> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Excluding Devices from Vulnerability Management

> Exclude specific devices from vulnerability reporting and notifications in Iru Endpoint. Manage exclusions from a device record or from a CVE Devices tab.

<Callout icon="list-check" color="#71118C" iconType="regular">This guide applies to Mac computers and Windows devices</Callout>

### About Excluding Devices

Some devices in your fleet may not need to be included in vulnerability reporting, such as dedicated test devices, devices assigned to employees on extended leave, or devices undergoing decommissioning. Excluded devices no longer contribute to affected-device counts, detection counts, the CVE **Devices** view, or vulnerability notifications.

Please see our [Vulnerability Management Overview](/en/endpoint/vulnerability-management/vulnerability-management-overview) article for more information about vulnerabilities.

### How It Works

Device exclusion lets you remove specific devices from fleet-wide vulnerability counts, views, and notifications. When you exclude a device, it no longer appears in CVE affected device totals or the **Devices** tab across Vulnerability Management, and vulnerability notifications for that device are suppressed.

Detections remain visible on the device record, so you keep full visibility at the device level without those results affecting top-line reporting. If a [Vulnerability Response Library Item](/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item) is scoped to an excluded device, automated patching continues according to the configured remediation rules.

You can exclude a device from its device record or from the **Devices** tab in any CVE detail view. You can remove an exclusion at any time to resume monitoring. If a device is deleted from Iru Endpoint, its exclusion is removed automatically.

### Excluding a Device

You can exclude a device from the device record in Iru Endpoint or from the **Devices** tab in a CVE detail view.

<Tabs>
  <Tab title="From a device record" icon="laptop">
    <Steps>
      <Step title="Open the device record">
        Navigate to **Devices** in the Iru Endpoint web app and select the device you want to exclude.
      </Step>

      <Step title="Open the device action menu">
        Click the **Device Action Menu** at the top right of the device record.
      </Step>

      <Step title="Start exclusion">
        Click **Exclude device**.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-exclude-device-from-device-record.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=1014c6fe1c9543ad83fa529e5ce1863a" alt="Device Action Menu on a device record with Exclude device option highlighted" width="554" height="1164" data-path="assets/media/images/iru-vulnerabilities-exclude-device-from-device-record.png" />
        </Frame>
      </Step>

      <Step title="Set the timeframe">
        Choose an **Enforcement timeframe**:

        * **Indefinitely** to exclude the device until you remove the exclusion
        * **Ignore until a specific date** to exclude the device until the date you select
      </Step>

      <Step title="Add optional details">
        Optionally, enter a **Ticket** URL and **Comment** to document the reason for exclusion.
      </Step>

      <Step title="Save the exclusion">
        Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-exclude-device-prompt.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=e02ed55909e82c543c80f3496146c8ab" alt="Exclude device dialog with Indefinitely and Ignore until a specific date timeframe options and optional Ticket and Comment fields" width="1004" height="1098" data-path="assets/media/images/iru-vulnerabilities-exclude-device-prompt.png" />
        </Frame>
      </Step>
    </Steps>
  </Tab>

  <Tab title="From a CVE detail view" icon="shield-virus">
    <Steps>
      <Step title="Navigate to Vulnerability Management">
        Go to the **Vulnerability Management** section in the Iru Endpoint web app.
      </Step>

      <Step title="Select the CVE">
        From the **Vulnerabilities** list, select the CVE that includes the device you want to exclude.
      </Step>

      <Step title="Open the Devices tab">
        Select the **Devices** tab if it is not already selected.
      </Step>

      <Step title="Start exclusion">
        Click **Exclude device** (shield icon) for the device you want to exclude.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-exclude-device-from-cve.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=a069560b93ebf15d43067eac422fa5d6" alt="CVE Devices tab showing the Exclude device shield button for a device in the list" width="1958" height="2040" data-path="assets/media/images/iru-vulnerabilities-exclude-device-from-cve.png" />
        </Frame>
      </Step>

