Turn on network mapping
Walk the one switch that arms network mapping for the whole fleet: where it lives, what it does before you touch it, turning it on, the excluded-clients list, the one per-client exception, and turning it back off.
What you will have
- Find the switch and read what it says about itself before touching it.
- Turn network mapping on and see what changes on the page.
- See the excluded clients list and know what it is for.
- Find the one per-client exception, on the client's own RMM tab, and read its three-line status honestly.
- Turn the switch back off and know what stops and what stays.
Why it works this way
This used to be a per-client control: arm one client, approve it, repeat for every client on the roster. It is not that any more. One flip now arms every client at once, existing and new. The only per-client control left is an exception, not an approval: a checkbox on a client's own RMM tab that takes that one client out while everyone else stays in.
Nothing about this switch is quiet. Every time it is turned on or off, one row is written to the audit log with the count of clients it just armed. The same is true of a client's own exclude checkbox. Neither writes anything else: no per-client row is created when the fleet switch arms nine clients at once, because being armed is worked out at the moment each device checks in, not stored ahead of time.
Steps
Open Settings > RMM > Network Mapping.
Its own settings page, listed under RMM in the left settings rail alongside Device Approval. The page heading and its own summary line read exactly: "One switch arms network mapping collection for every client. Off by default fleet-wide; exclude a rare client from its own settings."
Open Settings > RMM > Network Mapping. Read the switch before touching it.
It starts off, and the page says so in two places: the toggle itself, and the line under it, "Off - no client is being mapped." The panel's own helper text says what turning it on does: "One switch arms passive local topology reads plus a bounded local-subnet discovery sweep for every client. Off by default fleet-wide." In plain words: every client's agents would start sending what their own machine already knows about the network it sits on (its subnets, its route table, the neighbors in its ARP cache) plus a bounded scan of its own local subnet only, never anything past that bound. Those readings are what builds the picture on RMM > Network Map, covered by a future page once a device is enrolled to show it. This is new, so off is the safe starting point, and this is a new instance where nothing has been turned on yet.
Read the switch before touching it. Turn the switch on.
One click, no confirmation step, applies instantly. The toggle turns on and the line under it becomes a count: this tenant showed "9 of 9 clients mapped" the moment it flipped, because every client on the roster is armed at once, not one at a time. New clients created later are armed too, automatically, from the moment they exist. A toast confirms the flip ("Network mapping turned on for the fleet"), and the flip also writes one row to Settings > Logs > Audit named netmap.global_flip, with the same count.
Turn the switch on. See the Excluded clients panel underneath.
Its own card, right below the switch, titled Excluded clients. On a tenant where nobody has been excluded yet it reads plainly: "No client is excluded." This list is where a client shows up once it is excluded on its own RMM tab (the next step), each with an Un-exclude button to bring it straight back in. This panel only ever narrows who the switch reaches; it is never a second way to turn the whole thing off.
See the Excluded clients panel underneath. Open Clients, pick a client, then its RMM tab, for the one exception.
A card near the top of the tab, titled Exclude from network mapping, with its own helper line: "This client follows the fleet-wide network mapping switch unless excluded here." Its own status line spells out exactly where this one client stands right now: with the fleet switch on and this checkbox still off, it read "Currently mapped (the fleet-wide switch is on)." Turning this one checkbox on takes this client's devices out while every other client keeps collecting; turning it back off returns the client to following the fleet switch again. This is an ordinary edit permission on the client, not the owner-level permission the fleet switch itself needs. The account used through this whole walk is a plain Staff account (shown top right), and it could flip this checkbox the same as it read every other frame on this page - Owner access was never required for it.
Open Clients, pick a client, then its RMM tab, for the one exception. Turn the switch back off to close the loop.
The same one click, no confirmation, back on the Network Mapping settings page. The line underneath returns to "Off - no client is being mapped," a second netmap.global_flip row lands in the audit log with a count of zero, and a toast confirms it ("Network mapping turned off for the fleet"). Collection itself does not stop the instant the switch flips; it stops for each client at that client's agents' next check-in. Whatever a device already reported stays on its map until it ages out, so the map keeps telling the truth about when it last actually saw something instead of going blank the moment the switch turns off. Turning the switch back on later picks collection straight back up for every client that is not excluded.
Turn the switch back off to close the loop.
Other ways to do this
The client's own RMM tab
Clients > pick the client > RMM shows the same Exclude from network mapping card this walk uses in step 5, already claimed in full on the-clients-rmm-tab.
If it did not work
- If the toggle will not stay on, or reverts, check the account's own tier: this switch needs owner-level access (the same ceiling as deleting an RMM record), not ordinary edit access. The per-client exclude checkbox on a client's RMM tab needs only ordinary edit access on that client, so a Tech who cannot touch the fleet switch can still exclude their own client.
- If a client is not being mapped even though the fleet switch is on, check that client's own RMM tab for the Exclude from network mapping checkbox. If it is on, that one client is the exception; every other client keeps collecting.
- If the fleet switch is off, a client's own exclude checkbox does nothing either way: nobody is mapped while the switch is off, no matter how that checkbox is set.
Questions this page answers
What does turning network mapping on do?
It tells every client's agents to send what their own machine already knows about the network: the subnets its cards are on, its route table, and the neighbors in its ARP cache, plus a bounded discovery sweep of its own local subnet. Nothing outside that bound is scanned. The readings build the picture you see on RMM > Network Map. One switch, the whole fleet - there is no per-client toggle any more.
Why is it off by default, and how do I leave one client out?
It starts off. This is new, so off is the safe start. Turning it on arms every client at once. New clients get it too. If one client should sit out, use the exclude checkbox on that client's RMM tab. Everyone else keeps collecting. Every flip, and every exclude, goes in the audit log.
What happens when I turn the switch back off?
Collection stops fleet-wide at each agent's next check-in. The readings already collected stay on the map until they age out, so the page keeps telling you the truth about when it last saw each thing. Turning the switch back on picks straight back up for every client that isn't excluded.
How do I keep the switch on but leave one client out?
Open that client's RMM tab. Go to Clients, pick the client, then RMM. Turn on "Exclude from network mapping" there. This only narrows the switch. It needs normal edit access, not owner-level access. This page's excluded list shows who is out. Click to bring one back.
Was this helpful?