Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Remote Desktop Services (RDS)
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Policy Groups
    2. Trust Profiles
    3. Consents
    4. PII Protection
    5. Time-Based Policy
    6. Malvertising Protection
    7. Login Guard
    8. Watermark
  • Secure Access (ZTBA, formerly ZTNA)
    1. Introduction to ZTBA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Introduction to Trust Profiles

In this document
  • Where Trust Profiles Are Used
  • Trust Profiles and Subscriptions
  • How a Trust Profile Is Built
    • Checks
    • Platform Groups
    • Rule Groups
  • How Evaluation Works
  • Global Trust Profiles for Partners
  • Recommended Approach
  • Questions & Answers
Important
Trust Profiles require DefensX Agent version 2.4.176 or later. Older agents keep working as before, but they do not enforce trust profile requirements.

A Trust Profile is a set of device posture requirements that an endpoint has to meet before a policy lets it through. You can require, for example, that a Windows computer has BitLocker protection turned on, a running EDR process and a Windows 11 build, or that a Mac has FileVault enabled and is enrolled in your MDM.

Trust Profiles answer a question that user identity alone can’t: is this device in a state we trust? Valid credentials are no longer enough on their own. If the laptop they are used on doesn’t meet the profile, access is denied.

Trust Profiles are available from the CORE+ subscription. What you can do with them depends on your subscription level. See Trust Profiles and Subscriptions below.

trust profiles

Where Trust Profiles Are Used

On its own, a trust profile does nothing. It takes effect when a policy references it. You can attach a trust profile to two kinds of policy:

  • Secure Access Policies (ZTBA). The services linked to the policy are reachable only from endpoints that pass the profile. Set this in the Trust Profile field of the Secure Access Policy. Requires PREMIUM+.

  • Web Filter Policies. The profile is evaluated at the computer level. If the computer does not pass it, the web filter policy blocks. Set this in the Trust Profile block of the Web Filter policy page. Requires PREMIUM or higher.

One profile can be used by any number of policies. The Used By column on the Trust Profiles page shows which policies reference each profile.

Trust Profiles and Subscriptions

CORE+ PREMIUM PREMIUM+

Maximum number of trust profiles

5

30

30

Shortest Re-Check Time Interval

5 minutes

30 seconds

30 seconds

Trust profile status logs per computer

Yes

Yes

Yes

Online Check

Yes

Yes

Yes

Attach to Web Filter Policies

No

Yes

Yes

Attach to Secure Access Policies (ZTBA)

No

No

Yes

On CORE+, trust profiles are not attached to a policy, so they don’t allow or block anything. The agent still evaluates them on every computer and reports the result. Use Trust Profile Logs to see which computers meet your posture requirements before you move to enforcement on a higher subscription.

On CORE+, the Re-Check Time Interval options shorter than 5 minutes are not available.

How a Trust Profile Is Built

A trust profile has three layers.

Checks

A check is a single question the DefensX Agent answers about the endpoint, such as Is the Windows Firewall enabled? or Is a process running from this path? Each check has a platform. Registry checks exist only on Windows and FileVault only on macOS, for example.

Some checks need values, such as a path, a version number or a registry key. Some also need a comparison, such as equals, is greater or equal or contains.

Any check can be negated with NOT. The check then passes when the condition is not met, for example NOT Reboot is required.

Platform Groups

Checks are organized per platform. Each profile has a group for every supported platform:

Platform What you can do

Windows

Add any of the Windows checks.

macOS

Add any of the macOS checks.

iOS

Allow or block. There are no checks to add for iOS.

Android

Allow or block. There are no checks to add for Android.

Generic

Add checks that run on every endpoint regardless of platform. Today this is IP Country.

A few rules decide how platform groups behave:

  • A platform that is turned off is blocked. Endpoints of that platform never pass the profile.

  • A platform that is on but has no checks passes as it is. This is how you let a platform through without asking it anything.

