Skip to main content

About ManageEngine Endpoint Central (On-Premises)

ManageEngine Endpoint Central (formerly Desktop Central) manages Windows, macOS, and Linux endpoints: it inventories hardware and software, scans for missing patches and vulnerabilities, and deploys patches and software. This integration connects Serval to an Endpoint Central server you host yourself. If you use Endpoint Central Cloud, use the ManageEngine Endpoint Central integration instead; the two share the same API but authenticate differently. The integration is marked Beta in the connect screen, so its capabilities may still change. Authentication: An Endpoint Central authentication key for a dedicated console user. Serval sends it to your server on each request, and workflows never handle it. Access level: You choose what Serval may do when you connect, and Serval enforces it server-side on every request:
  • Read-only reads computers, inventory, patches, vulnerabilities, custom fields, and reports.
  • Full adds approving and deploying patches, scanning computers, managing agents, and editing custom fields.
The key’s Endpoint Central role applies on top of the access level: Serval can never do more than that user can. Data sync: None. Serval calls your server only when a workflow or health check runs.

What the Endpoint Central (On-Premises) integration enables

The read-only access level is enforced by Serval, not just documented: with it selected, Serval refuses any request to your server that isn’t a read, so workflows can’t deploy patches, change agents, or edit custom fields.

Before you connect

Most Endpoint Central servers sit on an internal network that Serval’s cloud can’t reach. Three deployments are possible:
  • Server reachable from the internet: connect normally, nothing extra needed.
  • Self-hosted Serval deployment: works when your deployment is configured to allow internal targets.
  • Serval cloud with a self-hosted worker: Enable Run on self-hosted workers for the connection. Requests then run from your network; the worker must be able to reach the server on its HTTPS port (8383 by default). A read-only connection also needs an up-to-date worker: on an older worker every request fails with a message asking you to upgrade it, because the older worker cannot enforce the read-only boundary per request.
Serval always connects over HTTPS and verifies the server’s certificate. Endpoint Central installs with a self-signed certificate, which fails verification. Either replace it with a certificate from a CA Serval trusts, or, when connecting through a self-hosted worker, pass your internal CA chain to the worker with --ca-certificate when you install or upgrade it. Serval never skips certificate verification.

Get your credentials

1

Create a dedicated user and role

In the Endpoint Central console, go to Admin, then User Administration, and create a user such as svc-serval. Give it a role that grants only the modules your workflows need, for example read access to Scope of Management, Inventory, and Patch Management. For a Full connection, add write access to the modules workflows will change. Make sure the role allows API access.
2

Generate an authentication key

Sign in as that user, go to Admin, then Integrations, then API Explorer, and open Authentication. Choose Local Authentication or AD Authentication to match the account, enter its credentials, and run the login. If two-factor authentication is enabled, complete the one-time-password step. Copy the auth_token value from the response; this is the authentication key.
3

Note your server host

Use the hostname or IP address you use to open the Endpoint Central console, without the “https://” prefix, for example endpointcentral.example.com. The server listens on port 8383 for HTTPS unless your installation changed it.

Connect in Serval

1

Open the integration

In Serval, go to the integrations page and select ManageEngine Endpoint Central (On-Premises) (marked Beta).
2

Enter the Endpoint Central Server Host

Enter the hostname or IP address of your server, for example endpointcentral.example.com. Port 8383 is assumed; add a port only if your server uses a different one.
3

Enter the Authentication Key

Paste the key from the previous section. It’s stored encrypted and shown masked after saving.
4

Choose the Access Level

Select Read-only unless workflows need to deploy patches, manage agents, or edit custom fields. You can change it later in the integration settings.
5

Save, then run the health checks

Saving validates the format of what you entered but doesn’t call your server, because the connect screen can’t reach an internal network even when workflows can. Run the health checks afterward to confirm the key works.

Verifying the connection

If the connection test passes but a module check fails, the key is valid and the user’s role lacks that module.

Gotchas and troubleshooting

The authentication key belongs to the user that generated it. Deleting or disabling that user, or generating a new key for it, invalidates the stored key and requests fail with an authentication error. Generate a new key and update it in the integration settings.
Endpoint Central returns only the computers and data the key’s user can see. When a workflow can’t find a computer you know is managed, check the user’s role and scope before suspecting the connection.
Enter a hostname or an IPv4 address for the server. IPv6 addresses are rejected when you save the connection, because the self-hosted worker’s network rules support IPv4 only.
Endpoint Central MSP uses a different API version and isn’t covered by this integration.
With the Full access level, a workflow can approve and install patches, which can reboot the targeted computers depending on the deployment policy. Scope such workflows to explicit resource IDs, and test them against a small custom group first.
The connect tile is marked Beta, so the available actions may still change.

Need help? Contact support@serval.com for assistance with your ManageEngine Endpoint Central integration.