> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Excluding Devices from Vulnerability Management

> Exclude devices from vulnerability reporting in Iru Endpoint. Manage CVE exclusions individually or in bulk from a device record, Devices page, or CVE tab.

<Callout icon="list-check" color="#71118C" iconType="regular">This guide applies to Mac computers and Windows devices</Callout>

### About Excluding Devices

Some devices in your fleet may not need to be included in vulnerability reporting, such as dedicated test devices, devices assigned to employees on extended leave, or devices undergoing decommissioning. Excluded devices no longer contribute to affected-device counts, detection counts, the CVE **Devices** view, or vulnerability notifications.

Please see our [Vulnerability Management Overview](/en/endpoint/vulnerability-management/vulnerability-management-overview) article for more information about vulnerabilities.

### How It Works

Device exclusion lets you remove specific devices from fleet-wide vulnerability counts, views, and notifications. When you exclude a device, it no longer appears in CVE affected device totals or the **Devices** tab across Vulnerability Management, and vulnerability notifications for that device are suppressed.

Detections remain visible on the device record, so you keep full visibility at the device level without those results affecting top-line reporting. If a [Vulnerability Response Library Item](/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item) is scoped to an excluded device, automated patching continues according to the configured remediation rules.

You can exclude a device from its device record or from the **Devices** tab in any CVE detail view. From the **Devices** page or a CVE **Devices** tab, you can also exclude or remove exclusions for multiple devices at once. You can remove an exclusion at any time to resume monitoring. If a device is deleted from Iru Endpoint, its exclusion is removed automatically.

### Excluding a Device

You can exclude a device from the device record in Iru Endpoint or from the **Devices** tab in a CVE detail view.

<Tabs>
  <Tab title="From a device record" icon="laptop">
    <Steps>
      <Step title="Open the device record">
        Navigate to **Devices** in the Iru Endpoint web app and select the device you want to exclude.
      </Step>

      <Step title="Open the device action menu">
        Click the **Device Action Menu** at the top right of the device record.
      </Step>

      <Step title="Start exclusion">
        Click **Exclude device vulnerabilities**.

        <Frame>
          <img src="https://mintcdn.com/iru/K5AidOLrQTWuBHR4/assets/media/images/iru-vulnerabilities-exclude-device-from-device-record.png?fit=max&auto=format&n=K5AidOLrQTWuBHR4&q=85&s=4c598f99cddf8c406256f62d2f28b593" alt="Device Action Menu on a device record with Exclude device vulnerabilities option highlighted" width="574" height="1050" data-path="assets/media/images/iru-vulnerabilities-exclude-device-from-device-record.png" />
        </Frame>
      </Step>

      <Step title="Set the timeframe">
        Choose an **Enforcement timeframe**:

        * **Indefinitely** to exclude the device until you remove the exclusion
        * **Ignore until a specific date** to exclude the device until the date you select
      </Step>

      <Step title="Add optional details">
        Optionally, enter a **Ticket** URL and **Comment** to document the reason for exclusion.
      </Step>

      <Step title="Save the exclusion">
        Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-exclude-device-prompt.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=e02ed55909e82c543c80f3496146c8ab" alt="Exclude device vulnerabilities dialog with Indefinitely and Ignore until a specific date timeframe options and optional Ticket and Comment fields" width="1004" height="1098" data-path="assets/media/images/iru-vulnerabilities-exclude-device-prompt.png" />
        </Frame>
      </Step>
    </Steps>
  </Tab>

  <Tab title="From a CVE detail view" icon="shield-virus">
    <Steps>
      <Step title="Navigate to Vulnerability Management">
        Go to the **Vulnerability Management** section in the Iru Endpoint web app.
      </Step>

      <Step title="Select the CVE">
        From the **Vulnerabilities** list, select the CVE that includes the device you want to exclude.
      </Step>

      <Step title="Open the Devices tab">
        Select the **Devices** tab.
      </Step>

      <Step title="Open the device menu">
        Click the **ellipsis** (**…**) next to the device you want to exclude.
      </Step>

      <Step title="Start exclusion">
        Click **Exclude device vulnerabilities**.

