Portal · Coverage
Coverage
Confirm which devices, capture paths, and connected sources are current before interpreting Portal trends.
- Capture pathsActive, inactive, or not configured
- Connected sourcesCurrent, inactive, or needs authorization
- Actionable gapsEach issue points to its recovery path
Coverage before conclusions
Coverage is the confidence check for every other Portal view. It separates a real change in AI use from a change in what Cortex can observe.
Read the Coverage cards
Capture pathsActive in the last 24 hours
Connected sourcesCurrent authorization
RemediationGaps with an available fix
Resolve a gap
| What you see | Where to go |
|---|---|
| Device never reported | Deployment and Defender sign-in |
| Device stopped reporting | Defender health and troubleshooting |
| Capture path not configured | Supported AI tools and source setup |
| Browser missing, CLI present | Browser routing and certificate setup |
| Connected source needs authorization | Workplace connections |
Work one row at a time. Restoring one device or source can clear several downstream gaps.
Before comparing trends
- Confirm the expected number of devices is reporting.
- Confirm the relevant capture paths were active for both periods.
- Confirm app connections are current when the analysis depends on organization context.
- Keep visibility and date range consistent.
A lower Portal total can mean less activity or less coverage. Coverage tells you which interpretation is supported.
Fix the underlying path
Was this helpful?