  • Inside a group you choose how checks combine. Match all checks means every check must pass. Match any check means one passing check is enough.

  • The endpoint’s own platform group is what counts. A Windows computer is judged by the Windows group only. The macOS group is ignored for it.

  • Generic checks are added on top. An endpoint has to pass its own platform group and the Generic group.

Rule Groups

Every profile starts with one rule group that holds all the platform groups above. For most profiles that one rule group is enough.

When you need to combine separate sets of requirements, add another rule group. Each rule group has its own platform groups. You then choose how the rule groups combine:

  • every rule group holds: the endpoint has to pass all of them.

  • any rule group holds: passing one of them is enough. This is the default.

A rule group can also be turned off. An inactive rule group is left out of the profile until you turn it back on.

How Evaluation Works

The DefensX Backend compiles each profile into a single expression and sends it to the agents. The agent evaluates the expression locally, on the interval set in the profile’s Re-Check Time Interval, and reports the result. The interval can be set from 30 seconds to 30 minutes, or from 5 minutes to 30 minutes on CORE+.

Each evaluation ends in one of three states:

Status Meaning

Pass

The endpoint meets everything the profile asks for.

Fail

At least one requirement is not met, or the endpoint’s platform is not allowed.

Unknown

The profile has not been evaluated on this endpoint yet.

If the agent cannot inspect something a check needs, the check reports an error instead of a false result. An example is a folder the agent is refused access to. An error means the endpoint does not pass. This is deliberate: a device must never pass a posture gate just because it couldn’t be inspected.

Note
A check that the endpoint’s agent version doesn’t know answers false. It does not report an error. If you use a new check, make sure your agents are up to date. Otherwise older agents will fail that check.

You can follow results in two places:

  • Online Check sends a profile to selected computers on demand and shows exactly which check passed or failed on each one. Use it while you build a profile.

  • Trust Profile Logs (under Logs & Reports > Logs) keeps the ongoing Pass / Fail history of every computer and profile.

Global Trust Profiles for Partners

Partners can create trust profiles under Global Tools > Trust Profiles. Profiles created there are globally available in the customer hierarchy. Every customer under the partner can select them in their own Secure Access and Web Filter policies without copying them.

In a customer’s policy selection list, a global profile appears as Partner Name :: Profile Name. Only the partner can edit a global profile. On the partner’s Trust Profiles page, the Used By column shows how many customers use each global profile.

Partners can create up to 30 global trust profiles, whatever their own subscription. Each customer can still only use them in the policies its own subscription allows.

Recommended Approach

  1. Start with a small profile and one platform. For example, Windows with BitLocker protection is on and Firewall is enabled.

  2. Use Online Check on a few computers you know well: one that should pass and one that shouldn’t.

  3. Attach the profile to a Secure Access Policy or Web Filter policy used by a small test group.

  4. Watch Trust Profile Logs for a few days before you apply it more widely.

On CORE+, skip step 3 and use steps 1, 2 and 4 to measure how many of your computers already meet the profile.

For step-by-step instructions, see the Creating and Managing Trust Profiles article. For every check and the platforms that support it, see the Trust Profile Checks Reference.

Questions & Answers

  • Why does a new trust profile let every device through?

A new profile starts with every platform allowed and no checks, so every endpoint passes. Add checks to the platforms you care about, and turn off the platforms you don’t want to allow.

  • What happens on agents older than 2.4.176?

They keep working, but they don’t enforce trust profile requirements.

  • Why can’t I pick a 30 second Re-Check Time Interval?

Intervals shorter than 5 minutes need a PREMIUM or higher subscription.

  • Why can’t I create another trust profile?

You have reached the trust profile limit of your subscription: 5 on CORE+ and 30 on PREMIUM and PREMIUM+. Delete a profile you no longer need, or upgrade your subscription.

  • Does the IP Country check use the device’s GPS location?

No. It uses the country that the DefensX network sees the connection coming from. A device on a VPN or behind a proxy in another country is judged by that country.

www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013