      <Step title="Set the timeframe">
        Choose an **Enforcement timeframe**:

        * **Indefinitely** to exclude the device until you remove the exclusion
        * **Ignore until a specific date** to exclude the device until the date you select
      </Step>

      <Step title="Add optional details">
        Optionally, enter a **Ticket** URL and **Comment** to document the reason for exclusion.
      </Step>

      <Step title="Save the exclusion">
        Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-exclude-device-prompt.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=e02ed55909e82c543c80f3496146c8ab" alt="Exclude device dialog with Indefinitely and Ignore until a specific date timeframe options and optional Ticket and Comment fields" width="1004" height="1098" data-path="assets/media/images/iru-vulnerabilities-exclude-device-prompt.png" />
        </Frame>
      </Step>
    </Steps>
  </Tab>
</Tabs>

### Modifying or Removing a Device Exclusion

You can modify or remove an exclusion from the device record or from the **Devices** tab in a CVE detail view.

<Tabs>
  <Tab title="From a device record" icon="laptop">
    <Steps>
      <Step title="Open the device record">
        Navigate to **Devices** in the Iru Endpoint web app and select the excluded device.
      </Step>

      <Step title="Modify or remove the exclusion">
        In the banner near the top of the device record, click **Modify** or **Remove exclusion**.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-modify-or-remove-exclusion.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=246b1a682bf7919f9663fb2993899b56" alt="Device record banner showing Modify and Remove exclusion options for an excluded device" width="2004" height="604" data-path="assets/media/images/iru-vulnerabilities-modify-or-remove-exclusion.png" />
        </Frame>
      </Step>

      <Step title="Modify the exclusion">
        If you clicked **Modify**, update the **Enforcement timeframe**, **Ticket**, or **Comment** as needed, then click **Save**. The dialog matches the one used when you first exclude a device.
      </Step>

      <Step title="Remove the exclusion">
        If you clicked **Remove exclusion**, confirm in the dialog by clicking **Remove exclusion** again.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-remove-exclusion-confirmation.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=de95c6ce0668204963ebfd9f812cfc3b" alt="Remove exclusion confirmation dialog prompting you to confirm before removing the device exclusion" width="1000" height="344" data-path="assets/media/images/iru-vulnerabilities-remove-exclusion-confirmation.png" />
        </Frame>
      </Step>
    </Steps>
  </Tab>

  <Tab title="From a CVE detail view" icon="shield-virus">
    <Steps>
      <Step title="Navigate to Vulnerability Management">
        Go to the **Vulnerability Management** section in the Iru Endpoint web app.
      </Step>

      <Step title="Select the CVE">
        From the **Vulnerabilities** list, select the CVE for the excluded device you want to manage.
      </Step>

      <Step title="Open the Devices tab">
        Select the **Devices** tab if it is not already selected.
      </Step>

      <Step title="Open filter options">
        Click the **Filters** button at the top right of the device list.
      </Step>

      <Step title="Show excluded devices">
        Toggle **Show excluded devices**. Excluded devices appear in the list with an **Excluded** badge.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-show-excluded-devices.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=f7104f741980a4fad50ee61fd57a6398" alt="CVE Devices tab filter options with Show excluded devices toggle enabled and excluded devices listed" width="1662" height="1536" data-path="assets/media/images/iru-vulnerabilities-show-excluded-devices.png" />
        </Frame>
      </Step>

      <Step title="Modify or remove the exclusion">
        For an excluded device, use **Modify exclusion** (pencil icon) or **Remove exclusion** (shield-off icon).
      </Step>

      <Step title="Modify the exclusion">
        If you are modifying the exclusion, click **Modify exclusion**, update the **Enforcement timeframe**, **Ticket**, or **Comment** as needed, then click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-cve-modify-exclusion.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=a5e3031e725d6ef5efe88ee929dfc2ad" alt="Modify exclusion pencil icon on an excluded device in the CVE Devices tab" width="1626" height="302" data-path="assets/media/images/iru-vulnerabilities-cve-modify-exclusion.png" />
        </Frame>
      </Step>

      <Step title="Remove the exclusion">
        If you are removing the exclusion, click **Remove exclusion** (shield-off icon).

