# How to use pre-configured policy template in Hexnode UEM for easy policy deployment

Hexnode UEM Policy Template is a set of pre-configured policies that you can use to create new policies and associate them to required target devices. Apart from the default policy templates, you can also create new templates in the Hexnode portal.
To associate a policy template to a target device, you have to first copy it to My Policies. You can either use the copied template directly, or you can modify the template policy to attach it to the devices. With Hexnode, you can create more than one policy using the same policy template. So, to create multiple policies with the same configuration, you just have to create one template and make its copy.
Hexnode’s Pre-defined Policy Templates include:

- [Android Website kiosk](#website)
- [BitLocker Security Policy](#bitlocker)
- [BYOD Policy for Corporate Data Containerization](#container)
- [Expense Management Policy](#expense)
- [HIPAA Compliance Policy](#hippa)
- [iOS Single App Kiosk Policy](#single-app)
- [Location Policy](#locate)
- [Samsung Knox Policy](#knox)
- [Standard DLP Policy](#dlp)
- [CIS Benchmark Compliance Level 1 – macOS ](#CIS-macOS%20Level-1)
- [CIS Benchmark Compliance Level 2 – macOS ](#CIS-macOS%20Level-2)
- [CIS Benchmark Compliance – Windows](#CIS%20Windows)
- [CIS Benchmark Compliance (Windows 10: Level 1 + BitLocker) – Standalone ](#CIS%20Windows%2010%20L1%20BitLocker%20Standalone)
- [CIS Benchmark Compliance (Windows 10: Level 1 + BitLocker) – Hybrid Joined ](#CIS%20Windows%2010%20L1%20BitLocker%20Hybrid%20Joined)
- [CIS Benchmark Compliance (Windows 10: Level 1 + BitLocker) – Microsoft Entra ID](#CIS%20Windows%2010%20L1%20BitLocker%20Microsoft%20Entra%20ID)
- [CIS Benchmark Compliance (Windows 11: Level 1 + BitLocker) – Standalone](#CIS%20Windows%2011%20L1%20BitLocker%20Standalone)
- [CIS Benchmark Compliance (Windows 11: Level 1 + BitLocker) – Hybrid Joined](#CIS%20Windows%2011%20L1%20BitLocker%20Hybrid%20Joined)
- [CIS Benchmark Compliance (Windows 11: Level 1 + BitLocker) – Microsoft Entra ID](#CIS%20Windows%2011%20L1%20BitLocker%20Microsoft%20Entra%20ID)
- [POS Device Policy](#pos)
- [Website Kiosk for Android TV](#website-kiosk)
- [Kiosk Lockdown for Android TV](#android-tv-kiosk)
- [Android TV Security Settings](#android-tv-security)

 Note: 
Instead of creating large number of same policies by individually configuring each, you can [create a policy template](https://www.hexnode.com/mobile-device-management/help/how-to-create-modify-delete-or-clone-policies/#to-create-a-template) in Hexnode with the required configurations. And this single template can be reproduced to policies as many times as required.

 

Pre-configured templates in Hexnode:
------------------------------------

Android Website kiosk

A pre-configured policy template to lockdown Android devices to a couple of web apps in multi-app kiosk mode.

**Template name:** Android Website Kiosk

**Description:** Lock down Android devices to a handful of websites.

**Template Configuration:**

[Kiosk Lockdown > Android Kiosk Lockdown > Multi App](https://www.hexnode.com/mobile-device-management/help/enable-multi-app-kiosk-mode-android-devices/): Amazon feedback & Amazon affiliates.

 

 

 

BitLocker Security Policy

A policy that is pre-configured to provide the basic industrial standard BitLocker encryption along with Windows password security.

**Template name:** BitLocker Security Policy

**Description:** Enable BitLocker encryption for industry-standard security.

**Template Configuration:**

- [Windows > Password](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-password-policy-for-windows/)
Password settingsConfigurationAllow simple valueDisabledPassword typeUsers can chooseMinimum Password length8Minimum complex charactersDigits onlyMinimum passcode age (in days)0Auto-Lock (in minutes)0Passcode history0Failed attempt before wipe0- [Windows > Security > BitLocker](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/)
BitLocker SettingsConfigurationPrompt to encrypt storage cardEnabledPrompt for device encryptionEnabledConfigure encryption method for disk drivesSelect default valueConfigure authentication when computer starts upEnableAllow BitLocker without a Trusted Platform Module (TPM)Select default valueAuthenticate with TPM startup keyDisallowAuthenticate with TPM startup pinDisallowAuthenticate with TPM startup key and PINDisallowEnable TPM during startupDisallowMinimum length for BitLocker startup PIN6Configure pre-boot recovery messageShow default recovery message and URLConfigure recovery options for system drivesDisabledConfigure recovery options for fixed drivesDisabledFixed drives require encryptionEnabledRemovable drives require encryptionEnabled

 

 

BYOD Policy for Corporate Data Containerization

A policy template to protect the corporate data in any iOS and Android BYOD device.

**Template name:** BYOD Policy for Corporate Data Containerization

**Description:** A common policy for iOS & Android devices to safeguard the corporate data in Managed apps and Work containers.

**Template Configuration:**

- [iOS > Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-ios-mdm-restrictions-using-hexnode-mdm/)
RestrictionsConfigurationAllow Device Functionality Camera Enabled FaceTime Enabled Screen capture Enabled Touch ID Enabled Siri Enabled Allow Siri while device is locked Enabled Voice dialing Enabled Automatic sync while roaming Enabled Allow Application Settings Show App Store on the device Enabled iTunes Store Enabled Force user to enter iTunes store password for each purchase Enabled In-app purchases Enabled Trust enterprise app Enabled Users can modify enterprise app trust Enabled Backup enterprise-deployed iBooks Enabled Sync managed app data with iCloud Disabled YouTube Enabled Safari Enabled Autofill Enabled Fraud warning Disabled JavaScript Enabled Block pop-ups Enabled Accept cookies Always Access Passbook when the device is locked Disabled Add friends in Game Center Enabled Allow iCloud SettingsBackupEnabledSync documentsEnabledPhoto Stream (Disallowing might cause data loss)EnabledShare photo streamsEnablediCloud photo libraryEnabledSync enterprise book metadata across devicesEnabledAllow Security and Privacy SettingsLock screen notificationsEnabledToday View on lock screenEnabledControl Centeron lock screenEnabledOver the air PKI updatesEnabledLimit ad trackingDisabledSend diagnostic data to AppleEnabledAccept untrusted TLS certificateEnabledForce encrypted backupDisabledShow notification on Apple Watch if wornDisabledAllow Explicit Content Explicit music, podcasts and iTunes U services Enabled iBooks store erotica Disabled Rating region United States Content ratingMoviesAllow All Movies TV Shows Allow All TV Shows Apps Allow All Apps - [iOS > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-ios-mdm-restrictions-using-hexnode-mdm/#advanced-restrictions)
RestrictionsConfigurationAllow Device FunctionalityAirDropEnabledApps can modify cellular data usageEnabledAdd or remove Touch ID/Face IDEnablediMessageEnabledGame CenterEnabledMultiplayer gamingEnabledPair with iTunesEnabledInstall configuration profileEnabledDefinition lookupEnabledPredictive keyboardEnabledAuto-correct wordsEnabledSuggest words on misspellingsEnabledKeyboard shortcutsEnabledPair with Apple WatchEnabledModify diagnostic data submission settingsEnabledModify Bluetooth settingsEnabledUse voice to typeEnabledConnect to MDM-configured Wi-Fi networks onlyDisabledUsers can modify Personal Hotspot settingsEnabledCreate VPN configurationEnabledAirPrintEnabledConnect with iBeaconEnabledStore AirPrint credentials in KeychainEnabledUse trusted certificates for secure printingDisabledAllow App SettingsInstall app from App StoreEnabledRemove appsEnabledRemove system appsEnablediBooks storeEnabledApple MusicEnablediTunes RadioEnabledNewsEnabledPodcastsEnabledDownload all purchased apps automaticallyEnabledAllow Security and Privacy SettingsActivation LockDisabledModify an accountEnabledErase content and settingsEnabledSiri can access user-generated contentEnabledModify Find My FriendsEnabledUse profanity filterDisabledShow web results using Spotlight SearchEnabledModify Restrictions/Screen TimeEnabledModify passcodeEnabledModify device nameEnabledModify wallpaperEnabledUsers can turn notifications on/offEnabledForce Automatic Date and TimeDisabledAutofill PasswordsEnabledRequest passwords from nearby devicesEnabledShare passwords via Airdrop Passwords featureEnabled- [iOS > Security > Business Container](https://www.hexnode.com/mobile-device-management/help/how-to-setup-business-container-for-ios-devices-using-hexnode-mdm/)
SettingsConfigurationOpen documents from managed apps in unmanaged appsDisabledOpen documents from unmanaged apps in managed appsDisabledManaged apps can write to Unmanaged Contact AccountsDisabledUnmanaged apps can read from Managed Contact AccountsDisabledBlock Sharing Managed Document using AirDropDisabled- [Android > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-android-mdm-restrictions-using-hexnode-mdm/#advanced-restrictions)
RestrictionsConfigurationAllow device functionalityMicrophoneEnabledScreen captureDisabledClipboardEnabledCopy contents between normal and work profilesEnabledShare via other appsEnabledUsers can adjust volumeEnabledMake a callEnabledDisplay SettingsHide System barsDisabledHide Status BarDisabledHide Navigation BarDisabledSplit-screen modeEnabledDisplay dialogs/windowsEnabledAllow Connectivity OptionsNFCEnabledAndroid BeamEnabledBeam from the deviceEnabledTransfer data via BluetoothEnabledConfigure BluetoothEnabledConfigure cell broadcastEnabledConfigure cellular networkEnabledUsers can reset network settingsEnabledConfigure Wi-FiEnabledConfigure hotspot and tetheringEnabledSecurity OptionsMinimum Wi-Fi Security LevelOpenAllow Sync SettingsSync data in backgroundEnabledSync data with Google accountEnabledAllow Account SettingsSMSEnabledReceive messagesEnabledSend messagesEnabledModify Accounts/UsersEnabledAdd UsersEnabledRemove UsersEnabledConfigure user credentialsEnabledAllow SettingsDeveloper modeEnabledUSB debuggingEnabledModify settingsEnabledPower saving modeEnabledUsers can enable location sharingEnabledFactory resetEnabledRead any connected physical external mediaEnabledUpdate date and time automaticallyEnabledSet time zone automaticallyEnabledDisable screen lock if the screen was turned offDisabledConfigure VPNEnabledAllow App SettingsInstall appsEnabledUninstall appsEnabledControl appsEnabledGoogle Play StoreEnabledVerify apps before installDisabledInstall apps from unknown sourcesDisabledApp Runtime PermissionsDefault permissionsParent profile app linkingEnabledFactory Reset Protection (Google Account Verification)Default

 

 

Expense Management Policy

An Android policy to set data and Wi-Fi restrictions and notifications to have control over expenses.

