Browse Docs
-
Introduction
-
Deployment
- Deployment via RMM
- Operating System Agent
- Deployment via GPO
- Deployment via Intune
- VDI and Remote Desktop Services (RDS)
- Windows Manual Deployment
- Mac MDM Deployment
- Mac Manual Deployment
- Network Deployment
- Secure Mobile Browser
- Bypass Option
- SaaS Restrictions
- Bookmark Manager
- Remote Uninstall
- Bulk Create Customers
-
Management
-
Integrations
-
Nexi AI
-
Policy Management
-
Secure Access (ZTBA, formerly ZTNA)
-
Auto Pilot
-
Training Videos
-
Questions & Answers
-
MSP Automation
ONLINE DOCUMENTATION
|
||||||||||||||||||||||||||||
Creating and managing Trust ProfilesIn this document
This article walks through creating a trust profile, adding platform checks, testing the profile on real computers and attaching it to a policy. Creating a Trust ProfileNavigate to Policy Management > Policies > Trust Profiles and click + New Trust Profile. Partners creating a profile for all of their customers use Global Tools > Trust Profiles instead.
Fill in the form:
Click Create Trust Profile. The profile opens on its platform page. It starts with one rule group in which every platform is allowed and none has any checks, so at this point every endpoint passes. The next step is to narrow it down. Setting Up PlatformsThe profile page lists one row per platform: Windows, macOS, iOS, Android and Generic. Each row summarizes what the platform is asked:
Allowing or Blocking a PlatformUse the toggle at the right of a platform row to allow or block that platform. When you block a platform, its checks are kept. If you turn the platform back on later, the same checks come back.
Adding Checks to a PlatformClick a platform row, for example Windows, to open its checks page.
Hover over the ? next to a check name to see a short description of it. For full details of every check, see the Trust Profile Checks Reference.
Generic ChecksThe Generic row holds checks that run on every endpoint, whatever its platform. Today the Generic group offers IP Country. Generic checks are required in addition to the platform group. With a Generic IP Country check set to equals United States, a Windows computer has to pass the Windows checks and connect from the United States.
Working With Multiple Rule GroupsOne rule group covers most needs. Add another rule group when a profile has to express two separate sets of requirements. An example is corporate Windows laptops that pass the full check list, or any device running a specific EDR software that passes a lighter check list.
Each rule group has an active toggle. Turning a rule group off leaves it out of the profile without deleting it. The trash icon removes a rule group and everything in it. Reviewing the Compiled ProfileAt the bottom of the profile page, open Compiled Profile to see the full expression that is sent to the agents. It reads as plain logic, for example:
Use it to confirm that the platforms and the and / or combinations say what you mean. Testing With Online CheckBefore you attach a profile to a policy, test it on real computers.
Commands usually reach online computers within 2 to 3 minutes, and the result list refreshes on its own. To get a faster answer, open the DefensX tray menu on the computer and click Reconnect.
Each computer ends up with one of these results:
Click a computer to open its detail page:
Attaching a Trust Profile to a PolicySecure Access Policy
The services linked to that policy are now reachable only from endpoints that pass the profile. The Trust Profile column of the Secure Access Policies table shows which profile each policy requires. Web Filter Policy
The change is saved automatically. The profile is evaluated at the computer level. If the computer doesn’t pass it, the policy blocks.
Monitoring With Trust Profile LogsNavigate to Logs & Reports > Logs > Trust Profile Logs to see every evaluation reported by your computers. Each row shows the platform, the computer, the trust profile, the status (Pass, Fail or Unknown) and when the check happened. Filter by computer, date range, trust profile or status. Filtering on Fail is a quick way to find the devices that are currently being held back by a profile. Managing Existing ProfilesThe action menu (…) on each row of the Trust Profiles list offers:
A profile that is used by a policy cannot be deleted or set to Inactive. The error message lists the policies that still use it. Remove the profile from those policies first. Changes to a profile reach the agents automatically within a short time. You don’t need to re-save the policies that use it. |
||||||||||||||||||||||||||||