WithSecure (Beta)
Quick DetailsRecommended Agent: On-Demand
Supported Agents: On-Demand and Self-Managed
Is Auto-Discovered By: N/A
Can Auto-Discover: Yes — discovers one child launchpoint per WithSecure customer organization
Parent/Child Type Inspector: Yes
Inspected via: API
Default Frequency: Daily. (max every 8 hours)
Data Summary: WithSecure Inspector Summary
Overview
The WithSecure Inspector brings WithSecure Elements endpoint security (EPP/EDR) into Liongard's CMDB and change-detection platform. A single partner-level API credential enumerates an MSP's customer organizations and, for each customer, inventories protected devices, endpoint-security posture, EDR incidents, and recent security events — surfacing endpoint risk and configuration drift across every managed client.
WithSecure (formerly F-Secure Business, rebranded in 2022) is a Finnish cloud security vendor. WithSecure Elements is its modular, multi-tenant platform (Elements Endpoint Protection, Elements EDR, Collaboration Protection, and Vulnerability Management). MSPs operate a partner organization with one child "company" organization per customer.
Inspector Setup Preparation
Before you begin: You need an EPP administrator account in WithSecure Elements Security Center. For MSPs, perform these steps from the partner organization.
- Sign in to WithSecure Elements Security Center as an EPP administrator.
- Select Management in the left navigation.
- Open Organization Settings.
- Select the API clients menu.
- Select Add new.
- Enter a description (for example, "Liongard"), keep Read-only selected, and select Add.
- Copy the Client ID and Client Secret shown in the confirmation dialog. The secret is displayed only once — store it securely, since it cannot be retrieved again.
Liongard Inspector Setup
Step 1: Parent Inspector Setup
Since WithSecure is a multi-tenant system where a single MSP partner account manages many customer organizations, you will set up a single "Parent" Inspector with the WithSecure partner-level API credentials, which will then auto-discover a "Child" Inspector for each customer organization.
In Liongard, navigate to Admin > Inspectors > Inspector Types > Navigate to the WithSecure Inspector > Select Add System.
Fill in the following information:
- Type of Inspector: Parent
- Environment: Select your MSP's Environment
- Friendly Name: Suggested Naming: Environment Name [WithSecure] Parent
- Agent: Select an On-Demand or Self-Managed agent
- API Client ID: Paste the Client ID copied during Inspector Setup Preparation
- API Client Secret: Paste the Client Secret copied during Inspector Setup Preparation
- Inspector Version: Latest (Auto-Update)
- Scheduling: The Inspector will default to run once a day at the time the Inspector is set up. Here you can adjust the schedule.
Select Save. The Inspector will now be triggered to run within the minute.
Step 2: Child Inspector Setup
After the first run of the Parent Inspector, your client WithSecure customer organizations will be Auto-Discovered and surfaced on the Discovered Systems page.
Navigate to the Discovered Systems tab in your Inspectors > WithSecure page.
- Activate your Discovered Systems by ensuring they're mapped to the correct Environment > Select the checkbox to the left of Inspector(s) > Select the Actions drop-down menu > Activate Launchpoints.
- Users may also Archive Discovered Systems by selecting the checkbox to the left of the Inspector(s) > Select the Actions drop-down menu > Archive Launchpoints.
Troubleshooting
- 401 on first run — the Client ID/Secret is wrong, expired, or the secret wasn't copied at creation; recreate the API client.
- 403 / no incidents or events — the customer organization is not EDR-licensed; the inspector ignores these and still collects devices.
- No child launchpoints discovered — the credential was created at a single company org rather than the partner level; recreate it at the partner organization.
- Rate limiting — EDR endpoints are capped at 300 requests/min per IP; the inspector throttles to stay under this and retries on transient 429s.
Updated about 7 hours ago

