Ability to Approve newly installed unattended access devices before they are added
If installers get in the wrong hands, unknown unattended access devices are added. This could allow an adversary to gather information about a ScreenConnect instance to potentially attack it. Additionally, it's common to get rogue devices show up. When unattended access is installed, we would like the device to go into a holding position and need approval before it's fully accessible in the system. Our RMM does this and it works well. Ideally, there should be minimal communication with the agent while it's waiting for approval to avoid an adversary mapping things out.
We'd also appreciate this. Even though in theory a rogue machine shouldn't be able to "do anything" in our environment, what's to say some new exploit isn't discovered that these rogue sessions could exploit. Also, it'd be easy for an agent to inadvertently run a bulk command that includes one of these machines with potentially sensitive information, like a password.
I think a lot of admins would prefer that there would be an approval mechanism for new machines added via the unattended installer. Additionally, it'd be good to have a way to essentially invalidate all existing installer builds (i.e. rotate keys) that wouldn't affect existing sessions. Both of these would give admins a lot more peace of mind; both prevention and a remediation method.