Browse Docs
-
Introduction
-
Deployment
- Deployment via RMM
- Operating System Agent
- Deployment via GPO
- Deployment via Intune
- VDI and Remote Desktop Services (RDS)
- Windows Manual Deployment
- Mac MDM Deployment
- Mac Manual Deployment
- Network Deployment
- Secure Mobile Browser
- Bypass Option
- SaaS Restrictions
- Bookmark Manager
- Remote Uninstall
- Bulk Create Customers
-
Management
-
Integrations
-
Nexi AI
-
Policy Management
-
Secure Access (ZTBA, formerly ZTNA)
-
Auto Pilot
-
Training Videos
-
Questions & Answers
-
MSP Automation
ONLINE DOCUMENTATION
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Security checks in Trust ProfileIn this document
Security checks cover the built-in protections that most device compliance policies ask for: firewall, disk encryption and antivirus.
Supported platforms: [Windows, macOS]
Firewall is enabled
Passes when Windows Defender Firewall is on for all three profiles: Domain, Private and Public. To require that the firewall is off, tick NOT. Things to know
BitLocker protection is on
Passes when BitLocker protection is active on the drive. This is the check to use for disk encryption compliance. Leave Drive empty to check the drive Windows is installed on. This is not always BitLocker drive is encrypted
Passes when the drive is fully encrypted, whether or not protection is currently active. This is the weaker check. Windows suspends BitLocker protection on its own during some feature updates, and while suspended the encryption key is stored on the disk unprotected. The two BitLocker state checks answer as follows:
Use BitLocker protection is on for compliance. Use BitLocker drive is encrypted only when you need to tell a drive that has never been encrypted apart from one where protection is suspended. BitLocker encryption method
Checks which cipher the drive is encrypted with. Choose the Method from the list:
To require 256-bit or stronger, add two checks, equals XTS-AES 256 and equals AES 256 (CBC), and set the group to Match any check. Match applies to the whole platform group. If your Windows group has other checks that must all pass, put the two method checks in a second rule group instead, and set An endpoint passes when to every rule group holds.
Things to know for all BitLocker checks
Antivirus is installed
Passes when an antivirus product is registered with Windows Security Center. Leave Product name empty to accept any product. To require a specific product, enter its display name as a glob pattern, for example Antivirus is enabled
Passes when a registered antivirus product is turned on. This is the check to use for antivirus compliance. Leave Product name empty to accept any active product.
Antivirus is up to date
Passes when a registered antivirus product is enabled and its detection signatures are up to date. Leave Product name empty to accept any product. Windows Server
Windows Server editions don’t have Windows Security Center, so on servers the three antivirus checks ask Microsoft Defender directly:
For servers that run a third-party antivirus, use a Process Running (by path) check for that product instead. FileVault is enabled
Passes when FileVault is turned on for the startup disk. To require that FileVault is off, tick NOT. Things to know
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||