IT Brief Ireland - Technology news for CIOs & IT decision-makers
Corporate it control room endpoint security zero trust monitoring

ManageEngine adds EDR & zero trust to Endpoint Central

Thu, 19th Mar 2026

ManageEngine has added endpoint detection and response (EDR) and secure private access to Endpoint Central, expanding it from endpoint management into a broader security and access platform.

ManageEngine positions Endpoint Central as a unified endpoint management and security tool. The update brings EDR into the same console used for device administration and patching, and adds controls for private access to internal applications based on device trust verification.

Endpoint Central already supports provisioning, configuration, and remote troubleshooting across Windows, macOS, Linux, ChromeOS, and mobile devices. ManageEngine says more than 31,000 organisations use the product worldwide, which is available on premises and as a SaaS service.

Attack surface focus

Endpoints remain a key target as organisations manage larger, more distributed device fleets. Many still rely on separate products for endpoint management, threat protection, and remote access. That split can increase operational overhead and create gaps when teams need to investigate and respond quickly.

ManageEngine also links the spread of AI-assisted techniques to growth in sophisticated attacks such as ransomware. It argues that traditional VPN models can increase risk by granting broad connectivity after authentication rather than restricting access at the level of each application request.

Chirag Mehta, Vice President and Principal Analyst at Constellation Research, said speed has become central to endpoint security as attackers move quickly once they gain access.

"Endpoint security has become a speed problem: enterprises need to detect and contain threats earlier while enforcing Zero Trust access to internal applications when credentials are compromised," Mehta said.

He described combining EDR with device-trust-based access controls as a way to reduce attacker dwell time and limit the impact of endpoint-driven incidents.

"Bringing EDR together with device-trust-based access controls helps shrink attacker dwell time and reduce the blast radius from endpoint-driven incidents," Mehta said.

Single console

ManageEngine says the EDR and secure private access features are natively integrated within Endpoint Central, allowing IT and security teams to work from a shared source of endpoint telemetry and use the same workflows for investigation and action.

The platform uses a single agent and a central console. ManageEngine says that approach can link security detections with endpoint management actions, including patching and configuration changes.

Mathivanan Venkatachalam, Vice President at ManageEngine, described the endpoint as an enforcement point for both detecting threats and controlling access in distributed environments.

"As enterprise environments become more distributed, the endpoint has become the enforcement point for both threat detection and access control," Venkatachalam said.

He said the additions are intended to change how organisations respond to threats and control access to key systems.

"With these capabilities, we're helping organizations shift from reactive security to autonomous resilience-enabling earlier threat detection and faster remediation while ensuring only trusted devices access critical resources," Venkatachalam said.

Feature set

ManageEngine says the new EDR functions provide visibility across processes, files, registry, and network activity. The system maps behaviours to MITRE ATT&CK techniques and presents attacker movement for investigation.

It also uses behavioural analytics and AI for threat detection, including file-less malware and living-off-the-land techniques. From the same console, teams can isolate compromised devices, terminate malicious processes, restore ransomware-encrypted files, and deploy patches.

ManageEngine also offers AI-guided investigation features to surface relevant telemetry and attack patterns for threat hunting and analysis. For access, it says secure private access uses identity-aware policies and evaluates each request, with device trust verification as a control.

Market signals

ManageEngine cited third-party recognition for Endpoint Central's malware protection and management functions. It says the product has AV-Comparatives' Approved Business Product certification, and that the testing organisation reported minimal system performance impact and the second-lowest resource footprint among evaluated solutions.

It also says it was named a Challenger in the 2026 Gartner Magic Quadrant for Endpoint Management Tools and a Leader in the IDC MarketScape: Worldwide Unified Endpoint Management Software 2025-2026 Vendor Assessment. The company added that it was the only vendor recognised as Customers' Choice in the 2025 Gartner Peer Insights Voice of the Customer for Endpoint Management Tools.

The EDR and secure private access functions are available as an add-on for Endpoint Central, which ManageEngine is positioning as a consolidation of endpoint management, security, and application access controls into one platform.