Skip to content
Current/ Help Center

ThreatLocker: protected endpoints, enforcement mode, and what was blocked

6 min read · Updated Sep 5, 2026

ThreatLocker is Zero Trust for endpoints: nothing runs unless it is on the allowlist, and approved software is ringfenced so it can only do what it is supposed to. This connector reads four things out of it: which machines carry the agent, whether ThreatLocker is actually enforcing on each one, how much it blocked, and which machines on the network have no agent at all. Each one hangs off the matching Current company, so it feeds your security business reviews and the company alert band. Current reads ThreatLocker and can never change anything in it.

Note
What this connector is for
It is a value-signal feed, not a console. Current mirrors endpoint counts, enforcement mode, check-in freshness, and blocked-execution counts per organization. It does not disable protection on a machine, open a maintenance window, approve a blocked application, edit or deploy a policy, mint an override code, reboot or upgrade an agent, or create and delete organizations. Those endpoints are not in the connector's code at all, so no bug can reach them.

What Current syncs

Data setWhat Current storesWhere it lands
OrganizationsEvery organization in your ThreatLocker tree, including the ones nested under a parent — by id and name. This is the key Current maps to a Current company.The mapping panel on the ThreatLocker card
Protected endpointsPer machine: its name and computer group, operating system, agent version, when it last checked in, when the agent was installed, and the enforcement mode ThreatLocker reports — stored exactly as ThreatLocker words it.The mapped company's security card, SBR packs, and dashboard coverage metrics
Enforcement coveragePer organization: how many endpoints are enforcing, how many are watching without blocking, how many Current could not classify, and how many stopped checking in more than three days ago.The company's posture panel and the SBR security chapter
Blocked executionsCounts only: what ThreatLocker denied in the last day and the last week, and how many of those were ringfencing violations. Current stores the numbers and never the events behind them.The company security card and dashboard preventive-value metrics
Coverage gapsHow many machines ThreatLocker saw on the network with no agent installed. The count only.The company security card, where it is the account manager's list
Note
Counts, not events
The blocked-execution numbers come from ThreatLocker's own audit total, read as a single figure. Current never stores the events behind them, and there is nothing to browse. Those rows carry file paths, process names and the user who was working at the time, which is end-user detail a company record has no business holding — and a busy workspace generates millions of them a day. What a business review needs is the number; that is what Current keeps.

Before you start: create a User Role

ThreatLocker will not let you create an API user until at least one User Role exists, and the role dropdown on the API user form is empty until one does. Create the role first and the rest takes about two minutes.

  1. 1
    1 · Open Manage ▸ Users ▸ User Roles
    Sign in to the ThreatLocker Portal as an administrator. Roles live alongside users under Manage.
  2. 2
    2 · Create a view-only role
    Name it something you will recognise later — "Current read-only" works. Give it exactly three permissions: View Computers, View Organizations, and View Unified Audit. Those three cover everything this article describes.
  3. 3
    3 · Grant nothing else
    Leave Edit Computers, Install Computers, Edit Organizations, and every approval or policy permission switched off. A view-only role means the credential Current holds has no way to change anything in ThreatLocker — which is the protection that keeps working even if something in Current were ever wrong.
Heads up
View Unified Audit is what makes the blocked count work
Without it, Current still syncs your endpoints and coverage perfectly well, and the card says so — but the blocked-execution numbers stay blank rather than showing zero, because Current was never allowed to ask. If your policy will not permit that permission, the connector is still worth having, and what you lose is the preventive-value number.

Create the API user in ThreatLocker

  1. 1
    1 · Open Manage ▸ Users ▸ API Users
    Same Manage menu as the roles. Press New API User and give it a name that says what it is for.
  2. 2
    2 · Add your view-only role WITHOUT picking an organization
    This is the step that decides whether Current sees one partner or all of them. When you attach the role, leave the organization selector empty. A role added with no organization applies across your whole tree; a role attached to a single organization gives Current exactly that one partner and no error to tell you so.
  3. 3
    3 · Generate the API token and copy it now
    Press Generate API Token. ThreatLocker shows it only while the side panel is open and never again — a lost token has to be regenerated, not recovered. Copy it before you close anything.

Find your instance code

ThreatLocker runs partners on separate portal instances, and a token only works against yours. In the ThreatLocker Portal, click Help in the top right: the short code is in brackets beside the "ThreatLocker Access" heading. It is also the middle part of your portal address. Some codes are a single character and some are longer — European, Australian and Canadian partners have codes like eu1, au1 and ca1 — so copy what you see rather than assuming a letter.

Connect it in Current

  1. 1
    Open the ThreatLocker card
    In Current's left sidebar open Integrations (it sits under Admin, so Tenant Admins have the link) and find ThreatLocker in the Monitoring and security section.
  2. 2
    Enter your instance code and API token
    The instance is the short code from the Help panel. The token is the one you copied when it was generated. Leave the optional top organization id empty unless you have a reason not to — empty means the organization the API user already belongs to, which is what a partner running one ThreatLocker tree wants.
  3. 3
    Press Test connection
    Current asks ThreatLocker for a single organization to prove both halves at once: that the token authenticates against your instance, and that its role can actually see the organization tree everything else is built on. Nothing is stored until that answer comes back. If ThreatLocker refuses, the card shows ThreatLocker's own reason rather than a generic failure. On success the token is stored server-side only — the browser never sees it again.
Heads up
The wrong instance looks exactly like a bad token
There is no global address and no redirect: a perfectly good token sent to the wrong instance fails the same way a wrong token does. Check the instance code against the Help panel before you regenerate anything. Two other paste mistakes look the same: a token copied short, and a token pasted with the word Bearer in front of it. ThreatLocker takes the token on its own.

