troubleshooting

  • 401 on first run — the Client ID/Secret is wrong, expired, or the secret wasn't copied at creation; recreate the API client.
  • 403 / no incidents or events — the customer organization is not EDR-licensed; the inspector ignores these and still collects devices.
  • No child launchpoints discovered — the credential was created at a single company org rather than the partner level; recreate it at the partner organization.
  • Rate limiting — EDR endpoints are capped at 300 requests/min per IP; the inspector throttles to stay under this and retries on transient 429s.

Did this page help you?