Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Remote Desktop Services (RDS)
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Policy Groups
    2. Trust Profiles
    3. Consents
    4. PII Protection
    5. Time-Based Policy
    6. Malvertising Protection
    7. Login Guard
    8. Watermark
  • Secure Access (ZTBA, formerly ZTNA)
    1. Introduction to ZTBA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Network checks in Trust Profile

In this document
  • IP Country

Network checks are about where the endpoint connects from, not about the device itself. They are set in the Generic row of a profile and apply to every platform.

Supported platforms: [Generic: Windows, macOS, iOS, Android]

IP Country

Platforms

[Generic: Windows, macOS, iOS, Android]

Comparison

equals, does not equal

Fields

Country codes (required, one or more countries)

Checks the country the endpoint’s connection comes from, as seen by the DefensX network.

  • equals passes when the country is any of the selected countries. Use it as an allow list, for example only from the United States and Canada.

  • does not equal passes when the country is none of the selected countries. Use it as a deny list.

To set it up, open the Generic row of the profile, click Add a check and choose IP Country under Network. Pick the countries from the list. The most frequently used countries, plus the country you are browsing from, are shown at the top. You can type to search, and Clear all removes the selection.

trust profile country checks
Things to know
  • The country comes from the connection, not from the device’s physical location. A device using a VPN, a proxy or a mobile network that exits in another country is judged by that country.

  • Generic checks are required on top of the platform checks. A Windows computer must pass the Windows group and the IP Country check.

  • A group can contain only one IP Country check. Put every country you need in that one check.

  • A connection that the network cannot place in any country fails an equals list and passes a does not equal list. If blocking unplaced connections matters to you, use equals (an allow list).

  • If the agent has not received a country for its connection yet, the check reports an error and the endpoint does not pass.

Tip
An allow list (equals) is safer than a deny list (does not equal). A new or unplaced country is kept out by an allow list but let through by a deny list.
www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013