How often it syncs

The endpoint sync runs every 6 hours on a schedule, plus whenever you press Sync now on the card. Each run walks your organizations and every protected endpoint. The blocked-execution counts and the coverage-gap count run once a day instead: they cost one request per organization each and they answer a question about a whole day, so running them four times over would spend four times the requests on the same answer. If your estate is large, the first few runs may finish part of it and pick up where they left off — the card says so while that is happening.

The read-only guarantee

ThreatLocker's portal API is the same one its own console uses, so the calls that disable protection on a machine, open a maintenance window, approve a blocked application, or delete an organization sit right beside the ones that read data. Current handles that with two belts. The view-only role you created is the outer one: the credential itself has no way to change anything at the vendor. The inner one is an allowlist naming four exact read addresses and nothing else — not a prefix, the whole address, character for character, so no neighbouring call can be reached by accident. Everything else is absent from the code rather than present and uncalled, and that includes reads Current chose not to take: the one that returns your agent deployment key, and the one that lists a partner's live override codes.

Map organizations to your companies

In ThreatLocker each end-customer is an organization, and Current maps every one of them, including organizations nested under a parent. Your own top organization appears in the list too — that is not a bug, and mapping it to your own company record gives you your internal posture alongside everything else.

Note
Names are the only thing to match on
ThreatLocker holds no reference to your PSA anywhere in its data, so unlike some feeds there is no account number to match on — the company name is all there is. Current links an organization to a Current company by normalized name (lowercased, with punctuation and Inc/LLC/Ltd-style suffixes stripped), and only when exactly one company matches. If your ThreatLocker organization names have drifted from your company names, expect to map more of them by hand than you would for other connectors.
  1. 1
    Let the auto-matcher run first
    Every sync links each organization to the one Current company whose normalized name matches. The clear ones map themselves; only the ambiguous ones need a hand.
  2. 2
    Open the mapping panel
    Integrations → ThreatLocker → Manage → Customer mapping. It opens on the Unmapped tab, which lists every organization the matcher could not place.
  3. 3
    Map an organization to its company
    On an unmapped row press Map, type a few letters of the Current company, and pick it. That organization's endpoints attach to the company right away, rather than waiting for the next scheduled sync.
  4. 4
    Ignore internal or test organizations
    For an organization that should never map to a partner — a lab, a demo, a decommissioned tenant — press Ignore. It moves to the Ignored tab and stops counting against the card's unmapped badge.
  5. 5
    Fix a wrong match later
    The Mapped tab lists every linked organization; Unmap corrects a bad auto-match, and the Ignored tab's Un-ignore brings a dismissed one back. A mapping you set by hand is never overwritten by a later auto-match, and neither is a manual unlink.

What unknown means here

ThreatLocker words its enforcement modes its own way, and it can add a new one whenever it likes. When Current does not recognise a mode, that machine is counted as unknown rather than as protected: it is left out of both the enforcing count and the watching-without-blocking count, and the card says how many are in that state. It is the one place where a connector reporting less is the connector working — a workspace reading a clean hundred percent because Current guessed at a word it had never seen would be the worst thing this feed could do. The same rule runs through the rest of it: a machine that has never reported a check-in is counted as unknown rather than as quiet, and a number Current was not able to ask for stays blank rather than showing zero. Zero blocked executions is a real and meaningful state — a well-tuned allowlist genuinely denies nothing on a quiet day — so it is never used to stand in for "we did not ask".

Troubleshooting

What the card saysWhat it meansWhat to do
ThreatLocker rejected these credentials (401)One of three things, in the order worth checking. The instance code is wrong; the token was pasted short; or something was typed in front of the token.Check the instance in the ThreatLocker Portal under Help first — it is the free check and it costs nothing. Then re-copy the token. ThreatLocker takes the token on its own, with nothing in front of it. Regenerating the token is the last thing to try, not the first.
ThreatLocker accepted the token but refused the organization list (403)The token works. The API user's role is missing View Organizations.In the Portal, Manage → Users → API Users, open the role and add View Organizations. Add View Computers and View Unified Audit while you are there — those are the other two reads Current makes.
Current can see your endpoints but not your Unified AuditThe role has View Computers but not View Unified Audit. Everything except the blocked-execution counts is syncing normally.Add View Unified Audit to the role, or leave it: the connector is still useful without it, and the blocked counts stay blank rather than showing a zero Current cannot stand behind.
Only one organization came backA role attached to a single organization instead of being left unscoped. Nothing errors, because from ThreatLocker's side the answer is correct.In the Portal, Manage → Users → API Users, remove the role from the API user and add it back without choosing an organization. Press Sync now afterwards.
ThreatLocker answered 404The address exists but does not serve this account. That is what a wrong instance code looks like.Read the code again from the Help panel in the ThreatLocker Portal, in brackets beside "ThreatLocker Access".
Current didn't recognize some endpoint modesThreatLocker returned a mode Current has no rule for. Those machines are counted as unknown rather than as protected.Nothing is broken and no data is lost — the mode is stored exactly as ThreatLocker sent it. Tell support which modes your workspace uses and the rule is added; the numbers correct themselves on the next sync without a re-sync.
Tip
Disconnecting
Disconnect on the card stops all ThreatLocker syncing. Your already-synced endpoint and organization data is kept — reconnect any time to resume. Nothing is changed in ThreatLocker either way.
Was this helpful?