# How to integrate Drata with Hexnode UEM for Windows devices?

Drata is an advanced security and compliance automation platform whose primary mission entails constantly monitoring devices to ensure that they meet the compliance and security criteria set by organizations.

As we know, Hexnode UEM has a system that ensures that the fleet of devices managed by it is compliant. With Drata in the picture, it amplifies the same by collecting more information on each organization’s security status, extracting data from the devices, the UEM and other sources. Drata’s automated monitoring system constantly watches all the devices and IT admins receive notifications instantly if any device is out of compliance. Admins can also access the audit reports created by Drata to know exactly what went wrong in each device and when.

The Hexnode-Drata integration is supported on Windows and macOS devices. This document explains the steps involved in the integration for Windows devices.

Integrating Drata with Hexnode UEM
----------------------------------

Follow the steps given below to execute the integration:

- Connect Hexnode to Drata 
    1. Navigate to **Enroll** and make a note of the **Server URL**. ![Make note of server URL from Hexnode portal](https:2023/03/Server-URL-in-Hexnode-portal.png "Server URL in Hexnode portal")
    2. Navigate to **Admin** > **API**.
    3. Click the lock icon to view the API key and make a note of it too. ![Make note of API Key from Hexnode portal](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2023/03/API-key-from-Hexnode-portal.png "API key in Hexnode portal")
    4. Login to your Drata portal.
    5. Click on your company’s name from the sidebar and click **Connections**.
        ![Navigate to Connections in the Drata portal](https:2023/03/Connections-in-Drata-portal.png "Connections in the Drata portal")
    6. Find Hexnode from the list and click **Connect**. ![Select Hexnode from list of connections in Drata portal](https:2023/03/Choose-Hexnode-from-list-of-connections.png "Choose Hexnode from list of connections")
    7. Enter the previously noted Server URL in the **API URL** field. Remember to include https:// at the beginning of the URL. ![Enter server URL in Drata portal](https:2023/03/Enter-server-URL-in-API-URL-field.png "Enter server URL in API URL field")
    8. Enter the previously noted API key in the **API Token** field.
    9. Click **Save & Test Connection**. ![Enter Hexnode’s API key in Drata portal](https:2023/03/Enter-API-key-in-API-token-field.png "Enter API key in API token field")
    10. Click on your company’s name from the sidebar again and click **Internal Security**. ![Navigate to Internal Security in the Drata portal](https:2023/03/Interal-Security-in-Drata-portal.png "Internal Security in Drata portal")
    11. Turn the **Automated via Hexnode MDM** toggle on and the **Automated via Drata** toggle off. If both options are enabled and the Drata agent is installed on the device, then the compliance data will come from the Drata agent and not Hexnode UEM. ![Enable Automated via Hexnode UEM option](https:2023/03/Automated-via-Hexnode-UEM.png "Automated via Hexnode UEM")
- Login to the Hexnode UEM portal.
The BitLocker, Password and Microsoft Defender policies have to be configured in the Hexnode UEM portal in order to collect compliance data that correspond to windows disk encryption, lock screen and antivirus respectively.

- Configure the BitLocker policy: 
    1. Navigate to **Policies** > **New Policy** > **New Blank Policy**.
    2. Click **Select**.
    3. Provide a suitable policy name.
    4. Navigate to **Windows** > **Security** > **BitLocker** and click **Configure**.
    5. Ensure that the **Prompt for device encryption** box is checked and configure the remaining fields as per requirement. You may refer to our document on [managing BitLocker](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/) for further details and step-wise explanations.
    6. Navigate to **Policy Targets** > **Add devices** and select the devices to be configured.
    7. Click **Save**. ![Configure the BitLocker policy in Hexnode portal](https:2023/03/Configure-BitLocker-policy.png "Configure BitLocker policy")
- Configure the Password policy: 
    1. Navigate to **Policies** > **New Policy** > **New Blank Policy**.
    2. Click **Select**.
    3. Provide a suitable policy name which includes the term “*Screensaver*” so that Drata can detect the policy.
    4. Navigate to **Windows** > **Password** and click **Configure**.
    5. Set the Auto-lock (in minutes) option to a value greater than 0 and configure the remaining fields as per requirement. Check out our document on [configuring password policy for Windows devices](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-password-policy-for-windows/) for further guidance.
    6. Navigate to **Policy Targets** > **Add devices** and select the devices to be configured.
    7. Click **Save**. ![Configure the password policy in Hexnode portal](https:2023/03/Configure-password-policy.png "Configure password policy")
- Configure the Microsoft Defender policy: 
    1. Navigate to **Policies** > **New Policy** > **New Blank Policy**.
    2. Click **Select**.
    3. Provide a suitable policy name which includes the term “*Anti-Virus*” so that Drata can detect the policy.
    4. Navigate to **Windows** > **Threat Management** > **Microsoft Defender** and click **Configure**.
    5. Check the following options under **Windows Defender Security Center**: 
        - Enable account protection UI
        - Enable app and browser protection UI
        - Enable device security UI > Show the Security processor (TPM) troubleshooting area
        - Enable family UI
        - Enable health UI
        - Enable network UI
        - Enable virus UI
    6. Refer to our document on [enabling Microsoft Defender](https://www.hexnode.com/mobile-device-management/help/how-to-enable-windows-defender-settings-for-windows-pc-using-hexnode-mdm/) to configure the rest of the settings.
    7. Navigate to **Policy Targets** > **Add devices** and select the devices to be configured.
    8. Click **Save**. ![Configure the Microsoft Defender policy in Hexnode portal](https:2023/03/Configure-Microsoft-Defender-policy.png "Configure Microsoft Defender policy")

The integration is now complete and Drata will begin collecting essential data regarding Windows devices enrolled in Hexnode UEM.