Knowledge Base
Browse Docs
  • Introduction
    1. DefensX
    2. DNS & Web Filtering
    3. Zero Trust Files
    4. Zero Trust Credentials
    5. ADWare Protection
    6. Remote Browser Isolation
    7. Secure Browser Extension
    8. Secure Mobile Browser
    9. System & Browser Requirements
  • Deployment
    1. Deployment via RMM
    2. Operating System Agent
    3. Deployment via GPO
    4. Deployment via Intune
    5. VDI and Remote Desktop Services (RDS)
    6. Windows Manual Deployment
    7. Mac MDM Deployment
    8. Mac Manual Deployment
    9. Network Deployment
    10. Secure Mobile Browser
    11. Bypass Option
    12. SaaS Restrictions
    13. Bookmark Manager
    14. Remote Uninstall
    15. Bulk Create Customers
  • Management
    1. Role-Based Access Control
    2. Message Templates
    3. AI Protections
    4. LLM Prompt Logger
  • Integrations
    1. Azure AD
    2. Identity Providers
    3. SIEM
  • Nexi AI
    1. Nexi AI
    2. Nexi AI for MSPs
    3. Nexi AI for End Users
    4. Bookmark Prompts and Schedule Reports in Nexi AI
  • Policy Management
    1. Policy Groups
    2. Trust Profiles
    3. Consents
    4. PII Protection
    5. Time-Based Policy
    6. Malvertising Protection
    7. Login Guard
    8. Watermark
  • Secure Access (ZTBA, formerly ZTNA)
    1. Introduction to ZTBA
    2. Configuration
  • Auto Pilot
    1. Auto Pilot
  • Training Videos
    1. Onboarding Videos
    2. Attack Scenarios
    3. MSP Admin Training Series
  • Questions & Answers
    1. Licensing
    2. Incognito Mode
    3. Onboarding
    4. Active Directory
    5. Group Synchronization
    6. Agent
    7. Conflicting Softwares
    8. Reporting
    9. Virtual Desktops
    10. Using the Backend
    11. DNS & Web Filtering
    12. Managing AI Tool Access
  • MSP Automation
    1. Overview
    2. External Notifications
    3. Integrations
    4. Partner API
ONLINE DOCUMENTATION

Domain checks in Trust Profile

In this document
  • Active Directory
    • Windows Machine Role
    • Windows AD Domain DNS Name
    • Windows AD Domain NETBIOS Name
    • Windows AD Domain GUID
  • Microsoft Entra ID
    • EntraID Join Type
    • EntraID Device Joined Tenant ID
  • macOS
    • macOS machine role

Domain checks ask who manages the computer. On Windows that means Active Directory membership and Microsoft Entra ID (formerly Azure AD) join. On macOS it means MDM enrollment. Use them to tell company-managed devices apart from personal ones.

trust profile domain checks

Supported platforms: [Windows, macOS]

Check Platforms

Windows Machine Role

[Windows]

Windows AD Domain DNS Name

[Windows]

Windows AD Domain NETBIOS Name

[Windows]

Windows AD Domain GUID

[Windows]

EntraID Join Type

[Windows]

EntraID Device Joined Tenant ID

[Windows]

macOS machine role

[macOS]

Active Directory

Windows Machine Role

Platforms

[Windows]

Comparison

equals, does not equal

Fields

Role (required, chosen from a list)

Checks the computer’s role with respect to an Active Directory domain:

Role Meaning

StandaloneWorkstation

A client computer that is not joined to a domain.

MemberWorkstation

A client computer joined to a domain.

StandaloneServer

A server that is not joined to a domain.

MemberServer

A server joined to a domain.

BackupDomainController

A domain controller.

PrimaryDomainController

The domain controller holding the PDC emulator role.

Unlike the other Active Directory checks, this one answers on every Windows computer, because a computer outside a domain still has a role. Use it to require domain membership, for example equals MemberWorkstation.

Windows AD Domain DNS Name

Platforms

[Windows]

Comparison

equals, does not equal

Fields

DNS name (required)

Compares the DNS name of the Active Directory domain the computer is joined to, for example corp.example.com. The comparison is not case sensitive.

This is the usual way to require joined to our domain.

Windows AD Domain NETBIOS Name

Platforms

[Windows]

Comparison

equals, does not equal

Fields

NetBIOS name (required)

Compares the short (NetBIOS) name of the domain. This is the part before the backslash in CORP\username. The comparison is not case sensitive.

Note
Windows keeps the workgroup name in the same place. A computer that is not in a domain reports its workgroup name here, usually WORKGROUP. Prefer Windows AD Domain DNS Name or Windows AD Domain GUID when the result matters.

Windows AD Domain GUID

Platforms

[Windows]

Comparison

equals, does not equal

Fields

GUID (required, in the form 11111111-2222-3333-4444-555555555555)

Compares the unique identifier of the domain. A domain can be renamed but its GUID never changes, so this is the most precise way to identify our domain.

Enter the GUID without braces. To find it, run (Get-ADDomain).ObjectGUID in PowerShell on a computer with the Active Directory PowerShell module installed.

Things to know for the Active Directory checks
  • On a computer that is not in a domain, the DNS Name and GUID checks fail for both equals and does not equal. Add Windows Machine Role when a computer may not be joined.

  • The agent refreshes domain information every few minutes. After a computer joins or leaves a domain, the checks can keep reporting the old state for up to six minutes.

Microsoft Entra ID

Important
Both Entra ID checks fail on computers that are also joined to an Active Directory domain (hybrid-joined computers), whatever their Entra ID state. They describe cloud-only joined devices. If your fleet includes hybrid-joined computers, cover them with an Active Directory check as well. Put both in a group set to Match any check, for example EntraID Join Type equals Device or Windows AD Domain DNS Name equals corp.example.com.

EntraID Join Type

Platforms

[Windows]

Comparison

equals, does not equal

Fields

Join type (required, chosen from a list)

Join type Meaning

Device

The computer is joined to Entra ID and owned by the organization.

Workplace

A personal computer where someone added a work account (Entra registered).

To require company-owned devices, use equals Device.

EntraID Device Joined Tenant ID

Platforms

[Windows]

Comparison

equals, does not equal

Fields

Tenant ID (required, in the form 11111111-2222-3333-4444-555555555555)

Checks that the computer is joined to a specific Entra ID tenant. This is a strict check. Computers that are only registered (join type Workplace) fail it, even when the account on them belongs to your tenant.

You can find your Tenant ID in the Microsoft Entra admin center under Overview. On a computer, run dsregcmd /status and look for TenantId.

macOS

macOS machine role

Platforms

[macOS]

Comparison

equals, does not equal

Fields

Role (required)

Checks whether the Mac is enrolled in an MDM. Type one of these two values:

Role Meaning

MDMManaged

The Mac is enrolled in an MDM, in any way.

Unmanaged

The Mac is not enrolled in any MDM.

To require MDM-managed Macs, use equals MDMManaged.

Note
This field is free text. Type the value exactly as shown. The comparison is not case sensitive, but a misspelled value never matches, so equals always fails and does not equal always passes.

MDMManaged covers every kind of MDM enrollment, including a user-approved enrollment that the user can remove.

www.defensx.com
Secure Industries, Inc 101 Avenue of The Americas, Floor 9 New York, NY 10013