Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Remote Desktop Services (RDS)
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Policy Groups
    2. Trust Profiles
    3. Consents
    4. PII Protection
    5. Time-Based Policy
    6. Malvertising Protection
    7. Login Guard
    8. Watermark
  • Secure Access (ZTBA, formerly ZTNA)
    1. Introduction to ZTBA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Creating and managing Trust Profiles

In this document
  • Creating a Trust Profile
  • Setting Up Platforms
    • Allowing or Blocking a Platform
    • Adding Checks to a Platform
    • Generic Checks
  • Working With Multiple Rule Groups
  • Reviewing the Compiled Profile
  • Testing With Online Check
  • Attaching a Trust Profile to a Policy
    • Secure Access Policy
    • Web Filter Policy
  • Monitoring With Trust Profile Logs
  • Managing Existing Profiles

This article walks through creating a trust profile, adding platform checks, testing the profile on real computers and attaching it to a policy.

Creating a Trust Profile

Navigate to Policy Management > Policies > Trust Profiles and click + New Trust Profile.

Partners creating a profile for all of their customers use Global Tools > Trust Profiles instead.

new trust profile

Fill in the form:

Field Description

Name

How this profile appears when you select it in a policy. At least 3 characters, and unique for the customer.

Description

Optional note for your own reference, up to 255 characters.

Re-Check Time Interval

How often endpoints re-evaluate the profile: 30 seconds, or 1, 2, 5, 10, 20 or 30 minutes. A shorter interval reacts faster to changes on the device.

Active Status

Only Active profiles can be selected in Secure Access and Web Filter policies.

Globally available in customer hierarchy

Shown only to partners on their own account. Yes makes the profile available to every customer under the partner. Profiles created from Global Tools are always global.

Click Create Trust Profile.

The profile opens on its platform page. It starts with one rule group in which every platform is allowed and none has any checks, so at this point every endpoint passes. The next step is to narrow it down.

Setting Up Platforms

The profile page lists one row per platform: Windows, macOS, iOS, Android and Generic. Each row summarizes what the platform is asked:

  • No checks yet, so Windows endpoints pass as they are: the platform is allowed with no checks.

  • Not allowed. iOS endpoints never pass this profile.: the platform is blocked.

  • Allowed. There is nothing to check on Android.: iOS and Android can only be allowed or blocked.

  • A list of checks joined with and / or: the checks the platform must pass.

trust profile summary

Allowing or Blocking a Platform

Use the toggle at the right of a platform row to allow or block that platform.

When you block a platform, its checks are kept. If you turn the platform back on later, the same checks come back.

Tip
If your organization has no mobile devices that should reach a service, turn off iOS and Android in profiles used for that service.

Adding Checks to a Platform

Click a platform row, for example Windows, to open its checks page.

  1. Click Add a check. A menu opens with the available checks grouped by category: File, Process, Application, Registry, Security, Operating System, Domain and Versions. You can type in the search box to filter the list.

  2. Pick a check. It is added to the page with the fields it needs.

  3. If the check has a comparison, choose it from the drop-down next to the check name, for example is greater or equal.

  4. Fill in the fields. Optional fields are marked (optional).

  5. Tick NOT if the check should pass when the condition is not met.

  6. Repeat for further checks with Add another check.

  7. Choose how the checks combine with Match:

    • all checks: every check has to pass.

    • any check: one passing check is enough.

  8. Click Save Checks.

add windows check

Hover over the ? next to a check name to see a short description of it. For full details of every check, see the Trust Profile Checks Reference.

Note
If a required field is missing or a value has the wrong format, the page shows the problem and does not save. Examples of wrong formats are a SHA256 digest that is not 64 hex characters, or a Tenant ID that is not a UUID.

Generic Checks

The Generic row holds checks that run on every endpoint, whatever its platform. Today the Generic group offers IP Country.

Generic checks are required in addition to the platform group. With a Generic IP Country check set to equals United States, a Windows computer has to pass the Windows checks and connect from the United States.

country checks

Working With Multiple Rule Groups

One rule group covers most needs. Add another rule group when a profile has to express two separate sets of requirements. An example is corporate Windows laptops that pass the full check list, or any device running a specific EDR software that passes a lighter check list.