        <Frame>
          <img src="https://mintcdn.com/iru/K5AidOLrQTWuBHR4/assets/media/images/iru-vulnerabilities-exclude-device-from-cve.png?fit=max&auto=format&n=K5AidOLrQTWuBHR4&q=85&s=cf424a5ac976cd206a636d18e3082e4a" alt="CVE Devices tab showing the ellipsis menu with Exclude device vulnerabilities for a device in the list" width="1584" height="1052" data-path="assets/media/images/iru-vulnerabilities-exclude-device-from-cve.png" />
        </Frame>
      </Step>

      <Step title="Set the timeframe">
        Choose an **Enforcement timeframe**:

        * **Indefinitely** to exclude the device until you remove the exclusion
        * **Ignore until a specific date** to exclude the device until the date you select
      </Step>

      <Step title="Add optional details">
        Optionally, enter a **Ticket** URL and **Comment** to document the reason for exclusion.
      </Step>

      <Step title="Save the exclusion">
        Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-exclude-device-prompt.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=e02ed55909e82c543c80f3496146c8ab" alt="Exclude device vulnerabilities dialog with Indefinitely and Ignore until a specific date timeframe options and optional Ticket and Comment fields" width="1004" height="1098" data-path="assets/media/images/iru-vulnerabilities-exclude-device-prompt.png" />
        </Frame>
      </Step>
    </Steps>
  </Tab>
</Tabs>

### Excluding Multiple Devices

You can exclude multiple devices at once from the **Devices** page or from the **Devices** tab in a CVE detail view.

<Tabs>
  <Tab title="From the Devices page" icon="laptop">
    <Steps>
      <Step title="Open the Devices page">
        Navigate to **Devices** in the Iru Endpoint web app.
      </Step>

      <Step title="Select devices">
        Select the checkboxes next to the devices you want to exclude.
      </Step>

      <Step title="Open the bulk action menu">
        Click the **ellipsis** (**…**) in the bulk action bar at the bottom of the list.
      </Step>

      <Step title="Start exclusion">
        Click **Exclude device vulnerabilities**.

        <Frame>
          <img src="https://mintcdn.com/iru/K5AidOLrQTWuBHR4/assets/media/images/iru-vulnerabilities-cve-bulk-exclude-from-devices.png?fit=max&auto=format&n=K5AidOLrQTWuBHR4&q=85&s=698bd514536e38ce01e74460f40b433e" alt="Devices page with multiple devices selected and Exclude device vulnerabilities in the bulk action menu" width="2216" height="1142" data-path="assets/media/images/iru-vulnerabilities-cve-bulk-exclude-from-devices.png" />
        </Frame>
      </Step>

      <Step title="Set the timeframe">
        Choose an **Enforcement timeframe**:

        * **Indefinitely** to exclude the devices until you remove the exclusions
        * **Ignore until a specific date** to exclude the devices until the date you select
      </Step>

      <Step title="Add optional details">
        Optionally, enter a **Ticket** URL and **Comment** to document the reason for exclusion. These details apply to all selected devices.
      </Step>

      <Step title="Save the exclusion">
        Click **Save**.
      </Step>
    </Steps>
  </Tab>

  <Tab title="From a CVE detail view" icon="shield-virus">
    <Steps>
      <Step title="Navigate to Vulnerability Management">
        Go to the **Vulnerability Management** section in the Iru Endpoint web app.
      </Step>

      <Step title="Select the CVE">
        From the **Vulnerabilities** list, select the CVE that includes the devices you want to exclude.
      </Step>

      <Step title="Open the Devices tab">
        Select the **Devices** tab.
      </Step>

      <Step title="Select devices">
        Select the checkboxes next to the devices you want to exclude.
      </Step>

      <Step title="Start exclusion">
        Click **Exclude device vulnerabilities** in the bulk action bar at the bottom of the list.

