- approve the direct connection;
- ask the owner to move it behind Passport;
- allow it temporarily; or
- ask the owner to remove it.
Review the action queue
Open Discover. The action queue appears first and groups the same MCP found in several clients into one decision. For each item, review:- who owns it and how they described its purpose;
- which supported clients contain it;
- whether Passport can guide a safe move; and
- the current admin decision.
What happens on a member’s computer
Passport Desktop scans only after the member enables Discover. For a supported remote connection, Desktop can guide a move behind Passport. Before changing anything, it checks that the reviewed entry, the governed replacement, and the client’s app selection still match. It creates a backup, changes only the reviewed entry, and verifies the result. If an admin asks for removal, the member can use the same reviewed backup-and-verify flow without creating a replacement. Passport never silently edits the file.Coverage and Fleet policy
The Discover page shows reporting computers and supported client sources. Project-level configuration, hosted clients, and computers without Passport Desktop discovery or the managed scanner are outside coverage. Choose Fleet policy in the page header to switch between:- Personal · opt-in — each member decides whether Desktop scans.
- Managed fleet — administrators deploy the scanner through endpoint management.
Managed scanner
For a managed Windows, Linux, or macOS fleet, schedule:
Your endpoint-management system decides what to do with exit code
5, such as notify, quarantine, or start its own remediation. Passport does not silently edit a managed device.
Managed mode does not turn on Desktop scanning. Use
passport discover for administrator-deployed reporting; Desktop remains controlled by the member.