Every pill and badge on the device page
The row of pills across the top of a device page is a summary of everything you would otherwise go looking for: whether the machine is reachable, what it is, whether you can drive Windows security prompts on it, who it belongs to and what it has been marked as.
They are all read-only. A pill is telling you something the agent reported or something you set elsewhere; none of them are buttons.
The pills, in the order they appear
| Pill | What it means |
|---|---|
| online / offline | Whether the agent has a live connection right now. This is the one that gates everything else: Connect, the terminal, the file explorer, processes and services all need it green. It is not the same as the machine being switched on, though in practice it usually is. |
| archived | The device has been archived: hidden from the working device list and moved to Archive, keeping all of its history, inventory and score. Shown only on archived devices. Restore from the Actions menu puts it back exactly as it was. |
| windows/amd64 | The OS family and the CPU architecture the agent reports, for example windows/amd64 or linux/arm64. Always present, because the agent knows this before it knows anything else. |
| Server | The product type, as the platform reports it: Server, Workstation and so on. It comes from the inventory rather than the agent's first handshake, so it is absent on a machine that has not reported one yet, and absent for good on platforms that do not have the notion. |
| UAC available / UAC unavailable | Windows only, and only while the device is online. Available means the agent's session is hosted by an elevated or SYSTEM process, so Windows security prompts are visible to you and can be driven from a remote session. Unavailable means it is hosted by a standard-user process: UAC prompts will not appear on your screen, and anything needing admin rights will appear to hang or fail until the session is elevated. |
| Acme Ltd | The device's group, if it is in one. One group per device. See groups and tags. |
| needs-reboot | One chip per tag, in the tag's own colour. A device carries as many as you like. Tags are also matched by the device list's search box, so a tag name is a quick way to pull up everything wearing it. |
Two more you will meet on the device list
| Pill | What it means |
|---|---|
| quick support | An attended quick-support session rather than an enrolled machine. The row disappears when the session ends, and the usual per-row tools are not offered on it. |
| connected | On the Manage tab, that the shared management channel to the agent is open. If this is not green, the terminal and the other panes have nothing to talk to. |
The line under the heading
Below the pills runs a single quiet line of facts. Reading left to right: the agent version, the machine's public IP and its LAN address where the two differ, last seen, and how old the inventory is. On an online machine it finishes with runs as and the account hosting the agent's session, with its Windows integrity level in brackets, which is the detail behind the UAC pill.
Agent version badges
| Badge | What it means | What to do |
|---|---|---|
| An arrow in a circle, beside the version | A newer agent build is published than the one this machine is running. It appears next to the version on the device page, in the device list and in the Agent card. | Nothing urgent. Agents do not update themselves; use Update agent in the Actions menu for one machine, or Update agents on the Groups page to authorise a whole group. |
| waiting to update | In the device list: the machine has been authorised to take the published build and has not done it yet. | Wait. Online machines act within moments; the rest update when they next connect. The authorisation lasts 24 hours. |
| updating | The update is in progress. | Wait. The device drops off and reconnects on the new build. |
| update failed, reverted, rollback failed | The update did not take. Reverted means the agent put the previous binary back on its own, which is the safe outcome. | Read the detail beside the label and the device's Logs tab. Reinstall from the Actions menu is the blunt fix. |
| held at 0.1.42 | A versioned rollback is pinning this device to one exact release. It will take no other build, including the latest, until the hold is lifted. | Clear version hold in the Actions menu returns it to normal updates. |
The tabs
| Tab | What is on it | Needs the device online |
|---|---|---|
| Overview | Security score, Microsoft Defender status on Windows, operating system, one card per disk with a usage bar, and the Agent card carrying the device ID, addresses, display status and enrolment date. | No |
| Hardware | CPU, memory, motherboard and the rest of what the inventory found. | No |
| Manage | Terminal, file explorer, processes and services. See connect and manage. | Yes |
| Screenshots | Pictures captured from remote sessions, kept with the device. | No |
| Logs | The agent's stored log. Deliberately a top-level tab rather than part of Manage, because a log matters most when the agent is unreachable. | No |
| Software | Installed packages, with the count in the tab label. | No |
| Users | Local user accounts, with the count in the tab label. | No |
| Network | Interfaces and addresses, with the count in the tab label. | No |
The Actions menu
| Action | What it does |
|---|---|
| Edit | Display name, group, tags and notes. The display name is an alias: clear it and the machine goes back to showing its hostname. |
| Refresh inventory | Asks the agent to collect and report now, rather than waiting for its schedule. |
| Update agent | Authorises and prompts this one machine to take the published build now. |
| Roll back | Returns the machine to the previous binary kept on it, or to any archived release. This sets a version hold. |
| Clear version hold | Lifts that hold. Shown only while one is in place. |
| Archive / Restore | Hides a decommissioned machine from the working list while keeping everything about it, and puts it back. |
| Reinstall | Admins only. Gives you a command that replaces the agent binary while keeping the device's identity, so the page stays the same one. |
| Forget | Admins only, and permanent. Requires typing the device name to confirm. |
Also in the header: Restart agent, which drops the device off the dashboard and brings it back a moment later, and the circular refresh button, which reloads the details and the score without reloading the page.
Moorfox is remote monitoring and management without the enterprise tax.
One agent, one dashboard, remote desktop and a real terminal on every machine you look after.