**Template name:** Expense Management Policy

**Description:** Data/Wi-Fi usage warning & restrictions for an arbitrary monthly limit.

**Template Configuration:** 
[Android > Mobile Data Management](https://www.hexnode.com/mobile-device-management/help/how-to-manage-mobile-data-usage-with-hexnode-mdm/)
Data Usage Restrictions:

RestrictionConfigurationEnable data usage trackingEnabledEnable network & data usage restrictionsEnabledNetwork RestrictionsNo RestrictionsData Usage Notifications**Notify both User and Admin, Monthly** when **Mobile data** exceeds **0.5 GB**Data Usage Restrictions**Restrict and notify all, Monthly** when **Mobile Data** exceeds **1 GB**Reset Data TrackingDaily at **18:30 (UTC +00:00) GMT Standard Time**, Monthly on day **1** of each month

 

 

HIPAA Compliance Policy

A policy with iOS and Android passcode and restriction along with Mac and Windows encryption configurations to set standards of confidentiality and integrity to protect ePHI.

**Template name:** HIPAA Compliance Policy

**Description:** Workstation and Device Security policies to protect ePHI.

**Template Configuration:**

- [iOS > Passcode](https://www.hexnode.com/mobile-device-management/help/password-policy-for-ios/)
PolicyConfigurationAllow simple valueDisabledRequire alpha numeric valueEnabledMinimum Passcode Length8Minimum complex characters1Minimum passcode age in days (0-730 days)30Auto Lock1 MinutePasscode History (1-50 passcodes)5Grace period for device lockImmediatelyFailed attempts (After the specified number of failed attempts, the device data will be wiped automatically)10- [iOS > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-ios-mdm-restrictions-using-hexnode-mdm/#advanced-restrictions)
RestrictionsConfigurationAllow Device FunctionalityAirDropEnabledApps can modify cellular data usageEnabledAdd or remove Touch ID/Face IDEnablediMessageEnabledGame CenterEnabledMultiplayer gamingEnabledPair with iTunesEnabledInstall configuration profileEnabledDefinition lookupEnabledPredictive keyboardEnabledAuto-correct wordsEnabledSuggest words on misspellingsEnabledKeyboard shortcutsEnabledPair with Apple WatchEnabledModify diagnostic data submission settingsEnabledModify Bluetooth settingsEnabledUse voice to typeEnabledConnect to MDM-configured Wi-Fi networks onlyDisabledUsers can modify Personal Hotspot settingsEnabledCreate VPN configurationEnabledAirPrintEnabledConnect with iBeaconEnabledStore AirPrint credentials in KeychainEnabledUse trusted certificates for secure printingDisabledAllow App SettingsInstall app from App StoreEnabledRemove appsEnabledRemove system appsEnablediBooks storeEnabledApple MusicEnablediTunes RadioEnabledNewsEnabledPodcastsEnabledDownload all purchased apps automaticallyEnabledAllow Security and Privacy SettingsActivation LockDisabledModify an accountEnabledErase content and settingsEnabledSiri can access user-generated contentEnabledModify Find My FriendsEnabledUse profanity filterDisabledShow web results using Spotlight SearchEnabledModify Restrictions/Screen TimeEnabledModify passcodeEnabledModify device nameEnabledModify wallpaperEnabledUsers can turn notifications on/offEnabledForce Automatic Date and TimeDisabledAutofill PasswordsEnabledRequest passwords from nearby devicesEnabledShare passwords via Airdrop Passwords featureEnabled- [iOS > Security > Business Container](https://www.hexnode.com/mobile-device-management/help/how-to-setup-business-container-for-ios-devices-using-hexnode-mdm/)
SettingsConfigurationOpen documents from managed apps in unmanaged appsEnabledOpen documents from unmanaged apps in managed appsEnabledManaged apps can write to Unmanaged Contact AccountsDisabledUnmanaged apps can read from Managed Contact AccountsDisabledBlock Sharing Managed Document using AirDropDisabled- [Android > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-android-mdm-restrictions-using-hexnode-mdm/#advanced-restrictions)
RestrictionsConfigurationAllow device functionalityMicrophoneEnabledScreen captureEnabledClipboardEnabledCopy contents between normal and work profilesDisabledShare via other appsEnabledUsers can adjust volumeEnabledMake a callEnabledDisplay SettingsHide System barsDisabledHide Status BarDisabledHide Navigation BarDisabledSplit-screen modeEnabledDisplay dialogs/windowsEnabledAllow Connectivity OptionsNFCEnabledAndroid BeamEnabledBeam from the deviceEnabledTransfer data via BluetoothEnabledConfigure BluetoothEnabledConfigure cell broadcastEnabledConfigure cellular networkEnabledUsers can reset network settingsEnabledConfigure Wi-FiEnabledConfigure hotspot and tetheringEnabledSecurity OptionsMinimum Wi-Fi Security LevelOpenAllow Sync SettingsSync data in backgroundEnabledSync data with Google accountEnabledAllow Account SettingsSMSEnabledReceive messagesEnabledSend messagesEnabledModify Accounts/UsersEnabledAdd UsersEnabledRemove UsersEnabledConfigure user credentialsEnabledAllow SettingsDeveloper modeDisabledUSB debuggingDisabledModify settingsEnabledPower saving modeEnabledUsers can enable location sharingEnabledFactory resetEnabledRead any connected physical external mediaEnabledUpdate date and time automaticallyEnabledSet time zone automaticallyEnabledDisable screen lock if the screen was turned offDisabledConfigure VPNEnabledAllow App SettingsInstall appsEnabledUninstall appsEnabledControl appsEnabledGoogle Play StoreEnabledVerify apps before installDisabledInstall apps from unknown sourcesDisabledApp Runtime PermissionsDefault permissionsParent profile app linkingEnabledFactory Reset Protection (Google Account Verification)Default- [Windows > Security > BitLocker](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/)
BitLocker SettingsConfigurationPrompt to encrypt storage cardEnabledPrompt for device encryptionEnabledConfigure encryption method for disk drivesSelect default valueConfigure authentication when computer starts upSelect default valueMinimum length for BitLocker startup PIN6Configure pre-boot recovery messageSelect default valueConfigure recovery options for system drivesDisabledConfigure recovery options for fixed drivesDisabledFixed drives require encryptionEnabledRemovable drives require encryptionEnabled- [macOS > Security > FileVault](https://www.hexnode.com/mobile-device-management/help/how-to-manage-filevault-with-hexnode-mdm/)
Policy SettingsConfigurationEnable FileVaultEnabledEncrypt usingInstitutional and Personal Recovery KeyEncryption certificateHexnodeMDM FileVault CertificateShow Personal Recovery Key to userEnabledSkip enabling FileVault at user loginDisabled

 

 

iOS Single App Kiosk Policy

A preconfigured policy to restrict an iOS device to a single app in kiosk mode.

**Template name:** iOS Single App Kiosk Policy

**Description:** Lock down iOS devices to a single app

**Template Configuration:**

[Kiosk Lockdown > iOS Kiosk Lockdown > Single App](https://www.hexnode.com/mobile-device-management/help/how-to-enable-kiosk-mode-for-ios/)

Uber Technologies Inc. is added as the app in single app kiosk.

FeatureConfigurationAdvanced Kiosk SettingsDisable touchDisabledDisable device screen rotationDisabledDisable volume buttonsDisabledDisable ringer switchEnabledDisable sleep wake buttonDisabledDisable auto lockDisabledEnable VoiceOverDisabledEnable ZoomDisabledEnable invert colorsDisabledEnable AssistiveTouchDisabledEnable speak selectionDisabledUser Enabled OptionsVoiceOverEnabledZoomEnabledInvert colorsDisabledAssistiveTouchDisabled

 

 

Location Policy

A pre-configured location tracking policy that tracks the devices’ location in specific time intervals.

**Template name:** Location Policy

**Description:** Enable Location Tracking on target devices.

**Template Configuration:**
[General Settings > Location Tracking](https://www.hexnode.com/mobile-device-management/help/how-to-configure-location-tracking-with-hexnode-mdm/)

PolicyDescriptionEnable Location TrackingEnabledLocation Update Interval1 Hrs

 

 

Samsung Knox Policy

A policy template for Samsung Knox device security.

**Template name:** Samsung Knox Policy

**Description:** With advanced restrictions exclusively available for Samsung devices.

**Template Configuration:**

- [Android > Password > Device Password ](https://www.hexnode.com/mobile-device-management/help/password-policy-for-android/)
Password SettingsConfigurationPassword RequirementAlphanumericMinimum Passcode Length8Password age (in days)_Auto-lock after_Password History (1-50 passcodes)_Failed attempts (After the specified number of failed attempts, the device data will be wiped automatically)_- [Android > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-android-mdm-restrictions-using-hexnode-mdm/#advanced-restrictions)
RestrictionsConfigurationAllow device functionalityMicrophoneEnabledScreen captureDisabledClipboardDisabledCopy contents between normal and work profilesDisabledShare via other appsDisabledUsers can adjust volumeEnabledMake a callEnabledDisplay SettingsHide System barsDisabledHide Status BarDisabledHide Navigation BarDisabledSplit-screen modeEnabledDisplay dialogs/windowsEnabledAllow Connectivity OptionsNFCEnabledAndroid BeamEnabledBeam from the deviceEnabledTransfer data via BluetoothEnabledConfigure BluetoothEnabledConfigure cell broadcastEnabledConfigure cellular networkEnabledUsers can reset network settingsEnabledConfigure Wi-FiEnabledConfigure hotspot and tetheringEnabledSecurity OptionsMinimum Wi-Fi Security LevelOpenAllow Sync SettingsSync data in backgroundEnabledSync data with Google accountEnabledAllow Account SettingsSMSEnabledReceive messagesEnabledSend messagesEnabledModify Accounts/UsersEnabledAdd UsersEnabledRemove UsersEnabledConfigure user credentialsEnabledAllow SettingsDeveloper modeDisabledUSB debuggingDisabledModify settingsEnabledPower saving modeEnabledUsers can enable location sharingEnabledFactory resetEnabledRead any connected physical external mediaEnabledUpdate date and time automaticallyEnabledSet time zone automaticallyEnabledDisable screen lock if the screen was turned offDisabledConfigure VPNEnabledAllow App SettingsInstall appsEnabledUninstall appsEnabledControl appsEnabledGoogle Play StoreEnabledVerify apps before installDisabledInstall apps from unknown sourcesDisabledApp Runtime PermissionsDefault permissionsParent profile app linkingEnabledFactory Reset Protection (Google Account Verification)Default

 

 

Standard DLP Policy

A standard data loss prevention policy for iOS, Android, Windows, and macOS devices.

