Browse Docs
-
Introduction
-
Deployment
- Deployment via RMM
- Operating System Agent
- Deployment via GPO
- Deployment via Intune
- VDI and Remote Desktop Services (RDS)
- Windows Manual Deployment
- Mac MDM Deployment
- Mac Manual Deployment
- Network Deployment
- Secure Mobile Browser
- Bypass Option
- SaaS Restrictions
- Bookmark Manager
- Remote Uninstall
- Bulk Create Customers
-
Management
-
Integrations
-
Nexi AI
-
Policy Management
-
Secure Access (ZTBA, formerly ZTNA)
-
Auto Pilot
-
Training Videos
-
Questions & Answers
-
MSP Automation
ONLINE DOCUMENTATION
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
Introduction to Trust ProfilesIn this document
A Trust Profile is a set of device posture requirements that an endpoint has to meet before a policy lets it through. You can require, for example, that a Windows computer has BitLocker protection turned on, a running EDR process and a Windows 11 build, or that a Mac has FileVault enabled and is enrolled in your MDM. Trust Profiles answer a question that user identity alone can’t: is this device in a state we trust? Valid credentials are no longer enough on their own. If the laptop they are used on doesn’t meet the profile, access is denied. Trust Profiles are available from the CORE+ subscription. What you can do with them depends on your subscription level. See Trust Profiles and Subscriptions below.
Where Trust Profiles Are UsedOn its own, a trust profile does nothing. It takes effect when a policy references it. You can attach a trust profile to two kinds of policy:
One profile can be used by any number of policies. The Used By column on the Trust Profiles page shows which policies reference each profile. Trust Profiles and Subscriptions
On CORE+, trust profiles are not attached to a policy, so they don’t allow or block anything. The agent still evaluates them on every computer and reports the result. Use Trust Profile Logs to see which computers meet your posture requirements before you move to enforcement on a higher subscription. On CORE+, the Re-Check Time Interval options shorter than 5 minutes are not available. How a Trust Profile Is BuiltA trust profile has three layers. ChecksA check is a single question the DefensX Agent answers about the endpoint, such as Is the Windows Firewall enabled? or Is a process running from this path? Each check has a platform. Registry checks exist only on Windows and FileVault only on macOS, for example. Some checks need values, such as a path, a version number or a registry key. Some also need a comparison, such as equals, is greater or equal or contains. Any check can be negated with NOT. The check then passes when the condition is not met, for example NOT Reboot is required. Platform GroupsChecks are organized per platform. Each profile has a group for every supported platform:
A few rules decide how platform groups behave:
Rule GroupsEvery profile starts with one rule group that holds all the platform groups above. For most profiles that one rule group is enough. When you need to combine separate sets of requirements, add another rule group. Each rule group has its own platform groups. You then choose how the rule groups combine:
A rule group can also be turned off. An inactive rule group is left out of the profile until you turn it back on. How Evaluation WorksThe DefensX Backend compiles each profile into a single expression and sends it to the agents. The agent evaluates the expression locally, on the interval set in the profile’s Re-Check Time Interval, and reports the result. The interval can be set from 30 seconds to 30 minutes, or from 5 minutes to 30 minutes on CORE+. Each evaluation ends in one of three states:
If the agent cannot inspect something a check needs, the check reports an error instead of a false result. An example is a folder the agent is refused access to. An error means the endpoint does not pass. This is deliberate: a device must never pass a posture gate just because it couldn’t be inspected.
You can follow results in two places:
Global Trust Profiles for PartnersPartners can create trust profiles under Global Tools > Trust Profiles. Profiles created there are globally available in the customer hierarchy. Every customer under the partner can select them in their own Secure Access and Web Filter policies without copying them. In a customer’s policy selection list, a global profile appears as Partner Name :: Profile Name. Only the partner can edit a global profile. On the partner’s Trust Profiles page, the Used By column shows how many customers use each global profile. Partners can create up to 30 global trust profiles, whatever their own subscription. Each customer can still only use them in the policies its own subscription allows. Recommended Approach
On CORE+, skip step 3 and use steps 1, 2 and 4 to measure how many of your computers already meet the profile. For step-by-step instructions, see the Creating and Managing Trust Profiles article. For every check and the platforms that support it, see the Trust Profile Checks Reference. Questions & Answers
A new profile starts with every platform allowed and no checks, so every endpoint passes. Add checks to the platforms you care about, and turn off the platforms you don’t want to allow.
They keep working, but they don’t enforce trust profile requirements.
Intervals shorter than 5 minutes need a PREMIUM or higher subscription.
You have reached the trust profile limit of your subscription: 5 on CORE+ and 30 on PREMIUM and PREMIUM+. Delete a profile you no longer need, or upgrade your subscription.
No. It uses the country that the DefensX network sees the connection coming from. A device on a VPN or behind a proxy in another country is judged by that country. |
||||||||||||||||||||||||||||||||||||||||||||||||||||