Integration

Current + ThreatLocker integration

A view-only ThreatLocker feed that brings protected endpoints, enforcement mode, blocked-execution counts and coverage gaps into strategic business reviews.

Michael Baas
Written by the Current MSP team · Reviewed by Michael Baas, Efficiency Engineer, ITPartners+
Last updated September 5, 2026

ThreatLocker is Zero Trust for endpoints: software runs only if it is on the allowlist, and approved software is ringfenced so it can only do what it was approved to do. Current's ThreatLocker integration is a view-only feed into the SBR/QBR module and the company alert band. It reads what ThreatLocker already knows and never writes back.

What the integration does

Current authenticates to ThreatLocker with a view-only API user, walks your organization tree and every protected endpoint every six hours, and reads the blocked-execution totals once a day. The result is staged as evidence for AI-assisted Strategic Business Reviews. Instead of screenshotting the ThreatLocker console the week of the review, the coverage and prevention numbers are already sitting on the company record when you open it.

What data flows

  • Organizations — your ThreatLocker tree, nested organizations included, matched to your Current companies so every signal below lands on the right record.
  • Protected endpoints — machine name and computer group, operating system, agent version, install date, and when each one last checked in.
  • Enforcement mode — what ThreatLocker reports for each machine, stored in its own words, alongside Current's reading of whether that mode is actually blocking or only watching.
  • Blocked executions — how much ThreatLocker denied in the last day and the last week per partner, and how much of that was ringfencing. Counts only.
  • Coverage gaps — how many machines ThreatLocker saw on the network without its agent installed.

The feed is one-way. Current does not disable protection on a machine, open a maintenance window, approve a blocked application, edit or deploy a policy, mint an override code, reboot or upgrade an agent, or create and delete organizations. Those endpoints are not in the connector's code, so they cannot be reached by a bug either. ThreatLocker stays the place where security decisions happen; Current uses the evidence.

Prevention is the number nobody can evidence

Detection feeds report things that got through and had to be caught. ThreatLocker reports things that were never allowed to run, and that is the hardest kind of MSP value to put in front of a partner — because when the product works, nothing happens, and nothing is difficult to charge for. A count of blocked executions is the closest thing there is to a receipt. Set beside the share of machines actually enforcing, it turns your endpoint protection is working from reassurance into a figure, and it sits alongside the detection story rather than replacing it.

Exact addresses, not prefixes

ThreatLocker's portal API is the same one its own console drives, which means the call that disables protection on a machine sits one word away from the call that lists machines. A connector that allowed a whole address prefix would allow both. Current's allowlist names four complete addresses, character for character, and nothing that is not one of them can be reached from the code at all. Two reads Current could have taken are deliberately left out on the same principle: the one that returns your agent deployment key, and the one that lists a partner's live override codes. Being a read is not the test; needing it is. The outer belt is the credential itself — the setup asks for a view-only API user, so nothing at the vendor would accept a write from Current even if one were somehow attempted.

Counts, never the events

Current stores how much ThreatLocker blocked, and never what it blocked. Each denial record names a file path, a process and the person who was working at the time. That is end-user detail, a company record is the wrong place for it, and a busy workspace generates those records by the million every day. Current asks ThreatLocker for the total and keeps the number. The investigation, when someone needs one, belongs in the ThreatLocker portal where the whole record lives.

Unknown reads as unknown

ThreatLocker words its enforcement modes its own way and can add a new one at any time. A mode Current does not recognise is counted as unknown, in neither the enforcing column nor the watching-without-blocking column, and the count of unknowns is shown rather than buried. It is the one place where a connector reporting a smaller number is the connector working correctly: an estate reading a clean hundred percent protected because a word went unrecognised is the worst outcome a security feed can produce. The same rule runs through the rest of it. A machine that has never reported a check-in is unknown rather than quiet. A number Current was not permitted to ask for stays blank rather than reading zero, because zero blocked executions is a real state on a well-tuned allowlist and blank means nobody asked.

The gap nobody is looking at

ThreatLocker also reports machines it can see on a partner's network with no agent installed at all, and Current mirrors that count. It is the rarest kind of integration number: one an account manager can act on the same afternoon. Every one of those machines is outside the protection the partner is paying for, and the conversation writes itself. Aggregated across a book it becomes a pipeline figure rather than a support ticket.

Matching organizations to companies

Each ThreatLocker organization is one end-customer, and organizations nested under a parent are mapped too, so a partner who groups customers under a regional holding organization does not lose them. ThreatLocker holds no reference to any PSA in its data, so the company name is the only thing there is to match on: Current links by normalized name, punctuation and Inc/LLC/Ltd-style suffixes stripped, and only when exactly one company matches. Where two could both be the answer, the organization waits on an unmapped list for a person to decide rather than being paired on a guess. A mapping set by hand is never overwritten by a later automatic match, and mapping an organization attaches its endpoints immediately instead of waiting for the next scheduled sync.

Where the data appears

  • In Strategic Business Reviews, in the security posture chapter alongside your detection feeds such as Huntress and your email-security evidence.
  • On the company record, where the security card shows protected endpoints, how many are enforcing, what was blocked, and how many machines have no agent.
  • In dashboard security metrics, including endpoint coverage and the share of machines actually enforcing.
  • In the company alert band, where a protection gap that has persisted joins the critical-security entry rather than duplicating it.

Why it matters

The prevention half of a security review is the part that goes unsaid, because the evidence for it lives in a console the account manager does not open and the product's success looks like an absence. An MSP running ThreatLocker for a partner like Northwind Traders can open the account and see how many machines are covered, how many are actually enforcing rather than sitting in a watching mode somebody opened months ago and never closed, how much was blocked last quarter, and which machines on that network have no agent at all — without anyone assembling a screenshot pack first. It gives the quietest part of the review a number.

Sources

  1. 1.ThreatLocker Zero Trust endpoint protectionThreatLocker

Keep reading

See it live

Real data. No slideware.

We’ll show you Current on a real book — the pipeline, the dependency engine, the AI briefs, and how time flows straight into your PSA billing.

A 30-minute tour tailored to how your team sells and delivers
Straight answers on Halo, ConnectWise, Autotask, Microsoft 365, and HubSpot sync
A clear path to rolling it out across your team and co-managed clients
Or drop us a note
We'll get right back to you to set up your walkthrough.

We'll only use your details to set up your Current walkthrough.

See our Privacy Policy.