**Template name:** Standard DLP Policy

**Description:** Standard Data Loss Prevention policies for optimal security.

**Template Configuration:**

- [iOS > Passcode](https://www.hexnode.com/mobile-device-management/help/password-policy-for-ios/)
PolicyConfigurationAllow simple valueDisabledRequire alpha numeric valueEnabledMinimum Passcode Length8Minimum complex characters1Minimum passcode age in days (0-730 days)30Auto Lock1 MinutePasscode History (1-50 passcodes)5Grace period for device lockImmediatelyFailed attempts (After the specified number of failed attempts, the device data will be wiped automatically)10- [iOS > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-ios-mdm-restrictions-using-hexnode-mdm/#advanced-restrictions)
RestrictionsConfigurationAllow Device FunctionalityAirDropEnabledApps can modify cellular data usageEnabledAdd or remove Touch ID/Face IDEnablediMessageEnabledGame CenterEnabledMultiplayer gamingEnabledPair with iTunesEnabledInstall configuration profileEnabledDefinition lookupEnabledPredictive keyboardEnabledAuto-correct wordsEnabledSuggest words on misspellingsEnabledKeyboard shortcutsEnabledPair with Apple WatchEnabledModify diagnostic data submission settingsEnabledModify Bluetooth settingsEnabledUse voice to typeEnabledConnect to MDM-configured Wi-Fi networks onlyDisabledUsers can modify Personal Hotspot settingsEnabledCreate VPN configurationEnabledAirPrintEnabledConnect with iBeaconEnabledStore AirPrint credentials in KeychainEnabledUse trusted certificates for secure printingDisabledAllow App SettingsInstall app from App StoreEnabledRemove appsEnabledRemove system appsEnablediBooks storeEnabledApple MusicEnablediTunes RadioEnabledNewsEnabledPodcastsEnabledDownload all purchased apps automaticallyEnabledAllow Security and Privacy SettingsActivation LockDisabledModify an accountEnabledErase content and settingsEnabledSiri can access user-generated contentEnabledModify Find My FriendsEnabledUse profanity filterDisabledShow web results using Spotlight SearchEnabledModify Restrictions/Screen TimeEnabledModify passcodeEnabledModify device nameEnabledModify wallpaperEnabledUsers can turn notifications on/offEnabledForce Automatic Date and TimeDisabledAutofill PasswordsEnabledRequest passwords from nearby devicesEnabledShare passwords via Airdrop Passwords featureEnabled- [Android > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-android-mdm-restrictions-using-hexnode-mdm/#advanced-restrictions)
RestrictionsConfigurationAllow device functionalityMicrophoneEnabledScreen captureEnabledClipboardEnabledCopy contents between normal and work profilesDisabledShare via other appsEnabledUsers can adjust volumeEnabledMake a callEnabledDisplay SettingsHide System barsDisabledHide Status BarDisabledHide Navigation BarDisabledSplit-screen modeEnabledDisplay dialogs/windowsEnabledAllow Connectivity OptionsNFCEnabledAndroid BeamEnabledBeam from the deviceEnabledTransfer data via BluetoothEnabledConfigure BluetoothEnabledConfigure cell broadcastEnabledConfigure cellular networkEnabledUsers can reset network settingsEnabledConfigure Wi-FiEnabledConfigure hotspot and tetheringEnabledSecurity OptionsMinimum Wi-Fi Security LevelOpenAllow Sync SettingsSync data in backgroundEnabledSync data with Google accountEnabledAllow Account SettingsSMSEnabledReceive messagesEnabledSend messagesEnabledModify Accounts/UsersEnabledAdd UsersEnabledRemove UsersEnabledConfigure user credentialsEnabledAllow SettingsDeveloper modeDisabledUSB debuggingDisabledModify settingsEnabledPower saving modeEnabledUsers can enable location sharingEnabledFactory resetEnabledRead any connected physical external mediaEnabledUpdate date and time automaticallyEnabledSet time zone automaticallyEnabledDisable screen lock if the screen was turned offDisabledConfigure VPNEnabledAllow App SettingsInstall appsEnabledUninstall appsEnabledControl appsEnabledGoogle Play StoreEnabledVerify apps before installDisabledInstall apps from unknown sourcesDisabledApp Runtime PermissionsDefault permissionsParent profile app linkingEnabledFactory Reset Protection (Google Account Verification)Default- [Windows > Security > BitLocker](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/)
BitLocker SettingsConfigurationPrompt to encrypt storage cardEnabledPrompt for device encryptionEnabledConfigure encryption method for disk drivesSelect default valueConfigure authentication when computer starts upSelect default valueMinimum length for BitLocker startup PIN6Configure pre-boot recovery messageShow default recovery message and URLConfigure recovery options for system drivesDisabledConfigure recovery options for fixed drivesDisabledFixed drives require encryptionEnabledRemovable drives require encryptionEnabled- [macOS > Security > FileVault](https://www.hexnode.com/mobile-device-management/help/how-to-manage-filevault-with-hexnode-mdm/)
Policy SettingsConfigurationEnable FileVaultEnabledEncrypt usingInstitutional and Personal Recovery KeyEncryption certificateHexnodeMDM FileVault CertificateShow Personal Recovery Key to userEnabledSkip enabling FileVault at user loginDisabled

 

 

CIS Benchmark Compliance Level 1 - macOS

The CIS (Center for Internet Security) benchmarks are a set of security configuration guidelines for various operating systems, applications, and network devices. They provide a standardized framework for strengthening system security, helping organizations to reduce their exposure to attacks and improve their overall security posture. These benchmarks are developed through a community consensus process and are widely recognized as a best practice for securing devices across all supported platforms. Hexnode supports making devices partially CIS Benchmark compliant.

**Template name:** CIS Benchmark Compliance Level 1 – macOS

**Description:** Apply this template to get one step closer to CIS compliance on your macOS devices.

Note: Not all rules mentioned in CIS Benchmark are configurable via Hexnode.

**Template Configuration:**

- [ macOS > Passcode](https://www.hexnode.com/mobile-device-management/help/set-passcode-rules-for-macos-using-hexnode-mdm/)
SettingsConfigurationAllow simple valueEnabledRequire alphanumeric valueEnabledChange password at next loginDisabledMinimum passcode length15Minimum complex charactersMaximum passcode age in days1Auto lockPasscode history15Grace period for device to lockMaximum failed attempts5Custom regular expressionDisabled- [ macOS > Restrictions](https://www.hexnode.com/mobile-device-management/help/macos-mdm-restrictions/)
RestrictionsConfigurationAllow Device FunctionalityAuto-unlock with Apple Watch in proximityEnabledTouch IDEnabledDefinition lookupEnabledEnforce on-device-only dictationDisabledUniversal controlEnabledUSB restricted modeEnabledIncoming Airplay requestsDisabledAllow personalized ads from AppleDisabledInstall configuration profilesEnabledUsers can turn VPN on/offEnabledAllow App SettingsStream using Music appEnabledCameraEnabledGame Center - Add friends in Game Center
- Game Center account modifications
- Multiplayer gaming

DisabledApp StoreAllow software update notifications onlyDisabledFinder SettingsBurn data to diskEnabledConnect to local servers or on the internetEnabledEject mounted volumesEnabledGo to FolderEnabledShow external hard disks on desktopEnabledShow hard disk on desktopDisabledShow mounted file servers on desktopDisabledShow removable media items on desktopEnabledWarn the user before emptying the trashEnabledSecurityAsk for password when removing the policyDisabledTimeout for Fingerprint48 hour(s)Send diagnosticsDisabledAllow iCloud OptionsBack to My MacDisabledFind My MacEnablediCloud MailEnabledCalendarEnabledReminderEnabledAddress BookEnabledNotesEnabledAuto-upload files in Desktop and DocumentsEnabledSync bookmarks with iCloudEnabledDocument and key-value syncEnabledSync passwords across devicesEnabledPhoto libraryEnabledFreeform servicesEnabled- [ macOS > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/macos-mdm-restrictions/)
RestrictionsConfigurationDevice Functionality and PersonalizationScreen CaptureRemote Screen ObservationEnabledAirDropDisabledWallpaper ModificationEnabledDictationEnabledHandoffEnablediTunes or Finder File SharingEnabledShow Web Results in Spotlight SearchEnablediPhone mirroringEnabledShow Wi-Fi status in menu barEnabledShow Bluetooth status in menu barEnabledSecurity and PrivacyActivation LockEnabledContent cachingLet user chooseErase all content and settingsEnabledPasscode ModificationEnabledAutofill PasswordsEnabledSafari AutoFillEnabledRequest passwords from nearby devicesEnabledShare passwords via Airdrop Passwords featureEnabledUsers can modify File Sharing settingsDisabledUsers can modify Bluetooth Sharing settingsDisabledUsers can modify Printer Sharing settingsDisabledUsers can modify Internet Sharing settingsDisabledUsers can modify Remote Management Sharing settingsDisabledUsers can modify Remote Apple Events Sharing settingsDisabledUsers can modify an accountEnabledUsers can modify Device NameEnabledUsers can create local user accountsEnabledUsers can add or remove Touch ID/Face IDEnabledUsers can modify Time Machine settingsEnabledUsers can modify Startup Disk settingsEnabledGuest AccountDisabledkeyboard entry for Terminal appEnabledSoftware update deferment15Users can modify Media Sharing settingsEnabledBypass screen capture alertDisabledApp Installation FromMac App Store and Identified DevelopersApp StoreRestrict app installations to admin usersDisabledRestrict App Store to Software Updates OnlyDisabledDisable App Store app adoptionDisabledRestrict App Store to apps installed via MDM and software updates onlyDisabledSecure Wi-Fi SettingsEnforce admin authorization when switching between Wi-Fi networksDisabledEnforce admin authorization to enable IBSSDisabledEnforce admin authorization to turn Wi-Fi on/offDisabledAllow Apple IntelligenceImage playgroundEnabledWriting toolsEnabledChatGPT integrationEnabledChatGPT user account sign-inEnabled- [ macOS > Security > Firewall](https://www.hexnode.com/mobile-device-management/help/how-to-configure-firewall-for-mac-with-hexnode-mdm/)
RestrictionsConfigurationFirewallEnable FirewallEnabledEnable stealth modeEnabledEnable loggingDisabledLogging levelThrottledBlock all incoming connectionsDisabledAllow incoming connections to built-in softwareEnabledAllow incoming connections to downloaded signed softwareEnabledApplicationsAllow/block incoming connections to the following appsAllow incoming connections- [ macOS > Security > FileVault](https://www.hexnode.com/mobile-device-management/help/how-to-manage-filevault-with-hexnode-mdm/)
SettingsConfigurationPrevent FileVault from being disabledDisabledPrevent FileVault from being enabledDisabledEnable FileVaultEnabledEncrypt usingInstitutional and Personal Recovery KeyEncryption certificate–Escrow Personal Recovery KeyDisabledShow Personal Recovery Key to userEnabledSkip enabling FileVault at user loginDisabledRequire user to unlock FileVault after hibernationDisabled- [ macOS > Security > Login Window Preferences](https://www.hexnode.com/mobile-device-management/help/how-to-configure-login-window-settings-for-macos-devices-using-hexnode-mdm/)
SettingsConfigurationDisplay login window asName and passwordHide Shut Down buttonDisabledHide Restart buttonDisabledHide Sleep buttonDisabledDisable login items bypassDisabledDisable Console Access from Login ScreenDisabledDisable Shut Down while user is logged inDisabledDisable Restart while user is logged inDisabledDisable Power Off while user is logged inDisabledDisable Log Out while user is logged inDisabledDisable Immediate Screen Lock optionsDisabledPassword hintsDisabledAutomatic loginDisabledShow text to display in the Login Window*WelcomeShow Admin Host Info–- [ macOS > Patches & Updates > Software Update Preferences](https://www.hexnode.com/mobile-device-management/help/configure-macos-software-update-preferences-with-hexnode/)
RestrictionsConfigurationSoftware Update PreferencesAutomatically check for new updatesEnableAutomatically download new updatesEnableAutomatically install macOS updatesEnableAutomatically install app updatesEnableAutomatically install critical updatesEnableAutomatically install configuration dataEnableInstall pre-release softwareNot ConfiguredForce admin privilege requirement for software updatesNot ConfiguredInstall Rapid Security ResponsesNot ConfiguredAllow removal of Rapid Security ResponsesNot ConfiguredDefer Software UpdatesDefer major upgradesNot ConfiguredDefer minor upgradesNot ConfiguredDefer app upgradesNot Configured- [ macOS > Configurations > Setup Assistant](https://www.hexnode.com/mobile-device-management/help/how-to-configure-setup-assistant-for-macos-devices-using-hexnode-mdm/)
SettingsConfigurationSkip Privacy setupDisabledSkip signing in with Apple IDDisabledSkip iCloud Storage setupDisabledSkip Siri setupDisabledSkip Choose Your Look setupDisabled- [ macOS > Configurations > Screensaver](https://www.hexnode.com/mobile-device-management/help/how-to-configure-screensaver-for-macos-devices-using-hexnode-mdm/)
SettingsConfigurationEnable ScreensaverEnabledLogin window screensaver idle time1 minScreensaver idle time20 minRequire Password to unlock screenEnabledSet delay for password prompt5 sec- [ macOS > Configurations > Energy Saver](https://www.hexnode.com/mobile-device-management/help/how-to-configure-energy-saver-settings-on-macos-devices/)
RestrictionsConfigurationDesktopAutomatically startup on power lossDisabledIdle timeout for system sleep0 minsIdle timeout for display sleep0 minsWake for network accessDisabledLaptop on AC PowerAutomatically startup on power lossDisabledIdle timeout for system sleep0 minsIdle timeout for display sleep0 minsWake for network accessDisabledLaptop on Battery PowerAutomatically startup on power lossDisabledIdle timeout for system sleep0 minsIdle timeout for display sleep0 minsWake for network accessDisabledGeneral SettingsPrevent temporary FileVault key storage during standbyDisabledDisable device sleepDisabled

