Security8 min read

Understanding Security Hardening Checks

Sentrivox runs 8 critical Windows security checks on every endpoint. Learn what each check means, why it matters, and how to fix failing checks.

What are hardening checks?

Security hardening checks verify that each Windows endpoint is configured safely. Even fully patched machines are vulnerable if basic settings — like the firewall, RDP authentication, or the Guest account — are misconfigured. Sentrivox runs 8 critical checks on every endpoint, on every heartbeat, and flags anything that fails.

ℹ️
Checked continuously
These checks don't run once — they run on every agent heartbeat, so if a setting drifts out of compliance, you find out quickly.

The 8 checks Sentrivox runs

1. Windows Firewall
The first line of defense against unauthorized network access. Sentrivox verifies all three firewall profiles (Domain, Private, Public) are enabled.
2. Windows Defender Antivirus
Real-time malware protection. Sentrivox checks that Defender and real-time protection are enabled and that definitions are current.
3. Guest Account
An enabled built-in Guest account lets anyone log in without credentials. Sentrivox flags any endpoint where Guest is enabled.
4. RDP Network Level Authentication
Without NLA, Remote Desktop exposes the login screen to unauthenticated users. Sentrivox checks NLA is enforced wherever RDP is configured.
5. SMBv1 Protocol
SMBv1 is the protocol exploited by WannaCry and NotPetya. Sentrivox flags any endpoint where this deprecated protocol is still enabled.
6. Password Policy
Weak password rules invite brute-force and password-spray attacks. Sentrivox checks minimum length, complexity, and lockout settings.
7. Windows Automatic Updates
Unpatched systems are the top ransomware entry point. Sentrivox checks that automatic updates are enabled and applied.
8. RDP Encryption Level
Weak RDP encryption is vulnerable to interception. Sentrivox verifies the encryption level is set to High or FIPS.

Reading check results in the portal

In the Security section, each endpoint shows a pass/fail status for all 8 checks. Failing checks are grouped by severity so you can prioritize:

  • Critical — issues like a disabled firewall, disabled Defender, or SMBv1 enabled. Fix these first.
  • High — issues like an enabled Guest account, missing RDP NLA, or weak passwords.
  • Passing — checks that are correctly configured and need no action.

Fixing a failing check

Each finding in the portal explains what failed and why it matters. To remediate, apply the correct Windows configuration on the affected endpoint — typically through Group Policy, local security settings, or PowerShell. On the next heartbeat, Sentrivox re-checks the setting and the finding clears automatically once it's resolved.

💡
Fix once, verify automatically
You don't need to manually mark findings as resolved. Correct the setting, and Sentrivox confirms the fix on the next check-in.

Related articles

Still need help?

Our team is here to help you get the most out of Sentrivox. Reach out any time and we'll get back to you fast.

Contact Support →Request a Demo