> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rad.security/llms.txt
> Use this file to discover all available pages before exploring further.

# Iru

> Configure the Iru Endpoint Management integration with RAD Security to ingest device inventory and compliance findings, and trigger device remediation.

# Iru Endpoint Management Integration Setup

This guide walks you through integrating Iru with RAD Security to ingest managed-device inventory and device compliance findings, and to trigger remediation on a device from RAD.

Iru is an endpoint management platform. RAD Security connects to the Iru API using an API token and pulls device inventory and compliance posture on a scheduled basis to correlate them with your runtime, cloud, and Kubernetes security data.

<Info>
  **Read-only ingestion, with one write action:** RAD only reads device inventory and compliance from Iru. The single exception is **device remediation** — RAD can trigger a remediation action on a device through Iru. That action is RBAC-gated (requires tenant write permission) and recorded as an OCSF Device Control Finding.
</Info>

## Prerequisites

Before you begin, ensure you have:

<Check>
  * An Iru account with API access
  * Permission to create an API token in Iru
  * Your Iru **API URL** (the base URL of your Iru API)
  * Access to a RAD Security workspace with integration permissions
</Check>

## Understanding Integration Components

<AccordionGroup>
  <Accordion title="API Token" icon="key">
    RAD Security authenticates to the Iru API using an **API token** generated in your Iru account. The token is stored as a secret and never returned by RAD.
  </Accordion>

  <Accordion title="API URL" icon="globe">
    The **API URL** is the base URL of your Iru API endpoint. It is required so RAD targets the correct Iru deployment. Obtain it from your Iru account or administrator.
  </Accordion>

  <Accordion title="Scheduled Polling" icon="clock">
    RAD Security ingests Iru device inventory and compliance via scheduled polling. Data arrives on RAD's polling cadence rather than being pushed by Iru.
  </Accordion>
</AccordionGroup>

***

## Step 1: Create an API Token in Iru

<Steps>
  <Step title="Sign in to the Iru Console">
    Log in to the Iru console with an account that has permission to manage API access.
  </Step>

  <Step title="Generate an API Token">
    Navigate to the API / access settings and create a new API token. Copy its value.

    <Warning>
      Copy the **API Token** immediately. It is typically shown only once at creation time. Store it securely in a password manager or secrets vault.
    </Warning>
  </Step>

  <Step title="Note Your API URL">
    Record the **API URL** (base URL) for your Iru deployment.
  </Step>
</Steps>

<Note>
  Exact console navigation and labels may vary across Iru versions. Consult your Iru documentation or administrator for the current steps to create an API token and confirm your API URL.
</Note>

***

## Configure in RAD Security

Navigate to your RAD Security workspace and configure the Iru integration with the following parameters:

### Required Parameters

| Parameter     | Required | Description                                     |
| ------------- | -------- | ----------------------------------------------- |
| **API Token** | Yes      | Iru API token used to authenticate API requests |
| **API URL**   | Yes      | Base URL of your Iru API deployment             |

***

## Verify Integration

<Steps>
  <Step title="Check Connection Status">
    1. Navigate to **Data Sources > Integrations > Endpoint Management** in RAD Security
    2. Locate your Iru integration
    3. Verify the connection status shows as **Connected**
  </Step>
</Steps>

<Check>
  Your Iru integration is now configured! RAD Security will ingest device inventory and compliance findings from Iru on a scheduled basis.
</Check>

## What Data is Synced

<AccordionGroup>
  <Accordion title="Device Inventory" icon="laptop">
    Iru managed devices, mapped to **OCSF Device Inventory Info (5001)** — hostname, OS, hardware, serial, owner, managed/compliant flags, risk, and first/last-seen timestamps.
  </Accordion>

  <Accordion title="Compliance Findings" icon="shield-exclamation">
    Device compliance posture, mapped to **OCSF Compliance Finding (2003)** and stored as security findings. Feeds unified posture analysis and RADBot.
  </Accordion>

  <Accordion title="Device Remediation" icon="screwdriver-wrench">
    The one write action — RAD can trigger an Iru remediation on a device. RBAC-gated (tenant write) and recorded as an **OCSF Device Control Finding**.
  </Accordion>
</AccordionGroup>

## Use Cases

<CardGroup cols={2}>
  <Card title="Compliance Management" icon="shield-check">
    Track device compliance gaps from discovery through remediation across your Iru fleet.
  </Card>

  <Card title="Asset Visibility" icon="laptop">
    Use managed-device inventory to understand your endpoint estate and reduce attack surface.
  </Card>

  <Card title="Threat Response" icon="screwdriver-wrench">
    Trigger Iru remediation on a non-compliant or compromised device directly from RAD.
  </Card>

  <Card title="RADBot Prioritization" icon="robot">
    Leverage RADBot to prioritize Iru device findings by real-world impact.
  </Card>
</CardGroup>

## Troubleshooting

<AccordionGroup>
  <Accordion title="Authentication Failed" icon="triangle-exclamation">
    **Possible causes:**

    * Incorrect API token
    * The token was revoked or disabled in Iru

    **Solution:**

    * Verify the API token is copied correctly (no extra spaces)
    * Confirm the token is still active in Iru
    * Regenerate the token in Iru and update it in RAD Security if needed
  </Accordion>

  <Accordion title="Connection Refused / Not Found" icon="globe">
    **Possible causes:**

    * Incorrect or unreachable API URL

    **Solution:**

    * Verify the **API URL** matches your Iru deployment's base URL
    * Confirm the URL is reachable and uses the correct scheme (`https://`)
  </Accordion>

  <Accordion title="Empty Results" icon="inbox">
    **Possible causes:**

    * The account has no devices or compliance data in scope

    **Solution:**

    * Confirm devices exist in the Iru console for the configured account
  </Accordion>
</AccordionGroup>

## Security Best Practices

<CardGroup cols={2}>
  <Card title="Use a Service Account" icon="user-gear">
    Create a dedicated API token for the RAD integration rather than tying it to a personal account.
  </Card>

  <Card title="Least Privilege" icon="shield-halved">
    Grant only the permissions required to read inventory and compliance, plus remediation if used.
  </Card>

  <Card title="Rotate Credentials" icon="rotate">
    Rotate the API token periodically according to your security policy.
  </Card>

  <Card title="Secure Secret Storage" icon="vault">
    Store the API token in a secrets vault. Never commit it to version control.
  </Card>
</CardGroup>

## Additional Resources

<CardGroup cols={2}>
  <Card title="Endpoint Management Overview" icon="laptop-mobile" href="/rad-security/integrations/endpoint-management/overview">
    Learn about RAD's endpoint management integrations
  </Card>

  <Card title="Data Sources" icon="database" href="/rad-security/integrations/data-sources">
    Connect additional security data sources
  </Card>
</CardGroup>

## Next Steps

<CardGroup cols={2}>
  <Card title="Endpoint Management Integrations" icon="laptop-mobile" href="/rad-security/integrations/endpoint-management/overview">
    Explore other endpoint management integration options
  </Card>

  <Card title="Data Sources" icon="database" href="/rad-security/integrations/data-sources">
    Connect additional security data sources
  </Card>

  <Card title="RADBot" icon="robot" href="/rad-security/getting-started/radbot">
    Learn how RADBot helps prioritize findings
  </Card>
</CardGroup>