 

 

CIS Benchmark Compliance Level 2 - macOS

**Template name:** CIS Benchmark Compliance Level 2 – macOS

**Template Configuration:**

- [ macOS > Passcode](https://www.hexnode.com/mobile-device-management/help/set-passcode-rules-for-macos-using-hexnode-mdm/)
SettingsConfigurationAllow simple valueEnabledRequire alphanumeric valueEnabledChange password at next loginDisabledMinimum passcode length15Minimum complex characters1Maximum passcode age in days1Auto lock–Passcode history15Grace period for device to lock–Maximum failed attempts5Custom regular expressionDisabled- [ macOS > Restrictions](https://www.hexnode.com/mobile-device-management/help/macos-mdm-restrictions/)
RestrictionsConfigurationAllow Device FunctionalityAuto-unlock with Apple Watch in proximityEnabledTouch IDEnabledDefinition lookupEnabledEnforce on-device-only dictationDisabledUniversal controlEnabledUSB restricted modeEnabledIncoming Airplay requestsDisabledAllow personalized ads from AppleDisabledInstall configuration profilesEnabledAllow App SettingsStream using Music appEnabledCameraEnabledGame Center - Add friends in Game Center
- Game Center account modifications
- Multiplayer gaming

DisabledApp StoreAllow software update notifications onlyDisabledFinder SettingsBurn data to diskEnabledConnect to local servers or on the internetEnabledEject mounted volumesEnabledGo to FolderEnabledShow external hard disks on desktopEnabledShow hard disk on desktopDisabledShow mounted file servers on desktopDisabledShow removable media items on desktopEnabledWarn the user before emptying the trashEnabledSecurityAsk for password when removing the policyDisabledTimeout for Fingerprint48 hour(s)Send diagnosticsDisabledAllow iCloud OptionsBack to My MacEnabledFind My MacEnablediCloud MailEnabledCalendarEnabledReminderEnabledAddress BookEnabledNotesEnabledAuto-upload files in Desktop and DocumentsDisabledSync bookmarks with iCloudEnabledDocument and key-value syncEnabledSync passwords across devicesEnabledPhoto libraryEnabledFreeform servicesEnabled- [ macOS > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/macos-mdm-restrictions/)
RestrictionsConfigurationDevice Functionality and PersonalizationScreen Capture - Remote Screen Observation

EnabledAirDropDisabledWallpaper ModificationEnabledDictationEnabledHandoffEnablediTunes or Finder File SharingEnabledShow Web Results in Spotlight SearchEnablediPhone mirroringEnabledShow Wi-Fi status in menu barDisabledShow Bluetooth status in menu barDisabledSecurity and PrivacyActivation LockEnabledContent cachingRestrictErase all content and settingsEnabledPasscode ModificationEnabledAutofill PasswordsEnabledSafari AutoFillEnabledRequest passwords from nearby devicesEnabledShare passwords via Airdrop Passwords featureEnabledUsers can modify File Sharing settingsDisabledUsers can modify Bluetooth Sharing settingsDisabledUsers can modify Printer Sharing settingsDisabledUsers can modify Internet Sharing settingsDisabledUsers can modify Remote Management Sharing settingsDisabledUsers can modify Remote Apple Events Sharing settingsDisabledUsers can modify an accountEnabledUsers can modify Device NameEnabledUsers can create local user accountsEnabledUsers can add or remove Touch ID/Face IDEnabledUsers can modify Time Machine settingsEnabledUsers can modify Startup Disk settingsEnabledGuest AccountDisabledkeyboard entry for Terminal appDisabledSoftware update deferment15Users can modify Media Sharing settingsDisabledBypass screen capture alertDisabledApp Installation FromMac App Store and Identified DevelopersApp StoreRestrict app installations to admin usersDisabledRestrict App Store to Software Updates OnlyDisabledDisable App Store app adoptionDisabledRestrict App Store to apps installed via MDM and software updates onlyDisabledSecure Wi-Fi SettingsEnforce admin authorization when switching between Wi-Fi networksDisabledEnforce admin authorization to enable IBSSDisabledEnforce admin authorization to turn Wi-Fi on/offDisabledAllow Apple IntelligenceImage playgroundEnabledWriting toolsEnabledChatGPT integrationEnabledChatGPT user account sign-inEnabled- [ macOS > Security > Firewall](https://www.hexnode.com/mobile-device-management/help/how-to-configure-firewall-for-mac-with-hexnode-mdm/)
RestrictionsConfigurationFirewallEnable FirewallEnabledEnable stealth modeEnabledEnable loggingDisabledLogging levelThrottledBlock all incoming connectionsDisabledAllow incoming connections to built-in softwareEnabledAllow incoming connections to downloaded signed softwareEnabledApplicationsAllow/block incoming connections to the following appsAllow incoming connections- [ macOS > Security > FileVault](https://www.hexnode.com/mobile-device-management/help/how-to-manage-filevault-with-hexnode-mdm/)
SettingsConfigurationPrevent FileVault from being disabledDisabledPrevent FileVault from being enabledDisabledEnable FileVaultEnabledEncrypt usingInstitutional and Personal Recovery KeyEncryption certificate–Escrow Personal Recovery KeyDisabledShow Personal Recovery Key to userEnabledSkip enabling FileVault at user loginDisabledRequire user to unlock FileVault after hibernationDisabled- [ macOS > Security > Login Window Preferences](https://www.hexnode.com/mobile-device-management/help/how-to-configure-login-window-settings-for-macos-devices-using-hexnode-mdm/)
SettingsConfigurationDisplay login window asName and passwordHide Shut Down buttonDisabledHide Restart buttonDisabledHide Sleep buttonDisabledDisable login items bypassDisabledDisable Console Access from Login ScreenDisabledDisable Shut Down while user is logged inDisabledDisable Restart while user is logged inDisabledDisable Power Off while user is logged inDisabledDisable Log Out while user is logged inDisabledDisable Immediate Screen Lock optionsDisabledPassword hintsDisabledAutomatic loginDisabledShow text to display in the Login Window*WelcomeShow Admin Host Info–- [ macOS > Patches & Updates > Software Update Preferences](https://www.hexnode.com/mobile-device-management/help/configure-macos-software-update-preferences-with-hexnode/)
RestrictionsConfigurationSoftware Update PreferencesAutomatically check for new updatesEnableAutomatically download new updatesEnableAutomatically install macOS updatesEnableAutomatically install app updatesEnableAutomatically install critical updatesEnableAutomatically install configuration dataEnableInstall pre-release softwareNot ConfiguredForce admin privilege requirement for software updatesNot ConfiguredInstall Rapid Security ResponsesNot ConfiguredAllow removal of Rapid Security ResponsesNot ConfiguredDefer Software UpdatesDefer major upgradesNot ConfiguredDefer minor upgradesNot ConfiguredDefer app upgradesNot Configured- [ macOS > Configurations > Setup Assistant](https://www.hexnode.com/mobile-device-management/help/how-to-configure-setup-assistant-for-macos-devices-using-hexnode-mdm/)
SettingsConfigurationSkip Privacy setupDisabledSkip signing in with Apple IDDisabledSkip iCloud Storage setupDisabledSkip Siri setupDisabledSkip Choose Your Look setupDisabled- [ macOS > Configurations > Screensaver](https://www.hexnode.com/mobile-device-management/help/how-to-configure-screensaver-for-macos-devices-using-hexnode-mdm/)
SettingsConfigurationEnable ScreensaverEnabledLogin window screensaver idle time1 minScreensaver idle time20 minRequire Password to unlock screenEnabledSet delay for password prompt5 sec- [ macOS > Configurations > Energy Saver](https://www.hexnode.com/mobile-device-management/help/how-to-configure-energy-saver-settings-on-macos-devices/)
RestrictionsConfigurationDesktopAutomatically startup on power lossDisabledIdle timeout for system sleep0 minsIdle timeout for display sleep0 minsWake for network accessDisabledLaptop on AC PowerAutomatically startup on power lossDisabledIdle timeout for system sleep0 minsIdle timeout for display sleep0 minsWake for network accessDisabledLaptop on Battery PowerAutomatically startup on power lossDisabledIdle timeout for system sleep0 minsIdle timeout for display sleep0 minsWake for network accessDisabledGeneral SettingsPrevent temporary FileVault key storage during standbyDisabledDisable device sleepDisabled

 

 

CIS Benchmark Compliance - Windows

The CIS Benchmarks are compliance guidelines for securely configuring IT systems. They provide best practices to reduce vulnerabilities and enhance security, covering areas such as password policies, account management, and system services. Adhering to these guidelines helps improve security and ensure regulatory compliance. Currently, Hexnode supports making Windows devices partially CIS Benchmark compliant.

**Template name:** CIS Benchmark Compliance – Windows

**Description:** Apply this template to get one step closer to CIS compliance on your Windows devices.

Note: Not all rules mentioned in CIS Benchmark are configurable via Hexnode.