        <Frame>
          <img src="https://mintcdn.com/iru/K5AidOLrQTWuBHR4/assets/media/images/iru-vulnerabilities-bulk-exclude-device-from-cve.png?fit=max&auto=format&n=K5AidOLrQTWuBHR4&q=85&s=1265c20b259dfc03faac5d58ef94f36a" alt="CVE Devices tab with multiple devices selected and Exclude device vulnerabilities in the bulk action bar" width="1598" height="1554" data-path="assets/media/images/iru-vulnerabilities-bulk-exclude-device-from-cve.png" />
        </Frame>
      </Step>

      <Step title="Set the timeframe">
        Choose an **Enforcement timeframe**:

        * **Indefinitely** to exclude the devices until you remove the exclusions
        * **Ignore until a specific date** to exclude the devices until the date you select
      </Step>

      <Step title="Add optional details">
        Optionally, enter a **Ticket** URL and **Comment** to document the reason for exclusion. These details apply to all selected devices.
      </Step>

      <Step title="Save the exclusion">
        Click **Save**.
      </Step>
    </Steps>
  </Tab>
</Tabs>

### Modifying or Removing a Device Exclusion

You can modify or remove an exclusion from the device record or from the **Devices** tab in a CVE detail view.

<Tabs>
  <Tab title="From a device record" icon="laptop">
    <Steps>
      <Step title="Open the device record">
        Navigate to **Devices** in the Iru Endpoint web app and select the excluded device.
      </Step>

      <Step title="Modify the exclusion">
        In the banner near the top of the device record, click **Modify**. Update the **Enforcement timeframe**, **Ticket**, or **Comment** as needed, then click **Save**. The dialog matches the one used when you first exclude a device.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-modify-or-remove-exclusion.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=246b1a682bf7919f9663fb2993899b56" alt="Device record banner showing Modify and Remove exclusion options for an excluded device" width="2004" height="604" data-path="assets/media/images/iru-vulnerabilities-modify-or-remove-exclusion.png" />
        </Frame>
      </Step>

      <Step title="Remove the exclusion">
        In the banner near the top of the device record, click **Remove exclusion**. In the confirmation dialog, click **Remove exclusion** again.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-remove-exclusion-confirmation.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=de95c6ce0668204963ebfd9f812cfc3b" alt="Remove exclusion confirmation dialog prompting you to confirm before removing the device exclusion" width="1000" height="344" data-path="assets/media/images/iru-vulnerabilities-remove-exclusion-confirmation.png" />
        </Frame>
      </Step>
    </Steps>
  </Tab>

  <Tab title="From a CVE detail view" icon="shield-virus">
    <Steps>
      <Step title="Navigate to Vulnerability Management">
        Go to the **Vulnerability Management** section in the Iru Endpoint web app.
      </Step>

      <Step title="Select the CVE">
        From the **Vulnerabilities** list, select the CVE for the excluded device you want to manage.
      </Step>

      <Step title="Open the Devices tab">
        Select the **Devices** tab.
      </Step>

      <Step title="Open filter options">
        Click the **Filters** button at the top right of the device list.
      </Step>

      <Step title="Show excluded devices">
        Toggle **Show excluded devices**. Excluded devices appear in the list with an **Excluded** badge.

        <Frame>
          <img src="https://mintcdn.com/iru/K5AidOLrQTWuBHR4/assets/media/images/iru-vulnerabilities-show-excluded-devices.png?fit=max&auto=format&n=K5AidOLrQTWuBHR4&q=85&s=163d69190989de516411b651a94d79fb" alt="CVE Devices tab filter options with Show excluded devices toggle enabled and excluded devices listed" width="1598" height="1544" data-path="assets/media/images/iru-vulnerabilities-show-excluded-devices.png" />
        </Frame>
      </Step>

      <Step title="Open the device menu">
        Click the **ellipsis** (**…**) next to the excluded device you want to modify.
      </Step>

      <Step title="Modify the exclusion">
        Click **Modify exclusion**. Update the **Enforcement timeframe**, **Ticket**, or **Comment** as needed, then click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/K5AidOLrQTWuBHR4/assets/media/images/iru-vulnerabilities-cve-modify-exclusion.png?fit=max&auto=format&n=K5AidOLrQTWuBHR4&q=85&s=3c80d03494ad0f4b8b8a5b18625293de" alt="Ellipsis menu showing Modify exclusion for an excluded device in the CVE Devices tab" width="1590" height="1540" data-path="assets/media/images/iru-vulnerabilities-cve-modify-exclusion.png" />
        </Frame>
      </Step>

      <Step title="Open the device menu">
        Click the **ellipsis** (**…**) next to the excluded device you want to remove.
      </Step>

      <Step title="Remove the exclusion">
        Click **Remove exclusion**.

