Automated Zscaler Device Enrollment Audit
Every Monday, WebRun signs in to Zscaler, lists the devices enrolled with Client Connector and their last connection status, compares that against your user and group roster, logs every person with no reporting device to Airtable, and writes the week's coverage audit into Notion.
How do I check which employee devices are missing from Zscaler?
Every Monday WebRun signs in to Zscaler, lists the devices enrolled with Client Connector, compares them against your user and group roster, then logs every person without a reporting device to Airtable and writes the coverage audit into Notion, so an unprotected laptop gets found before it is exploited.
- Unprotected laptops are named every Monday instead of found after an incident
- Coverage gaps carry a dated Airtable history you can show an auditor
- Team leads see only the gaps in their own group
Built for security admins · IT operations · compliance leads · managed service providers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
zscaler.comin a real browser with your saved login - no setup, no API keys. -
1
Zscaler - list enrolled devices and status
WebRun opens Zscaler to list enrolled devices and status. - Sign in to your Zscaler admin console and open the enrolled device list
- Capture the user, the device name, the platform, and the last time it connected
- Flag devices that have not checked in inside your tolerance window
- Walk your user groups and note anyone with no enrolled device at all
Done when Every user and device has an enrollment state and a last-seen date recorded.
-
2
Airtable - log the coverage gaps
WebRun opens Airtable to log the coverage gaps. - Open your device coverage base in Airtable and add a row for each gap found
- Record the user, the group, the device, the last-seen date, and the reason it was flagged
- Mark rows resolved when the device starts reporting again on a later run
- Keep the history so you can see whether coverage is improving week to week
Done when Every coverage gap has a dated Airtable row against a named person.
-
3
Notion - write the weekly audit
WebRun opens Notion to write the weekly audit. - Write this week's coverage audit into your security page in Notion
- Lead with the count of users with no enrolled device and the count that stopped reporting
- List the gaps by group so each team lead sees their own people
- Note what changed since last Monday, including gaps that were closed
Done when The security page holds a dated audit with the open gaps by group.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Can it change my Zscaler configuration?
No. WebRun reads the enrollment and status views only. It never edits policy, removes a device, or changes a user, so an audit run can never weaken your protection.
Will it email the people who are not enrolled?
No. WebRun logs the gap in Airtable and writes the audit in Notion. If you want the user contacted, WebRun can draft the note and leave it for an admin to send.
How long can a device be quiet before it is flagged?
You set the window, commonly seven days without a check-in. WebRun measures every device against it and only flags the ones past your threshold.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.