**Template Configuration:**

- [ Windows > Password](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-password-policy-for-windows/)
Password settingsConfigurationAllow simple valueDisabledPassword typeAlphanumeric passwordMinimum password length14Password ComplexityDigits, lowercase and uppercase lettersMinimum password age (in days)365Auto-lock (in minutes)15Password history24Failed attempt before wipe0- [ Windows > Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#basic-restrictions)
RestrictionsConfigurationAllow device functionality CameraDisabledCortana voice assistantEnabledUse Cortana if device is lockedEnabledUse storage card and USB drivesDisabledTelemetryDisallowLocation servicesForce Location OffChange languageEnabledUsers can enable/disable WorkplaceEnabledUsers can change AutoPlay settingsEnabledAllow App Settings Sync SettingsEnabledAllow SignIn OptionsEnabledAllow News and InterestsDisabledAllow Network SettingsWi-Fi EnabledBluetoothEnabledDiscover device over BluetoothEnabledUsers can turn VPN on/offEnabledConnect to VPN if on mobile networkEnabledConnect to VPN if roamingEnabledCellular data roamingEnabledAllow Security and Privacy Settings Manual MDM administration removalEnabledShow toast notification on lock screenDisableAccount SettingsOneDrive file syncDisabled- [ Windows > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#advanced-restrictions)
RestrictionsConfigurationAllow device functionality Users can reset the device EnabledUsers can change date and timeDisabledUsers can change power and sleep settingsEnabledAllow Embedded ModeDisabledAllow RegionEnabledAllow App SettingsUnlock developer options Not ConfiguredSearch can use user locationDisabledAllow Network SettingsInternet SharingEnabledConnect to Wi-Fi Sense automaticallyDisabledConnect to external Wi-Fi networks manuallyEnabledWi-Fi DirectEnabledAllow Security and Privacy SettingsInstall provisioning packageEnabledMandate signed certificate for provisioning packageDisabledRemove provisioning packageEnabledReceive advertisements over BluetoothDisabledPair with other devices automaticallyDisabledUsers can download Windows beta updatesDisallowWindows AIAI Data AnalysisNot ConfiguredCustomize Start MenuDocuments folderNot enforcedDownloads folderNot enforcedFile ExplorerNot enforcedHome groupNot enforcedMusic folderNot enforcedNetworksNot enforcedPersonal folderNot enforcedPictures folderNot enforcedSettingsNot enforcedVideos folderNot enforcedAccount SettingsBlock Microsoft accountsNot ConfiguredUsers can change account settingsEnabledUsers can add non-Microsoft accountsEnabledUsers can connect using Microsoft accountsEnabled- [ Windows > Threat Management > Microsoft Defender ](https://www.hexnode.com/mobile-device-management/help/how-to-enable-windows-defender-settings-for-windows-pc-using-hexnode-mdm/)
Policy SettingsConfigurationMicrosoft Defender Application GuardMicrosoft Defender Application GuardEnabledClipboard behaviorTurn On clipboard operation from an isolated session to the hostClipboard settingsAllow copying textsPrint behaviorNoneBlock non-enterprise contentDisabledData persistenceDisabledVirtual GPUDisabledSave files to hostDisabledCertificate ThumbprintsNot configuredAccess Camera and MicrophoneDisabledWindows Defender Security CenterEnable account protection UIEnabledEnable app and browser protection UIEnabledDisallow exploit protection overrideEnabledEnable Device security UIEnabledDisable TPM Firmware update warningDisabledShow the Security processor (TPM) troubleshooting areaEnabledDisable Clear TPM buttonDisabledHide the Secure boot areaDisabledNotificationsDisplay all notificationsEnable family UIEnabledEnable health UIEnabledEnable network UIEnabledEnable virus UIEnabledHide the Ransomware data recovery areaDisabledEnable customized toastsDisabledEnable in-app customizationDisabledCompany nameNot configuredEmail addressNot configuredPhone number/Skype IDNot configuredHelp portal URLNot configuredHide Windows Security notification area controlDisabled- [ Windows > Security > BitLocker ](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/)
BitLocker SettingsConfigurationRequire encryption for OS and fixed data drivesEnabledHide warning about existing third-party encryptionDisabledRecovery Password rotationNot ConfiguredEscrow recovery password to Hexnode UEMEnabled**OS Drive Settings**Configure BitLocker OS drive policyEnabledConfigure encryption methodDisabledConfigure additional startup authentication settingsEnabledAllow BitLocker to be activated on devices without a compatible TPMDisabledConfigure advanced authentication options for devices with compatible TPMRequired Options: Startup PINMinimum PIN length6Configure pre-boot recovery message and URLDisabledUsers must generate a recovery key or passwordRecovery Key, Password or bothSave BitLocker recovery information to Active Directory Domain Services (AD DS)Password and KeyBlock certificate-based data recovery agentEnabledHide recovery options on the deviceEnabledDo not enable BitLocker until recovery information is stored in AD DSEnabled**Fixed Drive Settings**Configure BitLocker fixed drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordRecovery Key, Password or bothSave BitLocker recovery information to Active Directory Domain Services (AD DS)DisableBlock certificate-based data recovery agentDisabledHide recovery options on the deviceDisabledDo not enable BitLocker until recovery information is stored in AD DSDisabled**Removable Drive Settings**Configure BitLocker removable drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerEnabled- [ Windows > Configurations > Screensaver ](https://www.hexnode.com/mobile-device-management/help/configure-screensaver-settings-for-windows-devices/)
Screensaver SettingsConfigurationEnable ScreensaverEnabledSelect ScreensaverBlankRequire Password to unlock screenEnabledStart screensaver after _ minutes of inactivity15Prevent user from accessing screensaver settings on deviceDisabled- [ Windows > Patches & Updates > Windows Update Preferences](https://www.hexnode.com/mobile-device-management/help/manage-windows-update-preferences-and-settings/)
SettingsConfigurationUpdate driversDisabledOptional UpdatesNot ConfiguredDownload updates over metered networkNot ConfiguredIgnore download limits for app updatesNot ConfiguredIgnore download limits for OS updatesNot ConfiguredAutomatic wake up for maintenanceEnabledDisable WUfB SafeguardsDisabledTarget productNot ConfiguredTarget versionNot ConfiguredFeature update uninstall period10 day(s)Pre-release buildsNot ConfiguredUpdate channelSemi-annualUpdate DeferralDefer Quality UpdatesEnabledDeferral period (Defer Quality Updates)0 day(s)Defer Feature UpdatesEnabledDeferral period (Defer Feature Updates)0 day(s)- [ Windows > Patches & Updates > Windows Update Experience](https://www.hexnode.com/mobile-device-management/help/configure-windows-update-end-user-experience/)
SettingsConfigurationMicrosoft App Update ServiceDisabledAutomatic update behaviorAuto install updates and notify users to restart if requiredActive hoursStart time: 8:00 AM 
 End time: 5:00 PMMaximum range of active hours18 hoursSkip restart checksDisabledDisable pause updatesEnabledDisallow users to check for updatesDisabledNotificationsUpdate notification levelDefault Windows NotificationNotifications during Active HoursNot ConfiguredAuto-restart notificationsNot ConfiguredDeadlinesConfigure update deadlinesDisabledConfigure restart deadlinesDisabledConfigure engaged restart deadlinesDisabled

 

 

CIS Benchmark Compliance (Windows 10: Level 1 + BitLocker) - Standalone

**Template name:** CIS Benchmark Compliance (Windows 10: Level 1 + BitLocker) – Standalone

**Description:** Apply this template to get one step closer to CIS compliance on your Windows devices.

**Note:** Not all rules mentioned in CIS Benchmark are configurable via Hexnode.

**Template Configuration:**

- [ Windows > Password](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-password-policy-for-windows/)
Password settingsConfigurationAllow simple valueDisabledPassword typeAlphanumeric passwordMinimum password length14Password ComplexityDigits, lowercase and uppercase lettersMinimum password age (in days)365Auto-lock (in minutes)15Password history24Failed attempt before wipe0- [ Windows > Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#basic-restrictions)
RestrictionsConfigurationAllow device functionalityCameraEnabledCortana voice assistantDisabledUse Cortana if device is lockedDisabledUse storage card and USB drivesEnabledTelemetryLimitedLocation servicesForce Location OffChange languageEnabledUsers can enable/disable WorkplaceEnabledUsers can change AutoPlay settingsEnabledAllow App SettingsSync SettingsEnabledAllow SignIn OptionsEnabledAllow News and InterestsDisabledMicrosoft feedback notificationsDisabledGame DVRDisabledAllow Network SettingsWi-FiEnabledBluetoothEnabledDiscover device over BluetoothEnabledUsers can turn VPN on/offEnabledConnect to VPN if on mobile networkEnabledConnect to VPN if roamingEnabledCellular data roamingEnabledAllow Security and Privacy SettingsManual MDM administration removalEnabledShow toast notification on lock screenEnabledAccount SettingsOneDrive file syncDisabled- [ Windows > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#advanced-restrictions)
RestrictionsConfigurationAllow device functionalityUsers can reset the deviceEnabledUsers can change date and timeEnabledUsers can change power and sleep settingsEnabledAllow Embedded ModeDisabledAllow RegionEnabledEnd task from Task ManagerEnabledProjection from deviceEnabledProjection to deviceEnabledRequire PIN for pairingFirst timeFile Explorer SettingsAllowed folder locationsAll folder locationsAllowed storage locationsAll storage locationsAllow App SettingsUnlock developer optionsDefaultAuto-update of store appsNot configuredSearch can use user locationDisabledAllow Network SettingsInternet SharingEnabledConnect to Wi-Fi Sense automaticallyDisabledConnect to external Wi-Fi networks manuallyEnabledWi-Fi DirectEnabledAllow Security and Privacy SettingsInstall provisioning packageEnabledMandate signed certificate for provisioning packageDisabledRemove provisioning packageEnabledReceive advertisements over BluetoothDisabledPair with other devices automaticallyEnabledOnline speech recognitionDisabledAllow apps to use Advertising IDEnabledUsers can download Windows beta updatesNot ConfiguredWindows AIAI Data AnalysisNot ConfiguredAccount SettingsBlock Microsoft accountsUsers cannot add or log on with Microsoft accountsUsers can change account settingsEnabledUsers can add non-Microsoft accountsEnabledUsers can connect using Microsoft accountsEnabled- [ Windows > Threat Management > Microsoft Defender ](https://www.hexnode.com/mobile-device-management/help/how-to-enable-windows-defender-settings-for-windows-pc-using-hexnode-mdm/)
Policy SettingsConfigurationMicrosoft Defender Application GuardMicrosoft Defender Application GuardEnabledClipboard behaviorCompletely turns Off the clipboard functionality for the Application GuardClipboard settingsAllow text copyingPrint behaviorNoneBlock non-enterprise contentDisabledData persistenceDisabledVirtual GPUDisabledSave files to hostDisabledCertificate ThumbprintsNot configuredAccess Camera and MicrophoneDisabledWindows Defender Security CenterEnable account protection UIEnabledEnable app and browser protection UIEnabledDisallow exploit protection overrideEnabledEnable Device security UIEnabledDisable TPM Firmware update warningDisabledShow the Security processor (TPM) troubleshooting areaEnabledDisable Clear TPM buttonDisabledHide the Secure boot areaDisabledNotificationsDisplay all notificationsEnable family UIEnabledEnable health UIEnabledEnable network UIEnabledEnable virus UIEnabledHide the Ransomware data recovery areaDisabledEnable customized toastsDisabledEnable in-app customizationDisabledCompany nameNot configuredEmail addressNot configuredPhone number/Skype IDNot configuredHelp portal URLNot configuredHide Windows Security notification area controlDisabled- [ Windows > Security > BitLocker ](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/)
BitLocker SettingsConfigurationRequire encryption for OS and fixed data drivesEnabledHide warning about existing third-party encryptionDisabledAllow Standard User EncryptionDisabledRecovery Password rotationNot ConfiguredEscrow recovery password to Hexnode UEMEnabled**OS Drive Settings**Configure BitLocker OS drive policyEnabledConfigure encryption methodDisabledConfigure additional startup authentication settingsEnabledAllow BitLocker to be activated on devices without a compatible TPMDisabledConfigure advanced authentication options for devices with compatible TPMRequired Options: Startup PINMinimum PIN length6Configure pre-boot recovery message and URLDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordOnly Recovery PasswordSave BitLocker recovery information to Active Directory Domain Services (AD DS)Password and KeyBlock certificate-based data recovery agentDisabledHide recovery options on the deviceEnabledDo not enable BitLocker until recovery information is stored in AD DSEnabled**Fixed Drive Settings**Configure BitLocker fixed drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordRecovery Key, Password or bothSave BitLocker recovery information to Active Directory Domain Services (AD DS)DisableBlock certificate-based data recovery agentEnabledHide recovery options on the deviceDisabledDo not enable BitLocker until recovery information is stored in AD DSDisabled**Removable Drive Settings**Configure BitLocker removable drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerEnabled- [ Windows > Configurations > Deploy Custom Configuration ](https://www.hexnode.com/mobile-device-management/help/custom-configuration-for-windows/)
Deploy Custom Configuration SettingsConfigurationEnforce atomic executionEnabled- [ Windows > Patches & Updates > Windows Update Preferences](https://www.hexnode.com/mobile-device-management/help/manage-windows-update-preferences-and-settings/)
SettingsConfigurationUpdate driversEnabledOptional UpdatesNot ConfiguredDownload updates over metered networkNot ConfiguredIgnore download limits for app updatesNot ConfiguredIgnore download limits for OS updatesNot ConfiguredAutomatic wake up for maintenanceEnabledDisable WUfB SafeguardsDisabledTarget productNot ConfiguredTarget versionNot ConfiguredFeature update uninstall period10 day(s)Pre-release buildsDisabledUpdate channelWindows Insider – Fast**Update Deferral**Defer Quality UpdatesEnabledDeferral period (Defer Quality Updates)0 day(s)Defer Feature UpdatesEnabledDeferral period (Defer Feature Updates)180 day(s)- [ Windows > Patches & Updates > Windows Update Experience](https://www.hexnode.com/mobile-device-management/help/configure-windows-update-end-user-experience/)
SettingsConfigurationMicrosoft App Update ServiceDisabledAutomatic update behaviorDisable user control, auto install and restart at a specified timeSchedule Frequency- First week of every month: Enabled
- Second week of every month: Enabled
- Third week of every month: Enabled
- Fourth week of every month: Enabled