        <Frame>
          <img src="https://mintcdn.com/iru/K5AidOLrQTWuBHR4/assets/media/images/iru-vulnerabilities-cve-remove-exclusion.png?fit=max&auto=format&n=K5AidOLrQTWuBHR4&q=85&s=0e8fb9a7e84a6b9e12d9a1c9fa9071f8" alt="Ellipsis menu showing Remove exclusion for an excluded device in the CVE Devices tab" width="1590" height="1540" data-path="assets/media/images/iru-vulnerabilities-cve-remove-exclusion.png" />
        </Frame>
      </Step>

      <Step title="Confirm the removal">
        In the confirmation dialog, click **Remove exclusion** again.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-remove-exclusion-confirmation.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=de95c6ce0668204963ebfd9f812cfc3b" alt="Remove exclusion confirmation dialog prompting you to confirm before removing the device exclusion" width="1000" height="344" data-path="assets/media/images/iru-vulnerabilities-remove-exclusion-confirmation.png" />
        </Frame>
      </Step>
    </Steps>
  </Tab>
</Tabs>

After you remove an exclusion, the device is included again in vulnerability scanning at the next scan cycle.

### Removing Multiple Device Exclusions

You can remove exclusions from multiple devices at once from the **Devices** page or from the **Devices** tab in a CVE detail view.

<Tabs>
  <Tab title="From the Devices page" icon="laptop">
    <Steps>
      <Step title="Open the Devices page">
        Navigate to **Devices** in the Iru Endpoint web app.
      </Step>

      <Step title="Select excluded devices">
        Select the checkboxes next to the excluded devices whose exclusions you want to remove.
      </Step>

      <Step title="Open the bulk action menu">
        Click the **ellipsis** (**…**) in the bulk action bar at the bottom of the list.
      </Step>

      <Step title="Remove the exclusions">
        Click **Remove exclusion**.

        <Frame>
          <img src="https://mintcdn.com/iru/K5AidOLrQTWuBHR4/assets/media/images/iru-vulnerabilities-cve-bulk-remove-exclusion-from-devices.png?fit=max&auto=format&n=K5AidOLrQTWuBHR4&q=85&s=ba65936b282c0f0c552095304bebf34c" alt="Devices page with multiple excluded devices selected and Remove exclusion in the bulk action menu" width="2214" height="1136" data-path="assets/media/images/iru-vulnerabilities-cve-bulk-remove-exclusion-from-devices.png" />
        </Frame>
      </Step>

      <Step title="Confirm the removal">
        In the confirmation dialog, click **Remove exclusion** again.
      </Step>
    </Steps>
  </Tab>

  <Tab title="From a CVE detail view" icon="shield-virus">
    <Steps>
      <Step title="Navigate to Vulnerability Management">
        Go to the **Vulnerability Management** section in the Iru Endpoint web app.
      </Step>

      <Step title="Select the CVE">
        From the **Vulnerabilities** list, select the CVE for the excluded devices you want to manage.
      </Step>

      <Step title="Open the Devices tab">
        Select the **Devices** tab.
      </Step>

      <Step title="Open filter options">
        Click the **Filters** button at the top right of the device list.
      </Step>

      <Step title="Show excluded devices">
        Toggle **Show excluded devices**. Excluded devices appear in the list with an **Excluded** badge.

