ThreatLocker: protected endpoints, enforcement mode, and what was blocked
ThreatLocker is Zero Trust for endpoints: nothing runs unless it is on the allowlist, and approved software is ringfenced so it can only do what it is supposed to. This connector reads four things out of it: which machines carry the agent, whether ThreatLocker is actually enforcing on each one, how much it blocked, and which machines on the network have no agent at all. Each one hangs off the matching Current company, so it feeds your security business reviews and the company alert band. Current reads ThreatLocker and can never change anything in it.
What Current syncs
| Data set | What Current stores | Where it lands |
|---|---|---|
| Organizations | Every organization in your ThreatLocker tree, including the ones nested under a parent — by id and name. This is the key Current maps to a Current company. | The mapping panel on the ThreatLocker card |
| Protected endpoints | Per machine: its name and computer group, operating system, agent version, when it last checked in, when the agent was installed, and the enforcement mode ThreatLocker reports — stored exactly as ThreatLocker words it. | The mapped company's security card, SBR packs, and dashboard coverage metrics |
| Enforcement coverage | Per organization: how many endpoints are enforcing, how many are watching without blocking, how many Current could not classify, and how many stopped checking in more than three days ago. | The company's posture panel and the SBR security chapter |
| Blocked executions | Counts only: what ThreatLocker denied in the last day and the last week, and how many of those were ringfencing violations. Current stores the numbers and never the events behind them. | The company security card and dashboard preventive-value metrics |
| Coverage gaps | How many machines ThreatLocker saw on the network with no agent installed. The count only. | The company security card, where it is the account manager's list |
Before you start: create a User Role
ThreatLocker will not let you create an API user until at least one User Role exists, and the role dropdown on the API user form is empty until one does. Create the role first and the rest takes about two minutes.
- 11 · Open Manage ▸ Users ▸ User RolesSign in to the ThreatLocker Portal as an administrator. Roles live alongside users under Manage.
- 22 · Create a view-only roleName it something you will recognise later — "Current read-only" works. Give it exactly three permissions: View Computers, View Organizations, and View Unified Audit. Those three cover everything this article describes.
- 33 · Grant nothing elseLeave Edit Computers, Install Computers, Edit Organizations, and every approval or policy permission switched off. A view-only role means the credential Current holds has no way to change anything in ThreatLocker — which is the protection that keeps working even if something in Current were ever wrong.
Create the API user in ThreatLocker
- 11 · Open Manage ▸ Users ▸ API UsersSame Manage menu as the roles. Press New API User and give it a name that says what it is for.
- 22 · Add your view-only role WITHOUT picking an organizationThis is the step that decides whether Current sees one partner or all of them. When you attach the role, leave the organization selector empty. A role added with no organization applies across your whole tree; a role attached to a single organization gives Current exactly that one partner and no error to tell you so.
- 33 · Generate the API token and copy it nowPress Generate API Token. ThreatLocker shows it only while the side panel is open and never again — a lost token has to be regenerated, not recovered. Copy it before you close anything.
Find your instance code
ThreatLocker runs partners on separate portal instances, and a token only works against yours. In the ThreatLocker Portal, click Help in the top right: the short code is in brackets beside the "ThreatLocker Access" heading. It is also the middle part of your portal address. Some codes are a single character and some are longer — European, Australian and Canadian partners have codes like eu1, au1 and ca1 — so copy what you see rather than assuming a letter.
Connect it in Current
- 1Open the ThreatLocker cardIn Current's left sidebar open Integrations (it sits under Admin, so Tenant Admins have the link) and find ThreatLocker in the Monitoring and security section.
- 2Enter your instance code and API tokenThe instance is the short code from the Help panel. The token is the one you copied when it was generated. Leave the optional top organization id empty unless you have a reason not to — empty means the organization the API user already belongs to, which is what a partner running one ThreatLocker tree wants.
- 3Press Test connectionCurrent asks ThreatLocker for a single organization to prove both halves at once: that the token authenticates against your instance, and that its role can actually see the organization tree everything else is built on. Nothing is stored until that answer comes back. If ThreatLocker refuses, the card shows ThreatLocker's own reason rather than a generic failure. On success the token is stored server-side only — the browser never sees it again.
How often it syncs
The endpoint sync runs every 6 hours on a schedule, plus whenever you press Sync now on the card. Each run walks your organizations and every protected endpoint. The blocked-execution counts and the coverage-gap count run once a day instead: they cost one request per organization each and they answer a question about a whole day, so running them four times over would spend four times the requests on the same answer. If your estate is large, the first few runs may finish part of it and pick up where they left off — the card says so while that is happening.