Scheduled Install DayAny DayScheduled Install TimeNot ConfiguredSkip restart checksDisabledDisable pause updatesEnabledDisallow users to check for updatesDisabled**Notifications**Update notification levelNot ConfiguredNotifications during Active HoursNot ConfiguredAuto-restart notificationsNot Configured**Deadlines**Configure update deadlinesDisabledConfigure restart deadlinesDisabledConfigure engaged restart deadlinesDisabled

 

 

CIS Benchmark Compliance (Windows 10: Level 1 + BitLocker) - Hybrid Joined

**Template name:** CIS Benchmark Compliance (Windows 10: Level 1 + BitLocker) – Hybrid Joined

**Description:** Apply this template to get one step closer to CIS compliance on your Windows devices.

**Note:** Not all rules mentioned in CIS Benchmark are configurable via Hexnode.

**Template Configuration:**

- [ Windows > Password](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-password-policy-for-windows/)
Password settingsConfigurationAllow simple valueDisabledPassword typeAlphanumeric passwordMinimum password length14Password ComplexityDigits, lowercase and uppercase lettersMinimum password age (in days)365Auto-lock (in minutes)15Password history24Failed attempt before wipe0- [ Windows > Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#basic-restrictions)
RestrictionsConfigurationAllow device functionalityCameraEnabledCortana voice assistantDisabledUse Cortana if device is lockedDisabledUse storage card and USB drivesEnabledTelemetrySend basic device info and security dataLocation servicesForce Location OffChange languageEnabledUsers can enable/disable WorkplaceEnabledUsers can change AutoPlay settingsEnabledAllow App SettingsSync SettingsEnabledAllow SignIn OptionsEnabledAllow News and InterestsDisabledMicrosoft feedback notificationsDisabledGame DVRDisabledAllow Network SettingsWi-FiEnabledBluetoothEnabledDiscover device over BluetoothEnabledUsers can turn VPN on/offEnabledConnect to VPN if on mobile networkEnabledConnect to VPN if roamingEnabledCellular data roamingEnabledAllow Security and Privacy SettingsManual MDM administration removalEnabledShow toast notification on lock screenEnabledAccount SettingsOneDrive file syncDisabled- [ Windows > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#advanced-restrictions)
RestrictionsConfigurationAllow device functionalityUsers can reset the deviceEnabledUsers can change date and timeEnabledUsers can change power and sleep settingsEnabledAllow Embedded ModeDisabledAllow RegionEnabledEnd task from Task ManagerEnabledProjection from deviceEnabledProjection to deviceEnabledRequire PIN for pairingFirst timeFile Explorer SettingsAllowed folder locationsAll folder locationsAllowed storage locationsAll storage locationsAllow App SettingsUnlock developer optionsDefaultAuto-update of store appsNot configuredSearch can use user locationDisabledAllow Network SettingsInternet SharingEnabledConnect to Wi-Fi Sense automaticallyDisabledConnect to external Wi-Fi networks manuallyEnabledWi-Fi DirectEnabledAllow Security and Privacy SettingsInstall provisioning packageEnabledMandate signed certificate for provisioning packageDisabledRemove provisioning packageEnabledReceive advertisements over BluetoothDisabledPair with other devices automaticallyEnabledOnline speech recognitionDisabledAllow apps to use Advertising IDEnabledUsers can download Windows beta updatesNot ConfiguredWindows AIAI Data AnalysisNot ConfiguredAccount SettingsBlock Microsoft accountsUsers cannot add or log on with Microsoft accountsUsers can change account settingsEnabledUsers can add non-Microsoft accountsEnabledUsers can connect using Microsoft accountsEnabled- [ Windows > Threat Management > Microsoft Defender ](https://www.hexnode.com/mobile-device-management/help/how-to-enable-windows-defender-settings-for-windows-pc-using-hexnode-mdm/)
Policy SettingsConfigurationMicrosoft Defender Application GuardMicrosoft Defender Application GuardEnabledClipboard behaviorCompletely turns Off the clipboard functionality for the Application GuardClipboard settingsAllow text copyingPrint behaviorNoneBlock non-enterprise contentDisabledData persistenceDisabledVirtual GPUDisabledSave files to hostDisabledCertificate ThumbprintsNot configuredAccess Camera and MicrophoneDisabledWindows Defender Security CenterEnable account protection UIEnabledEnable app and browser protection UIEnabledDisallow exploit protection overrideEnabledEnable Device security UIEnabledDisable TPM Firmware update warningDisabledShow the Security processor (TPM) troubleshooting areaEnabledDisable Clear TPM buttonDisabledHide the Secure boot areaDisabledNotificationsDisplay all notificationsEnable family UIEnabledEnable health UIEnabledEnable network UIEnabledEnable virus UIEnabledHide the Ransomware data recovery areaDisabledEnable customized toastsDisabledEnable in-app customizationDisabledCompany nameNot configuredEmail addressNot configuredPhone number/Skype IDNot configuredHelp portal URLNot configuredHide Windows Security notification area controlDisabled- [ Windows > Security > BitLocker ](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/)
BitLocker SettingsConfigurationRequire encryption for OS and fixed data drivesEnabledHide warning about existing third-party encryptionDisabledAllow Standard User EncryptionDisabledRecovery Password rotationNot ConfiguredEscrow recovery password to Hexnode UEMEnabled**OS Drive Settings**Configure BitLocker OS drive policyEnabledConfigure encryption methodDisabledConfigure additional startup authentication settingsEnabledAllow BitLocker to be activated on devices without a compatible TPMDisabledConfigure advanced authentication options for devices with compatible TPMRequired Options: Startup PINMinimum PIN length6Configure pre-boot recovery message and URLDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordOnly Recovery PasswordSave BitLocker recovery information to Active Directory Domain Services (AD DS)Password and KeyBlock certificate-based data recovery agentDisabledHide recovery options on the deviceEnabledDo not enable BitLocker until recovery information is stored in AD DSEnabled**Fixed Drive Settings**Configure BitLocker fixed drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordRecovery Key, Password or bothSave BitLocker recovery information to Active Directory Domain Services (AD DS)DisableBlock certificate-based data recovery agentEnabledHide recovery options on the deviceDisabledDo not enable BitLocker until recovery information is stored in AD DSDisabled**Removable Drive Settings**Configure BitLocker removable drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerEnabled- [ Windows > Configurations > Deploy Custom Configuration ](https://www.hexnode.com/mobile-device-management/help/custom-configuration-for-windows/)
Deploy Custom Configuration SettingsConfigurationEnforce atomic executionEnabled- [ Windows > Patches & Updates > Windows Update Preferences](https://www.hexnode.com/mobile-device-management/help/manage-windows-update-preferences-and-settings/)
SettingsConfigurationUpdate driversEnabledOptional UpdatesNot ConfiguredDownload updates over metered networkNot ConfiguredIgnore download limits for app updatesNot ConfiguredIgnore download limits for OS updatesNot ConfiguredAutomatic wake up for maintenanceEnabledDisable WUfB SafeguardsDisabledTarget productNot ConfiguredTarget versionNot ConfiguredFeature update uninstall period10 day(s)Pre-release buildsDisabledUpdate channelWindows Insider – Fast**Update Deferral**Defer Quality UpdatesEnabledDeferral period (Defer Quality Updates)0 day(s)Defer Feature UpdatesEnabledDeferral period (Defer Feature Updates)180 day(s)- [ Windows > Patches & Updates > Windows Update Experience](https://www.hexnode.com/mobile-device-management/help/configure-windows-update-end-user-experience/)
SettingsConfigurationMicrosoft App Update ServiceDisabledAutomatic update behaviorDisable user control, auto install and restart at a specified timeSchedule Frequency- First week of every month: Enabled
- Second week of every month: Enabled
- Third week of every month: Enabled
- Fourth week of every month: Enabled

Scheduled Install DayAny DayScheduled Install TimeNot ConfiguredSkip restart checksDisabledDisable pause updatesEnabledDisallow users to check for updatesDisabled**Notifications**Update notification levelNot ConfiguredNotifications during Active HoursNot ConfiguredAuto-restart notificationsNot Configured**Deadlines**Configure update deadlinesDisabledConfigure restart deadlinesDisabledConfigure engaged restart deadlinesDisabled

 

 

