Device hardening
Hold Windows, macOS and Linux devices to hardening baselines, audit first, enforce in rings with approvals, roll back any change, and see drift the moment a setting moves.
- 1 Device hardening overview What device hardening does in Tenvara, how audit, enforcement, rollback and drift fit together, and where to find it.
- 2 The setting library and baselines Browse the 424 hardening settings in plain words, use the shipped baselines, and build and version your own.
- 3 Assigning and auditing Assign baselines at every policy level, override single settings, agree exceptions with the customer, and read compliance and what enforcing would change.
- 4 Enforcing in rings and rolling back Start an enforcement run, get it approved, let the pilot ring prove it inside maintenance windows, then roll back a run, a device or a single setting.
- 5 Group Policy and Intune How hardening works beside Group Policy and Microsoft Intune, reads what they already set, never fights them, and pushes a baseline to Intune as a settings catalog policy.
- 6 Drift and reporting Drift alerts that name who changed a setting, keep enforced to put it back, fights between tools, and hardening in the overview, Home, the monthly report and the customer portal.
- 7 macOS and Linux What hardening reads and sets on Macs through the agent, and the read-only checks for Ubuntu and Debian.