I just enabled ESPM in my environment and immediately saw it detect SafeDomain Guardian running on one of my endpoints.
The finding provided quite a bit of useful detail, including the full executable path, execution count, package family name, and Microsoft Store package ID. However, it did not identify which device was running the application.
In my case, I only manage a relatively small number of endpoints, so I was able to narrow it down manually. In a larger environment—or if the same application were present on multiple devices—that would quickly become much more difficult and time-consuming.
At minimum, ESPM findings should include the associated organization and hostname, or otherwise provide a way to pivot from the application/process event to the endpoint that generated it.
Since the underlying telemetry is already detailed enough to show the executable path and process activity, tying that information back to the originating device would make ESPM findings significantly more actionable.
If this has already been requested, feel free to merge this with the existing feedback.