CIS Benchmark Compliance (Windows 10: Level 1 + BitLocker) - Microsoft Entra ID 

**Template name:** CIS Benchmark Compliance (Windows 10: Level 1 + BitLocker) – Microsoft Entra ID

**Description:** Apply this template to get one step closer to CIS compliance on your Windows devices.

**Note:** Not all rules mentioned in CIS Benchmark are configurable via Hexnode.

**Template Configuration:**

- [ Windows > Password](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-password-policy-for-windows/)
Password settingsConfigurationAllow simple valueDisabledPassword typeAlphanumeric passwordMinimum password length14Password ComplexityDigits, lowercase and uppercase lettersMinimum password age (in days)365Auto-lock (in minutes)15Password history24Failed attempt before wipe0- [ Windows > Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#basic-restrictions)
RestrictionsConfigurationAllow device functionalityCameraEnabledCortana voice assistantDisabledUse Cortana if device is lockedDisabledUse storage card and USB drivesEnabledTelemetrySend basic device info and security dataLocation servicesForce Location OffChange languageEnabledUsers can enable/disable WorkplaceEnabledUsers can change AutoPlay settingsEnabledAllow App SettingsSync SettingsEnabledAllow SignIn OptionsEnabledAllow News and InterestsDisabledMicrosoft feedback notificationsDisabledGame DVRDisabledAllow Network SettingsWi-FiEnabledBluetoothEnabledDiscover device over BluetoothEnabledUsers can turn VPN on/offEnabledConnect to VPN if on mobile networkEnabledConnect to VPN if roamingEnabledCellular data roamingEnabledAllow Security and Privacy SettingsManual MDM administration removalEnabledShow toast notification on lock screenEnabledAccount SettingsOneDrive file syncDisabled- [ Windows > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#advanced-restrictions)
RestrictionsConfigurationAllow device functionalityUsers can reset the deviceEnabledUsers can change date and timeEnabledUsers can change power and sleep settingsEnabledAllow Embedded ModeDisabledAllow RegionEnabledEnd task from Task ManagerEnabledProjection from deviceEnabledProjection to deviceEnabledRequire PIN for pairingFirst timeFile Explorer SettingsAllowed folder locationsAll folder locationsAllowed storage locationsAll storage locationsAllow App SettingsUnlock developer optionsDefaultAuto-update of store appsNot configuredSearch can use user locationDisabledAllow Network SettingsInternet SharingEnabledConnect to Wi-Fi Sense automaticallyDisabledConnect to external Wi-Fi networks manuallyEnabledWi-Fi DirectEnabledAllow Security and Privacy SettingsInstall provisioning packageEnabledMandate signed certificate for provisioning packageDisabledRemove provisioning packageEnabledReceive advertisements over BluetoothDisabledPair with other devices automaticallyEnabledOnline speech recognitionDisabledAllow apps to use Advertising IDEnabledUsers can download Windows beta updatesNot ConfiguredWindows AIAI Data AnalysisNot ConfiguredAccount SettingsBlock Microsoft accountsUsers cannot add or log on with Microsoft accountsUsers can change account settingsEnabledUsers can add non-Microsoft accountsEnabledUsers can connect using Microsoft accountsEnabled- [ Windows > Threat Management > Microsoft Defender ](https://www.hexnode.com/mobile-device-management/help/how-to-enable-windows-defender-settings-for-windows-pc-using-hexnode-mdm/)
Policy SettingsConfigurationMicrosoft Defender Application GuardMicrosoft Defender Application GuardEnabledClipboard behaviorCompletely turns Off the clipboard functionality for the Application GuardClipboard settingsAllow text copyingPrint behaviorNoneBlock non-enterprise contentDisabledData persistenceDisabledVirtual GPUDisabledSave files to hostDisabledCertificate ThumbprintsNot configuredAccess Camera and MicrophoneDisabledWindows Defender Security CenterEnable account protection UIEnabledEnable app and browser protection UIEnabledDisallow exploit protection overrideEnabledEnable Device security UIEnabledDisable TPM Firmware update warningDisabledShow the Security processor (TPM) troubleshooting areaEnabledDisable Clear TPM buttonDisabledHide the Secure boot areaDisabledNotificationsDisplay all notificationsEnable family UIEnabledEnable health UIEnabledEnable network UIEnabledEnable virus UIEnabledHide the Ransomware data recovery areaDisabledEnable customized toastsDisabledEnable in-app customizationDisabledCompany nameNot configuredEmail addressNot configuredPhone number/Skype IDNot configuredHelp portal URLNot configuredHide Windows Security notification area controlDisabled- [ Windows > Security > BitLocker ](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/)
BitLocker SettingsConfigurationRequire encryption for OS and fixed data drivesEnabledHide warning about existing third-party encryptionDisabledAllow Standard User EncryptionDisabledRecovery Password rotationNot ConfiguredEscrow recovery password to Hexnode UEMEnabled**OS Drive Settings**Configure BitLocker OS drive policyEnabledConfigure encryption methodDisabledConfigure additional startup authentication settingsEnabledAllow BitLocker to be activated on devices without a compatible TPMDisabledConfigure advanced authentication options for devices with compatible TPMRequired Options: Startup PINMinimum PIN length6Configure pre-boot recovery message and URLDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordOnly Recovery PasswordSave BitLocker recovery information to Active Directory Domain Services (AD DS)Password and KeyBlock certificate-based data recovery agentDisabledHide recovery options on the deviceEnabledDo not enable BitLocker until recovery information is stored in AD DSEnabled**Fixed Drive Settings**Configure BitLocker fixed drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordRecovery Key, Password or bothSave BitLocker recovery information to Active Directory Domain Services (AD DS)DisableBlock certificate-based data recovery agentEnabledHide recovery options on the deviceDisabledDo not enable BitLocker until recovery information is stored in AD DSDisabled**Removable Drive Settings**Configure BitLocker removable drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerEnabled- [ Windows > Configurations > Deploy Custom Configuration ](https://www.hexnode.com/mobile-device-management/help/custom-configuration-for-windows/)
Deploy Custom Configuration SettingsConfigurationEnforce atomic executionEnabled- [ Windows > Patches & Updates > Windows Update Preferences](https://www.hexnode.com/mobile-device-management/help/manage-windows-update-preferences-and-settings/)
SettingsConfigurationUpdate driversEnabledOptional UpdatesNot ConfiguredDownload updates over metered networkNot ConfiguredIgnore download limits for app updatesNot ConfiguredIgnore download limits for OS updatesNot ConfiguredAutomatic wake up for maintenanceEnabledDisable WUfB SafeguardsDisabledTarget productNot ConfiguredTarget versionNot ConfiguredFeature update uninstall period10 day(s)Pre-release buildsDisabledUpdate channelWindows Insider – Fast**Update Deferral**Defer Quality UpdatesEnabledDeferral period (Defer Quality Updates)0 day(s)Defer Feature UpdatesEnabledDeferral period (Defer Feature Updates)180 day(s)- [ Windows > Patches & Updates > Windows Update Experience](https://www.hexnode.com/mobile-device-management/help/configure-windows-update-end-user-experience/)
SettingsConfigurationMicrosoft App Update ServiceDisabledAutomatic update behaviorDisable user control, auto install and restart at a specified timeSchedule Frequency- First week of every month: Enabled
- Second week of every month: Enabled
- Third week of every month: Enabled
- Fourth week of every month: Enabled

Scheduled Install DayAny DayScheduled Install TimeNot ConfiguredSkip restart checksDisabledDisable pause updatesEnabledDisallow users to check for updatesDisabled**Notifications**Update notification levelDefault Windows NotificationNotifications during Active HoursNot ConfiguredAuto-restart notificationsNot Configured**Deadlines**Configure update deadlinesDisabledConfigure restart deadlinesDisabledConfigure engaged restart deadlinesDisabled

 

 

CIS Benchmark Compliance (Windows 11: Level 1 + BitLocker) - Standalone 

**Template name:** CIS Benchmark Compliance (Windows 11: Level 1 + BitLocker) – Standalone

**Description:** Apply this template to get one step closer to CIS compliance on your Windows devices.

**Note:** Not all rules mentioned in CIS Benchmark are configurable via Hexnode.

**Template Configuration:**

- [ Windows > Password](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-password-policy-for-windows/)
Password settingsConfigurationAllow simple valueDisabledPassword typeAlphanumeric passwordMinimum password length14Password ComplexityDigits, lowercase and uppercase lettersMinimum password age (in days)365Auto-lock (in minutes)15Password history24Failed attempt before wipe0- [ Windows > Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#basic-restrictions)
RestrictionsConfigurationAllow device functionalityCameraEnabledCortana voice assistantDisabledUse Cortana if device is lockedDisabledUse storage card and USB drivesEnabledTelemetrySend basic device info and security dataLocation servicesForce Location OffChange languageEnabledUsers can enable/disable WorkplaceEnabledUsers can change AutoPlay settingsEnabledAllow App SettingsSync SettingsEnabledAllow SignIn OptionsEnabledAllow News and InterestsDisabledMicrosoft feedback notificationsDisabledGame DVRDisabledAllow Network SettingsWi-FiEnabledBluetoothEnabledDiscover device over BluetoothEnabledUsers can turn VPN on/offEnabledConnect to VPN if on mobile networkEnabledConnect to VPN if roamingEnabledCellular data roamingEnabledAllow Security and Privacy SettingsManual MDM administration removalEnabledShow toast notification on lock screenEnabledAccount SettingsOneDrive file syncDisabled- [ Windows > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#advanced-restrictions)
RestrictionsConfigurationAllow device functionalityUsers can reset the deviceEnabledUsers can change date and timeEnabledUsers can change power and sleep settingsEnabledAllow Embedded ModeDisabledAllow RegionEnabledEnd task from Task ManagerEnabledProjection from deviceEnabledProjection to deviceEnabledRequire PIN for pairingFirst timeFile Explorer SettingsAllowed folder locationsAll folder locationsAllowed storage locationsAll storage locationsAllow App SettingsUnlock developer optionsDefaultAuto-update of store appsNot configuredSearch can use user locationDisabledAllow Network SettingsInternet SharingEnabledConnect to Wi-Fi Sense automaticallyDisabledConnect to external Wi-Fi networks manuallyEnabledWi-Fi DirectEnabledAllow Security and Privacy SettingsInstall provisioning packageEnabledMandate signed certificate for provisioning packageDisabledRemove provisioning packageEnabledReceive advertisements over BluetoothDisabledPair with other devices automaticallyEnabledOnline speech recognitionDisabledAllow apps to use Advertising IDEnabledUsers can download Windows beta updatesNot ConfiguredWindows AIAI Data AnalysisNot ConfiguredAccount SettingsBlock Microsoft accountsUsers cannot add or log on with Microsoft accountsUsers can change account settingsEnabledUsers can add non-Microsoft accountsEnabledUsers can connect using Microsoft accountsEnabled- [ Windows > Threat Management > Microsoft Defender ](https://www.hexnode.com/mobile-device-management/help/how-to-enable-windows-defender-settings-for-windows-pc-using-hexnode-mdm/)
Policy SettingsConfigurationMicrosoft Defender Application GuardMicrosoft Defender Application GuardEnabledClipboard behaviorCompletely turns Off the clipboard functionality for the Application GuardClipboard settingsAllow text copyingPrint behaviorNoneBlock non-enterprise contentDisabledData persistenceDisabledVirtual GPUDisabledSave files to hostDisabledCertificate ThumbprintsNot configuredAccess Camera and MicrophoneDisabledWindows Defender Security CenterEnable account protection UIEnabledEnable app and browser protection UIEnabledDisallow exploit protection overrideEnabledEnable Device security UIEnabledDisable TPM Firmware update warningDisabledShow the Security processor (TPM) troubleshooting areaEnabledDisable Clear TPM buttonDisabledHide the Secure boot areaDisabledNotificationsDisplay all notificationsEnable family UIEnabledEnable health UIEnabledEnable network UIEnabledEnable virus UIEnabledHide the Ransomware data recovery areaDisabledEnable customized toastsDisabledEnable in-app customizationDisabledCompany nameNot configuredEmail addressNot configuredPhone number/Skype IDNot configuredHelp portal URLNot configuredHide Windows Security notification area controlDisabled- [ Windows > Security > BitLocker ](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/)
BitLocker SettingsConfigurationRequire encryption for OS and fixed data drivesEnabledHide warning about existing third-party encryptionDisabledAllow Standard User EncryptionDisabledRecovery Password rotationNot ConfiguredEscrow recovery password to Hexnode UEMEnabled**OS Drive Settings**Configure BitLocker OS drive policyEnabledConfigure encryption methodDisabledConfigure additional startup authentication settingsEnabledAllow BitLocker to be activated on devices without a compatible TPMDisabledConfigure advanced authentication options for devices with compatible TPMRequired Options: Startup PINMinimum PIN length6Configure pre-boot recovery message and URLDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordOnly Recovery PasswordSave BitLocker recovery information to Active Directory Domain Services (AD DS)Password and KeyBlock certificate-based data recovery agentDisabledHide recovery options on the deviceEnabledDo not enable BitLocker until recovery information is stored in AD DSEnabled**Fixed Drive Settings**Configure BitLocker fixed drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordRecovery Key, Password or bothSave BitLocker recovery information to Active Directory Domain Services (AD DS)DisableBlock certificate-based data recovery agentEnabledHide recovery options on the deviceDisabledDo not enable BitLocker until recovery information is stored in AD DSDisabled**Removable Drive Settings**Configure BitLocker removable drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerEnabled- [ Windows > Configurations > Deploy Custom Configuration ](https://www.hexnode.com/mobile-device-management/help/custom-configuration-for-windows/)
Deploy Custom Configuration SettingsConfigurationEnforce atomic executionEnabled- [ Windows > Patches & Updates > Windows Update Preferences](https://www.hexnode.com/mobile-device-management/help/manage-windows-update-preferences-and-settings/)
SettingsConfigurationUpdate driversEnabledOptional UpdatesNot ConfiguredDownload updates over metered networkNot ConfiguredIgnore download limits for app updatesNot ConfiguredIgnore download limits for OS updatesNot ConfiguredAutomatic wake up for maintenanceEnabledDisable WUfB SafeguardsDisabledTarget productNot ConfiguredTarget versionNot ConfiguredFeature update uninstall period10 day(s)Pre-release buildsDisabledUpdate channelWindows Insider – Fast**Update Deferral**Defer Quality UpdatesEnabledDeferral period (Defer Quality Updates)0 day(s)Defer Feature UpdatesEnabledDeferral period (Defer Feature Updates)180 day(s)- [ Windows > Patches & Updates > Windows Update Experience](https://www.hexnode.com/mobile-device-management/help/configure-windows-update-end-user-experience/)
SettingsConfigurationMicrosoft App Update ServiceDisabledAutomatic update behaviorDisable user control, auto install and restart at a specified timeSchedule Frequency- First week of every month: Enabled
- Second week of every month: Enabled
- Third week of every month: Enabled
- Fourth week of every month: Enabled

