Understanding Security Hardening Checks
Sentrivox runs 8 critical Windows security checks on every endpoint. Learn what each check means, why it matters, and how to fix failing checks.
What are hardening checks?
Security hardening checks verify that each Windows endpoint is configured safely. Even fully patched machines are vulnerable if basic settings — like the firewall, RDP authentication, or the Guest account — are misconfigured. Sentrivox runs 8 critical checks on every endpoint, on every heartbeat, and flags anything that fails.
The 8 checks Sentrivox runs
Reading check results in the portal
In the Security section, each endpoint shows a pass/fail status for all 8 checks. Failing checks are grouped by severity so you can prioritize:
- Critical — issues like a disabled firewall, disabled Defender, or SMBv1 enabled. Fix these first.
- High — issues like an enabled Guest account, missing RDP NLA, or weak passwords.
- Passing — checks that are correctly configured and need no action.
Fixing a failing check
Each finding in the portal explains what failed and why it matters. To remediate, apply the correct Windows configuration on the affected endpoint — typically through Group Policy, local security settings, or PowerShell. On the next heartbeat, Sentrivox re-checks the setting and the finding clears automatically once it's resolved.