        <Frame>
          <img src="https://mintcdn.com/iru/K5AidOLrQTWuBHR4/assets/media/images/iru-vulnerabilities-show-excluded-devices.png?fit=max&auto=format&n=K5AidOLrQTWuBHR4&q=85&s=163d69190989de516411b651a94d79fb" alt="CVE Devices tab filter options with Show excluded devices toggle enabled and excluded devices listed" width="1598" height="1544" data-path="assets/media/images/iru-vulnerabilities-show-excluded-devices.png" />
        </Frame>
      </Step>

      <Step title="Select excluded devices">
        Select the checkboxes next to the excluded devices whose exclusions you want to remove.
      </Step>

      <Step title="Remove the exclusions">
        Click **Remove exclusion** in the bulk action bar at the bottom of the list.

        <Frame>
          <img src="https://mintcdn.com/iru/K5AidOLrQTWuBHR4/assets/media/images/iru-vulnerabilities-cve-bulk-remove-exclusion.png?fit=max&auto=format&n=K5AidOLrQTWuBHR4&q=85&s=6cd6a4f520335e8e76af6217c73de31d" alt="CVE Devices tab with multiple excluded devices selected and Remove exclusion in the bulk action bar" width="1570" height="1538" data-path="assets/media/images/iru-vulnerabilities-cve-bulk-remove-exclusion.png" />
        </Frame>
      </Step>

      <Step title="Confirm the removal">
        In the confirmation dialog, click **Remove exclusion** again.
      </Step>
    </Steps>
  </Tab>
</Tabs>

After you remove exclusions, the devices are included again in vulnerability scanning at the next scan cycle.

### Considerations

<CardGroup cols={2}>
  <Card title="Scope of exclusion" icon="circle-minus">
    Excluding a device removes it from all CVE affected device counts across every vulnerability in Vulnerability Management. Exclusion is not scoped to a single CVE. Vulnerability detections remain visible on the device record. Exclusion affects top-level Vulnerability Management counts, views, and notifications only. To suppress a specific CVE without excluding the device entirely, use [Accepting CVE Risks](/en/endpoint/vulnerability-management/accepting-cve-risks) instead.
  </Card>

  <Card title="Vulnerability Response" icon="shield-virus">
    If a [Vulnerability Response Library Item](/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item) is scoped to an excluded device, it continues to patch the device according to the configured remediation rules. Exclusion does not prevent automated remediation.
  </Card>

  <Card title="Deleted devices" icon="trash">
    If a device is deleted from Iru Endpoint, its exclusion is removed automatically. If the same device re-enrolls, it is monitored by default. Re-apply the exclusion manually if needed.
  </Card>

  <Card title="CVE status and remediation counts" icon="chart-line">
    An excluded device does not count toward the affected-device total for any CVE. Excluding a device does not change the **Remediated** status of a CVE by itself. Remediation status is based on active (non-excluded) devices only. If excluding a device means all remaining affected devices for a CVE are remediated, the CVE status updates to **Remediated**.
  </Card>

  <Card title="Visibility" icon="eye">
    Excluded devices are not hidden from the **Devices** section of Iru Endpoint. They are hidden from Vulnerability Management views and counts only. Exclusions are auditable. Each exclusion records who applied it, when, and any comment provided.
  </Card>

  <Card title="Notifications" icon="bell">
    Vulnerability notifications for excluded devices are suppressed while the exclusion is active. Removing an exclusion resumes notifications at the next scan cycle.
  </Card>
</CardGroup>

### Related Articles

<CardGroup cols={2}>
  <Card title="Vulnerability Management Overview" icon="info-circle" href="/en/endpoint/vulnerability-management/vulnerability-management-overview">
    Detect CVEs across your fleet, prioritize by severity, and track remediation progress
  </Card>

  <Card title="Accepting CVE Risks" icon="shield" href="/en/endpoint/vulnerability-management/accepting-cve-risks">
    Accept CVE risks when patching is not feasible, set expiration dates, and track exceptions
  </Card>

  <Card title="Configure the Vulnerability Response Library Item" icon="cog" href="/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item">
    Automate remediation for vulnerable Auto Apps on macOS based on CVE severity
  </Card>
</CardGroup>
