Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Remote Desktop Services (RDS)
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Policy Groups
    2. Trust Profiles
    3. Consents
    4. PII Protection
    5. Time-Based Policy
    6. Malvertising Protection
    7. Login Guard
    8. Watermark
  • Secure Access (ZTBA, formerly ZTNA)
    1. Introduction to ZTBA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Operating System checks in Trust Profile

In this document
  • Windows build number
  • Reboot is pending
  • Reboot is required
  • An OS update is available
  • macOS Release Version
  • Darwin (kernel) version

Operating System checks look at the Windows or macOS version and update state. Use them to keep outdated or unpatched computers away from sensitive services.

trust profile operating system check

Supported platforms: [Windows, macOS]

Check Platforms

Windows build number

[Windows]

Reboot is pending

[Windows]

Reboot is required

[Windows]

An OS update is available

[Windows]

macOS Release Version

[macOS]

Darwin (kernel) version

[macOS]

Windows build number

Platforms

[Windows]

Comparison

equals, does not equal, is less than, is less than or equal, is greater than, is greater or equal

Fields

Build number (required)

Compares the Windows build number, which is how Windows releases are identified. Use is greater or equal to set a minimum release.

Windows release Build number

Windows 10 22H2

19045

Windows 11 21H2

22000

Windows 11 22H2

22621

Windows 11 23H2

22631

Windows 11 24H2

26100

Enter a plain number without leading zeros, for example 22631.

Tip
To see a computer’s build number, run winver, or check Settings > System > About > OS build. The build number is the part before the dot.
Note
Windows Server uses its own build numbers. For example, Windows Server 2022 is build 20348. If a profile covers both desktops and servers, remember that servers will be compared against the same number.

Reboot is pending

Platforms

[Windows]

Comparison

None

Fields

None

Passes when Windows has a pending restart, for example after installing an update or a driver. Use it with NOT to require that no restart is waiting.

Reboot is required

Platforms

[Windows]

Comparison

None

Fields

None

Passes when Windows reports that a restart is required. Use it with NOT to require that no restart is needed.

Reboot is pending and Reboot is required are separate flags set by different parts of Windows. Either one can be set without the other. To require no restart waiting of any kind, add both with NOT, in a group set to Match all checks.

An OS update is available

Platforms

[Windows]

Comparison

None

Fields

None

Passes when Windows Update has updates for this computer that are not installed yet. Use it with NOT to require an up-to-date computer.

Things to know
  • The check uses the result of the last Windows Update scan stored on the computer. It does not contact Windows Update itself.

  • A computer that hasn’t reached Windows Update for a long time has no stored result. It reports no update available, the same as a fully patched computer. To cover this, combine the check with Windows build number.

  • If the Windows Update service is disabled, the check reports an error.

macOS Release Version

Platforms

[macOS]

Comparison

equals, does not equal, is less than, is less than or equal, is greater than, is greater or equal

Fields

Version (required)

Compares the macOS version as Apple names it, for example 14.5. This is the version shown in Apple menu > About This Mac, and the one to use in most profiles.

Use is greater or equal to set a minimum version, for example 14.5. Versions are compared number by number and a missing part counts as zero, so 15 is the same as 15.0.0.

Note
Some older agent builds see macOS 11 and later as version 10.16. In that case the check reports an error instead of comparing a wrong number. If you see this in Online Check, update the agent or use Darwin (kernel) version instead.

Darwin (kernel) version

Platforms

[macOS]

Comparison

equals, does not equal, is less than, is less than or equal, is greater than, is greater or equal

Fields

Version (required)

Compares the version of the macOS kernel (Darwin). It uses different numbers from the macOS version:

macOS Darwin

macOS 13 Ventura

22.x

macOS 14 Sonoma

23.x (macOS 14.5 is 23.5.0)

macOS 15 Sequoia

24.x

macOS 26 Tahoe

25.x

To see the Darwin version, run uname -r in Terminal.

Important
Don’t mix up the two numbering schemes. A rule of Darwin version is greater or equal 14 passes every modern Mac. A rule of macOS Release Version is greater or equal 23 fails them all.
www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013