Skip to main content

66 docs tagged with "Certificates"

Documents on digital certificates and their implementation and management

View all tags

Boot Environment Audit

Audits the boot environment, Secure Boot certificates, OEM updates, telemetry, and cumulative update status on a Windows device and returns the results as an object.

Boot Environment Audit

Sets this custom field to 1 when the script runs successfully, indicating that the boot environment has been audited and data is available in the other custom fields.

Boot Environment Audit

The script audits Windows boot security and populates 24 custom fields (SB_ prefix) with critical data: Secure Boot status, UEFI CA 2023 certificate enrollment, OEM driver updates, cumulative update readiness, BIOS versions, firmware boot entries, WinRE status, telemetry configuration, and registry servicing values. It downloads and executes the core audit script, transforms output for RMM database compatibility, and exports JSON results for custom field integration, enabling administrators to track boot security posture and compliance across managed endpoints.

Boot Environment Audit

A centralized dashboard to monitor Windows boot security across all endpoints. Instantly identify missing OEM updates, Secure Boot status, CA 2023 readiness, and potential boot misconfigurations.

Boot Environment Audit

This solution outlines the automated process for auditing the boot environment and security configuration of Windows endpoints using ConnectWise RMM.

Boot Environment Audit

Audits the boot environment, Secure Boot certificates, OEM updates, telemetry, and cumulative update status across Windows devices and stores the results for fleet-wide reporting.

Certificate Expiration 30 Days

This monitor looks for any SSL certificates that have an expiration date of less than 30 days. This solution is effective for catching machines that may have been missed and do not have active reminders in place for certificate renewals. Additionally, the difference between the certification addition and expiration should be at least 30 days to trigger an alert.

Certificate Expiration Monitoring

This solution outlines the steps for identifying and monitoring Windows certificates that are set to expire within the next 30 days through CW RMM.

cPVAL Install Cisco Umbrella Root CA Certificate

Flag this checkbox to enable installation of the Cisco Umbrella Root CA certificate on all Windows and Mac devices managed for the client. This ensures secure SSL inspection and trusted communication with Cisco Umbrella services.

cPVAL SecureBoot Check

This document describes a custom field that tracks the secureboot status on machines, detailing its dependencies and specific field information relevant to machine management.

cPVAL SecureBoot Status

This task checks and records the SecureBoot status on devices, including SecureBoot certificates.

cPVAL Windows Telemetry Status

This custom field indicates the current telemetry (diagnostic data) level on Windows. Shows whether Windows telemetry is enabled and its level (Basic, Enhanced, Full)

Deploy Cisco Umbrella Root CA Certificate

This group contains all client machines (Windows and Mac) where the organization-level custom field "cPVAL Install Cisco Umbrella Root CA Certificate" is enabled. A task runs daily against this group to install or verify the Cisco Umbrella.

Get-BootEnvironmentDetails

Audits the boot environment, Secure Boot certificates, OEM updates, telemetry, and cumulative update status on a Windows device and returns the results as an object.

Remediate-SecureBootCompliance2026

This script remediates UEFI Secure Boot compliance for Windows 2026 by ensuring systems have the required 2023 UEFI certificates (KEK and db), enabling Microsoft-managed certificate updates, and reporting the remediation status. It validates Secure Boot, configures registry keys for automatic updates, monitors servicing status, and logs results.

Remediation SecureBoot 2026 Compliance

This script automates the remediation of UEFI Secure Boot certificates required for Windows 2026 compliance. It ensures the system has the latest 2023 UEFI certificates (KEK and db) and configures the system for automatic Microsoft-managed UEFI certificate updates.

Remediation SecureBoot 2026 Compliance

This script automates the remediation of UEFI Secure Boot certificates required for Windows 2026 compliance. It ensures the system has the latest 2023 UEFI certificates (KEK and db) and configures the system for automatic Microsoft-managed UEFI certificate updates.

SB_Available_Updates

Secure Boot registry AvailableUpdates value. Updated by the Boot Environment Audit task.

SB_BiosVersion

Current BIOS version string from Win32_BIOS. Updated by the Boot Environment Audit task.

SB_BucketHash

Secure Boot servicing BucketHash registry value. Updated by the Boot Environment Audit task.

SB_Confidence_Level

Secure Boot servicing ConfidenceLevel registry value. Updated by the Boot Environment Audit task.

SB_Confidence_Update_Type

Secure Boot servicing ConfidenceUpdateType registry value. Updated by the Boot Environment Audit task.

SB_Data_Collection_Time

Timestamp when boot environment data was last collected. Updated by the Boot Environment Audit task.

SB_DualBoot_Evidence

Evidence lines from bcdedit for non-Windows EFI indicators. Updated by the Boot Environment Audit task.

SB_Nov_2025_CU_Installed

Whether November 2025 or newer cumulative update is installed. Updated by the Boot Environment Audit task.

SB_OEM_Updates_Count

Number of available OEM driver updates. Updated by the Boot Environment Audit task.

SB_Present_Conditions

Comma-separated summary of detected boot conditions. Updated by the Boot Environment Audit task.

SB_PXE_Evidence

Evidence lines from bcdedit for PXE/network boot indicators. Updated by the Boot Environment Audit task.

SB_PXE_Present

Whether PXE or network boot entries are detected in firmware. Updated by the Boot Environment Audit task.

SB_SecureBoot_Status

Secure Boot state: Enabled, Disabled, or Unknown. Updated by the Boot Environment Audit task.

SB_Telemetry_Status

Windows telemetry state based on registry and DiagTrack service. Updated by the Boot Environment Audit task.

SB_UEFICA2023_Error

Secure Boot servicing UEFICA2023Error registry value. Updated by the Boot Environment Audit task.

SB_UEFICA2023_Status

Secure Boot servicing UEFICA2023Status registry value. Updated by the Boot Environment Audit task.

SB_WinRE_Enabled

Whether Windows Recovery Environment is enabled on the device. Updated by the Boot Environment Audit task.

Secure Boot Compliance Audit

This solution checks the Secure Boot status and validates the associated certificates. If the system is using older Secure Boot certificates, the custom fields are updated accordingly. If the system is using updated certificates. The custom fields are updated to reflect the compliant status.

SecureBoot 2026 Compliance Check

This script evaluates whether a Windows device is prepared for the upcoming Microsoft Secure Boot certificate transition scheduled for 2026. Microsoft is replacing legacy Secure Boot certificates with updated 2023-era certificates (KEK and DB). Devices that do not contain these updated certificates may be considered at risk once older certificates expire.

SecureBoot 2026 Compliance Check

This script evaluates whether a Windows device is prepared for the upcoming Microsoft Secure Boot certificate transition scheduled for 2026. Microsoft is replacing legacy Secure Boot certificates with updated 2023-era certificates (KEK and DB). Devices that do not contain these updated certificates may be considered at risk once older certificates expire.

SecureBoot Compliance - Audit

This script evaluates whether a Windows device is prepared for the upcoming Microsoft Secure Boot certificate transition scheduled for 2026.

Secureboot Remediation and Audit Solution

This solution checks the Secure Boot status and validates the associated certificates. If the system is using older Secure Boot certificates, the custom fields are updated accordingly. If the system is using updated certificates, the custom fields are updated to reflect the compliant status.

SSL Certificate Audit

This Script pulls any and all certificates in the personal certificate repository on windows machines that it is run on.

Windows Secure Boot Audit

Fetches the status of key certificate and configurations that will be needed before the current secure boot certificates expire.

Windows Secure Boot Audit

This solution fetches the status of key certificate and configurations that will be needed before the current secure boot certificates expire.