The read-only guarantee
ThreatLocker's portal API is the same one its own console uses, so the calls that disable protection on a machine, open a maintenance window, approve a blocked application, or delete an organization sit right beside the ones that read data. Current handles that with two belts. The view-only role you created is the outer one: the credential itself has no way to change anything at the vendor. The inner one is an allowlist naming four exact read addresses and nothing else — not a prefix, the whole address, character for character, so no neighbouring call can be reached by accident. Everything else is absent from the code rather than present and uncalled, and that includes reads Current chose not to take: the one that returns your agent deployment key, and the one that lists a partner's live override codes.
Map organizations to your companies
In ThreatLocker each end-customer is an organization, and Current maps every one of them, including organizations nested under a parent. Your own top organization appears in the list too — that is not a bug, and mapping it to your own company record gives you your internal posture alongside everything else.
- 1Let the auto-matcher run firstEvery sync links each organization to the one Current company whose normalized name matches. The clear ones map themselves; only the ambiguous ones need a hand.
- 2Open the mapping panelIntegrations → ThreatLocker → Manage → Customer mapping. It opens on the Unmapped tab, which lists every organization the matcher could not place.
- 3Map an organization to its companyOn an unmapped row press Map, type a few letters of the Current company, and pick it. That organization's endpoints attach to the company right away, rather than waiting for the next scheduled sync.
- 4Ignore internal or test organizationsFor an organization that should never map to a partner — a lab, a demo, a decommissioned tenant — press Ignore. It moves to the Ignored tab and stops counting against the card's unmapped badge.
- 5Fix a wrong match laterThe Mapped tab lists every linked organization; Unmap corrects a bad auto-match, and the Ignored tab's Un-ignore brings a dismissed one back. A mapping you set by hand is never overwritten by a later auto-match, and neither is a manual unlink.
What unknown means here
ThreatLocker words its enforcement modes its own way, and it can add a new one whenever it likes. When Current does not recognise a mode, that machine is counted as unknown rather than as protected: it is left out of both the enforcing count and the watching-without-blocking count, and the card says how many are in that state. It is the one place where a connector reporting less is the connector working — a workspace reading a clean hundred percent because Current guessed at a word it had never seen would be the worst thing this feed could do. The same rule runs through the rest of it: a machine that has never reported a check-in is counted as unknown rather than as quiet, and a number Current was not able to ask for stays blank rather than showing zero. Zero blocked executions is a real and meaningful state — a well-tuned allowlist genuinely denies nothing on a quiet day — so it is never used to stand in for "we did not ask".
Troubleshooting
| What the card says | What it means | What to do |
|---|---|---|
| ThreatLocker rejected these credentials (401) | One of three things, in the order worth checking. The instance code is wrong; the token was pasted short; or something was typed in front of the token. | Check the instance in the ThreatLocker Portal under Help first — it is the free check and it costs nothing. Then re-copy the token. ThreatLocker takes the token on its own, with nothing in front of it. Regenerating the token is the last thing to try, not the first. |
| ThreatLocker accepted the token but refused the organization list (403) | The token works. The API user's role is missing View Organizations. | In the Portal, Manage → Users → API Users, open the role and add View Organizations. Add View Computers and View Unified Audit while you are there — those are the other two reads Current makes. |
| Current can see your endpoints but not your Unified Audit | The role has View Computers but not View Unified Audit. Everything except the blocked-execution counts is syncing normally. | Add View Unified Audit to the role, or leave it: the connector is still useful without it, and the blocked counts stay blank rather than showing a zero Current cannot stand behind. |
| Only one organization came back | A role attached to a single organization instead of being left unscoped. Nothing errors, because from ThreatLocker's side the answer is correct. | In the Portal, Manage → Users → API Users, remove the role from the API user and add it back without choosing an organization. Press Sync now afterwards. |
| ThreatLocker answered 404 | The address exists but does not serve this account. That is what a wrong instance code looks like. | Read the code again from the Help panel in the ThreatLocker Portal, in brackets beside "ThreatLocker Access". |
| Current didn't recognize some endpoint modes | ThreatLocker returned a mode Current has no rule for. Those machines are counted as unknown rather than as protected. | Nothing is broken and no data is lost — the mode is stored exactly as ThreatLocker sent it. Tell support which modes your workspace uses and the rule is added; the numbers correct themselves on the next sync without a re-sync. |
