Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Remote Desktop Services (RDS)
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Policy Groups
    2. Trust Profiles
    3. Consents
    4. PII Protection
    5. Time-Based Policy
    6. Malvertising Protection
    7. Login Guard
    8. Watermark
  • Secure Access (ZTBA, formerly ZTNA)
    1. Introduction to ZTBA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Security checks in Trust Profile

In this document
  • Firewall is enabled
  • BitLocker protection is on
  • BitLocker drive is encrypted
  • BitLocker encryption method
  • Antivirus is installed
  • Antivirus is enabled
  • Antivirus is up to date
  • FileVault is enabled

Security checks cover the built-in protections that most device compliance policies ask for: firewall, disk encryption and antivirus.

trust profile security check

Supported platforms: [Windows, macOS]

Check Platforms

Firewall is enabled

[Windows]

BitLocker protection is on

[Windows]

BitLocker drive is encrypted

[Windows]

BitLocker encryption method

[Windows]

Antivirus is installed

[Windows]

Antivirus is enabled

[Windows]

Antivirus is up to date

[Windows]

FileVault is enabled

[macOS]

Firewall is enabled

Platforms

[Windows]

Comparison

None

Fields

None

Passes when Windows Defender Firewall is on for all three profiles: Domain, Private and Public. To require that the firewall is off, tick NOT.

Things to know
  • The check reads the local firewall setting. If a Group Policy turns the firewall off while the local setting is on, the check still passes.

  • On a computer where a firewall profile has never been configured, that profile reads as off, so the check fails.

BitLocker protection is on

Platforms

[Windows]

Comparison

None

Fields

Drive (optional)

Passes when BitLocker protection is active on the drive. This is the check to use for disk encryption compliance.

Leave Drive empty to check the drive Windows is installed on. This is not always C:. To check another drive, enter its letter in any form: D, d, D: or D:\.

BitLocker drive is encrypted

Platforms

[Windows]

Comparison

None

Fields

Drive (optional)

Passes when the drive is fully encrypted, whether or not protection is currently active.

This is the weaker check. Windows suspends BitLocker protection on its own during some feature updates, and while suspended the encryption key is stored on the disk unprotected. The two BitLocker state checks answer as follows:

Drive state BitLocker drive is encrypted BitLocker protection is on

Encrypted, protection active

Passes

Passes

Encrypted, protection suspended

Passes

Fails

Encryption in progress

Fails

Fails

Not encrypted

Fails

Fails

Use BitLocker protection is on for compliance. Use BitLocker drive is encrypted only when you need to tell a drive that has never been encrypted apart from one where protection is suspended.

BitLocker encryption method

Platforms

[Windows]

Comparison

equals, does not equal

Fields

Method (required), Drive (optional)

Checks which cipher the drive is encrypted with. Choose the Method from the list:

Method Meaning

None

The drive is not encrypted.

AES 128 with diffuser (Vista/7 only)

Legacy method used by Windows Vista and 7.

AES 256 with diffuser (Vista/7 only)

Legacy method used by Windows Vista and 7.

AES 128 (CBC)

AES 128-bit in CBC mode.

AES 256 (CBC)

AES 256-bit in CBC mode.

XTS-AES 128

AES 128-bit in XTS mode. The Windows default since Windows 10 version 1511.

XTS-AES 256

AES 256-bit in XTS mode.

Hardware encryption

The drive encrypts itself (self-encrypting drive). Windows reports no key length for it.

To require 256-bit or stronger, add two checks, equals XTS-AES 256 and equals AES 256 (CBC), and set the group to Match any check. Match applies to the whole platform group. If your Windows group has other checks that must all pass, put the two method checks in a second rule group instead, and set An endpoint passes when to every rule group holds.

Important
This check reports the cipher, not whether encryption has finished. A drive that is still being encrypted already reports the method it is converting to. Always pair it with BitLocker protection is on.
Things to know for all BitLocker checks
  • A drive that is locked reports an error.

  • A drive that does not exist, or a Windows edition without BitLocker (such as Windows Home), makes the checks fail and reports None as the method.

  • These checks only see BitLocker. They say nothing about other disk encryption products.

Antivirus is installed

Platforms

[Windows]

Comparison

None

Fields

Product name (optional)

Passes when an antivirus product is registered with Windows Security Center.

Leave Product name empty to accept any product. To require a specific product, enter its display name as a glob pattern, for example CrowdStrike* or Sophos*.

Antivirus is enabled

Platforms

[Windows]

Comparison

None

Fields

Product name (optional)

Passes when a registered antivirus product is turned on. This is the check to use for antivirus compliance.

Leave Product name empty to accept any active product.

Tip
Don’t enter Microsoft Defender as the product name unless Defender really is your only antivirus. Defender turns itself off when another antivirus product registers. On a well-protected computer, Defender is therefore off while the other product is on. With the product name left empty, the check passes through whichever product is working.

Antivirus is up to date

Platforms

[Windows]

Comparison

None

Fields

Product name (optional)

Passes when a registered antivirus product is enabled and its detection signatures are up to date. Leave Product name empty to accept any product.

Windows Server

Windows Server editions don’t have Windows Security Center, so on servers the three antivirus checks ask Microsoft Defender directly:

  • With Product name empty, the checks report on Defender. If a third-party antivirus is installed, Defender is in passive mode and the checks fail.

  • A Product name other than Defender reports an error on servers.

For servers that run a third-party antivirus, use a Process Running (by path) check for that product instead.

FileVault is enabled

Platforms

[macOS]

Comparison

None

Fields

None

Passes when FileVault is turned on for the startup disk. To require that FileVault is off, tick NOT.

Things to know
  • A Mac where FileVault has been enabled by MDM but has not restarted yet fails. FileVault only turns on after the restart.

  • A Mac that is still encrypting its disk for the first time already passes. Unlike BitLocker, there is no separate check for encryption finished.

  • If macOS does not give a clear answer in time, the check reports an error.

www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013