  1. On the profile page click Add Another Rule Group. A new rule group is added below the first one, with every platform allowed and no checks.

  2. Set up its platforms the same way as the first.

  3. Click the rule group’s name to rename it. By default rule groups are named Rule group 1, Rule group 2, and so on.

  4. Under An endpoint passes when, choose:

    • every rule group holds: the endpoint must pass all rule groups.

    • any rule group holds: passing one rule group is enough.

multiple rule groups

Each rule group has an active toggle. Turning a rule group off leaves it out of the profile without deleting it. The trash icon removes a rule group and everything in it.

Reviewing the Compiled Profile

At the bottom of the profile page, open Compiled Profile to see the full expression that is sent to the agents. It reads as plain logic, for example:

(windows() and windows.bitlocker.protected() and windows.firewall.enabled())
or
(macosx() and macosx.filevault.enabled())
or
ios()

Use it to confirm that the platforms and the and / or combinations say what you mean.

Testing With Online Check

Before you attach a profile to a policy, test it on real computers.

start trust profile check
  1. On the profile page, click Online Check. You can also use Online Check in the profile’s action menu on the Trust Profiles list.

  2. In Find computers, type at least 3 characters of a computer name and pick computers from the results. Only computers seen in the last 14 days are offered. Add as many computers as you want into the list.

  3. Click Start Trust Profile Check.

Commands usually reach online computers within 2 to 3 minutes, and the result list refreshes on its own. To get a faster answer, open the DefensX tray menu on the computer and click Reconnect.

trust profile check status

Each computer ends up with one of these results:

Result Meaning

Passed

The computer meets everything the profile asks.

Not passed

At least one requirement failed, or the computer’s platform is not allowed.

Check error

The agent could not evaluate the profile. The error message is shown on the detail page.

Expired

The computer did not answer in time. Make sure it is online and try again.

Click a computer to open its detail page:

  • Why it did not pass lists the checks that failed, with the values they were given.

  • What was checked shows every check in the profile with its result, grouped the same way the profile is built (All of these / Any one of these).

  • Expression and raw response shows the exact expression and the agent’s full answer. This is useful when you contact support.

trust profile check result detail

Attaching a Trust Profile to a Policy

Secure Access Policy

  1. Navigate to Secure Access > Configuration & Logs > Configuration.

  2. Create a new Secure Access Policy or edit an existing one.

  3. In Trust Profile, select the profile. No trust profile required removes the requirement.

  4. Save the policy.

The services linked to that policy are now reachable only from endpoints that pass the profile. The Trust Profile column of the Secure Access Policies table shows which profile each policy requires.

Web Filter Policy

  1. Navigate to Policy Management > Policies and open the Web Filter policy of the policy group.

  2. In the Trust Profile block, select the profile.

The change is saved automatically. The profile is evaluated at the computer level. If the computer doesn’t pass it, the policy blocks.

Note
Only Active trust profiles appear in these lists. If no active profile exists yet, the field shows a Create one link instead.

Monitoring With Trust Profile Logs

Navigate to Logs & Reports > Logs > Trust Profile Logs to see every evaluation reported by your computers. Each row shows the platform, the computer, the trust profile, the status (Pass, Fail or Unknown) and when the check happened.

Filter by computer, date range, trust profile or status. Filtering on Fail is a quick way to find the devices that are currently being held back by a profile.

Managing Existing Profiles

The action menu (…​) on each row of the Trust Profiles list offers:

  • Edit: change the name, description, re-check interval and status.

  • Duplicate: create an inactive copy named Copy of <name>, with all rule groups and checks. Use it to try changes without touching a profile that is in use.

  • Platforms: open the profile’s platform page.

  • Online Check: test the profile on selected computers.

  • Delete: remove the profile.

A profile that is used by a policy cannot be deleted or set to Inactive. The error message lists the policies that still use it. Remove the profile from those policies first.

Changes to a profile reach the agents automatically within a short time. You don’t need to re-save the policies that use it.

www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013