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-cve-remove-exclusion.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=7e89039f302c269cd255dc42a8f40450" alt="Remove exclusion shield-off icon on an excluded device in the CVE Devices tab" width="1626" height="304" data-path="assets/media/images/iru-vulnerabilities-cve-remove-exclusion.png" />
        </Frame>
      </Step>

      <Step title="Confirm the removal">
        In the confirmation dialog, click **Remove exclusion** again.

        <Frame>
          <img src="https://mintcdn.com/iru/ucyRxmJ2-RMgR7Fj/assets/media/images/iru-vulnerabilities-remove-exclusion-confirmation.png?fit=max&auto=format&n=ucyRxmJ2-RMgR7Fj&q=85&s=de95c6ce0668204963ebfd9f812cfc3b" alt="Remove exclusion confirmation dialog prompting you to confirm before removing the device exclusion" width="1000" height="344" data-path="assets/media/images/iru-vulnerabilities-remove-exclusion-confirmation.png" />
        </Frame>
      </Step>
    </Steps>
  </Tab>
</Tabs>

After you remove an exclusion, the device is included again in vulnerability scanning at the next scan cycle.

### Considerations

<CardGroup cols={2}>
  <Card title="Scope of exclusion" icon="circle-minus">
    Excluding a device removes it from all CVE affected device counts across every vulnerability in Vulnerability Management. Exclusion is not scoped to a single CVE. Vulnerability detections remain visible on the device record. Exclusion affects top-level Vulnerability Management counts, views, and notifications only. To suppress a specific CVE without excluding the device entirely, use [Accepting CVE Risks](/en/endpoint/vulnerability-management/accepting-cve-risks) instead.
  </Card>

  <Card title="Vulnerability Response" icon="shield-virus">
    If a [Vulnerability Response Library Item](/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item) is scoped to an excluded device, it continues to patch the device according to the configured remediation rules. Exclusion does not prevent automated remediation.
  </Card>

  <Card title="Deleted devices" icon="trash">
    If a device is deleted from Iru Endpoint, its exclusion is removed automatically. If the same device re-enrolls, it is monitored by default. Re-apply the exclusion manually if needed.
  </Card>

  <Card title="CVE status and remediation counts" icon="chart-line">
    An excluded device does not count toward the affected-device total for any CVE. Excluding a device does not change the **Remediated** status of a CVE by itself. Remediation status is based on active (non-excluded) devices only. If excluding a device means all remaining affected devices for a CVE are remediated, the CVE status updates to **Remediated**.
  </Card>

  <Card title="Visibility" icon="eye">
    Excluded devices are not hidden from the **Devices** section of Iru Endpoint. They are hidden from Vulnerability Management views and counts only. Exclusions are auditable. Each exclusion records who applied it, when, and any comment provided.
  </Card>

  <Card title="Notifications" icon="bell">
    Vulnerability notifications for excluded devices are suppressed while the exclusion is active. Removing an exclusion resumes notifications at the next scan cycle.
  </Card>
</CardGroup>

### Related Articles

<CardGroup cols={2}>
  <Card title="Vulnerability Management Overview" icon="info-circle" href="/en/endpoint/vulnerability-management/vulnerability-management-overview">
    Detect CVEs across your fleet, prioritize by severity, and track remediation progress
  </Card>

  <Card title="Accepting CVE Risks" icon="shield" href="/en/endpoint/vulnerability-management/accepting-cve-risks">
    Accept CVE risks when patching is not feasible, set expiration dates, and track exceptions
  </Card>

  <Card title="Configure the Vulnerability Response Library Item" icon="cog" href="/en/endpoint/vulnerability-management/configure-the-vulnerability-response-library-item">
    Automate remediation for vulnerable Auto Apps on macOS based on CVE severity
  </Card>
</CardGroup>