Scheduled Install DayAny DayScheduled Install TimeNot ConfiguredSkip restart checksDisabledDisable pause updatesEnabledDisallow users to check for updatesDisabled**Notifications**Update notification levelDefault Windows NotificationNotifications during Active HoursNot ConfiguredAuto-restart notificationsNot Configured**Deadlines**Configure update deadlinesDisabledConfigure restart deadlinesDisabledConfigure engaged restart deadlinesDisabled

 

 

CIS Benchmark Compliance (Windows 11: Level 1 + BitLocker) - Hybrid Joined

**Template name:** CIS Benchmark Compliance (Windows 11: Level 1 + BitLocker) – Hybrid Joined

**Description:** Apply this template to get one step closer to CIS compliance on your Windows devices.

**Note:** Not all rules mentioned in CIS Benchmark are configurable via Hexnode.

**Template Configuration:**

- [ Windows > Password](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-password-policy-for-windows/)
Password settingsConfigurationAllow simple valueDisabledPassword typeAlphanumeric passwordMinimum password length14Password ComplexityDigits, lowercase and uppercase lettersMinimum password age (in days)365Auto-lock (in minutes)15Password history24Failed attempt before wipe0- [ Windows > Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#basic-restrictions)
RestrictionsConfigurationAllow device functionalityCameraEnabledCortana voice assistantDisabledUse Cortana if device is lockedDisabledUse storage card and USB drivesEnabledTelemetrySend basic device info and security dataLocation servicesForce Location OffChange languageEnabledUsers can enable/disable WorkplaceEnabledUsers can change AutoPlay settingsEnabledAllow App SettingsSync SettingsEnabledAllow SignIn OptionsEnabledAllow News and InterestsDisabledMicrosoft feedback notificationsDisabledGame DVRDisabledAllow Network SettingsWi-FiEnabledBluetoothEnabledDiscover device over BluetoothEnabledUsers can turn VPN on/offEnabledConnect to VPN if on mobile networkEnabledConnect to VPN if roamingEnabledCellular data roamingEnabledAllow Security and Privacy SettingsManual MDM administration removalEnabledShow toast notification on lock screenEnabledAccount SettingsOneDrive file syncDisabled- [ Windows > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#advanced-restrictions)
RestrictionsConfigurationAllow device functionalityUsers can reset the deviceEnabledUsers can change date and timeEnabledUsers can change power and sleep settingsEnabledAllow Embedded ModeDisabledAllow RegionEnabledEnd task from Task ManagerEnabledProjection from deviceEnabledProjection to deviceEnabledRequire PIN for pairingFirst timeFile Explorer SettingsAllowed folder locationsAll folder locationsAllowed storage locationsAll storage locationsAllow App SettingsUnlock developer optionsDefaultAuto-update of store appsNot configuredSearch can use user locationDisabledAllow Network SettingsInternet SharingEnabledConnect to Wi-Fi Sense automaticallyDisabledConnect to external Wi-Fi networks manuallyEnabledWi-Fi DirectEnabledAllow Security and Privacy SettingsInstall provisioning packageEnabledMandate signed certificate for provisioning packageDisabledRemove provisioning packageEnabledReceive advertisements over BluetoothDisabledPair with other devices automaticallyEnabledOnline speech recognitionDisabledAllow apps to use Advertising IDEnabledUsers can download Windows beta updatesNot ConfiguredWindows AIAI Data AnalysisNot ConfiguredAccount SettingsBlock Microsoft accountsUsers cannot add or log on with Microsoft accountsUsers can change account settingsEnabledUsers can add non-Microsoft accountsEnabledUsers can connect using Microsoft accountsEnabled- [ Windows > Threat Management > Microsoft Defender ](https://www.hexnode.com/mobile-device-management/help/how-to-enable-windows-defender-settings-for-windows-pc-using-hexnode-mdm/)
Policy SettingsConfigurationMicrosoft Defender Application GuardMicrosoft Defender Application GuardEnabledClipboard behaviorCompletely turns Off the clipboard functionality for the Application GuardClipboard settingsAllow text copyingPrint behaviorNoneBlock non-enterprise contentDisabledData persistenceDisabledVirtual GPUDisabledSave files to hostDisabledCertificate ThumbprintsNot configuredAccess Camera and MicrophoneDisabledWindows Defender Security CenterEnable account protection UIEnabledEnable app and browser protection UIEnabledDisallow exploit protection overrideEnabledEnable Device security UIEnabledDisable TPM Firmware update warningDisabledShow the Security processor (TPM) troubleshooting areaEnabledDisable Clear TPM buttonDisabledHide the Secure boot areaDisabledNotificationsDisplay all notificationsEnable family UIEnabledEnable health UIEnabledEnable network UIEnabledEnable virus UIEnabledHide the Ransomware data recovery areaDisabledEnable customized toastsDisabledEnable in-app customizationDisabledCompany nameNot configuredEmail addressNot configuredPhone number/Skype IDNot configuredHelp portal URLNot configuredHide Windows Security notification area controlDisabled- [ Windows > Security > BitLocker ](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/)
BitLocker SettingsConfigurationRequire encryption for OS and fixed data drivesEnabledHide warning about existing third-party encryptionDisabledAllow Standard User EncryptionDisabledRecovery Password rotationNot ConfiguredEscrow recovery password to Hexnode UEMEnabled**OS Drive Settings**Configure BitLocker OS drive policyEnabledConfigure encryption methodDisabledConfigure additional startup authentication settingsEnabledAllow BitLocker to be activated on devices without a compatible TPMDisabledConfigure advanced authentication options for devices with compatible TPMRequired Options: Startup PINMinimum PIN length6Configure pre-boot recovery message and URLDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordOnly Recovery PasswordSave BitLocker recovery information to Active Directory Domain Services (AD DS)Password and KeyBlock certificate-based data recovery agentDisabledHide recovery options on the deviceEnabledDo not enable BitLocker until recovery information is stored in AD DSEnabled**Fixed Drive Settings**Configure BitLocker fixed drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordRecovery Key, Password or bothSave BitLocker recovery information to Active Directory Domain Services (AD DS)DisableBlock certificate-based data recovery agentEnabledHide recovery options on the deviceDisabledDo not enable BitLocker until recovery information is stored in AD DSDisabled**Removable Drive Settings**Configure BitLocker removable drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerEnabled- [ Windows > Configurations > Deploy Custom Configuration ](https://www.hexnode.com/mobile-device-management/help/custom-configuration-for-windows/)
Deploy Custom Configuration SettingsConfigurationEnforce atomic executionEnabled- [ Windows > Patches & Updates > Windows Update Preferences](https://www.hexnode.com/mobile-device-management/help/manage-windows-update-preferences-and-settings/)
SettingsConfigurationUpdate driversEnabledOptional UpdatesNot ConfiguredDownload updates over metered networkNot ConfiguredIgnore download limits for app updatesNot ConfiguredIgnore download limits for OS updatesNot ConfiguredAutomatic wake up for maintenanceEnabledDisable WUfB SafeguardsDisabledTarget productNot ConfiguredTarget versionNot ConfiguredFeature update uninstall period10 day(s)Pre-release buildsDisabledUpdate channelWindows Insider – Fast**Update Deferral**Defer Quality UpdatesEnabledDeferral period (Defer Quality Updates)0 day(s)Defer Feature UpdatesEnabledDeferral period (Defer Feature Updates)180 day(s)- [ Windows > Patches & Updates > Windows Update Experience](https://www.hexnode.com/mobile-device-management/help/configure-windows-update-end-user-experience/)
SettingsConfigurationMicrosoft App Update ServiceDisabledAutomatic update behaviorDisable user control, auto install and restart at a specified timeSchedule Frequency- First week of every month: Enabled
- Second week of every month: Enabled
- Third week of every month: Enabled
- Fourth week of every month: Enabled

Scheduled Install DayAny DayScheduled Install TimeNot ConfiguredSkip restart checksDisabledDisable pause updatesEnabledDisallow users to check for updatesDisabled**Notifications**Update notification levelNot ConfiguredNotifications during Active HoursNot ConfiguredAuto-restart notificationsNot Configured**Deadlines**Configure update deadlinesDisabledConfigure restart deadlinesDisabledConfigure engaged restart deadlinesDisabled

 

 

CIS Benchmark Compliance (Windows 11: Level 1 + BitLocker) - Microsoft Entra ID 

**Template name:** CIS Benchmark Compliance (Windows 11: Level 1 + BitLocker) – Microsoft Entra ID

**Description:** Apply this template to get one step closer to CIS compliance on your Windows devices.

**Note:** Not all rules mentioned in CIS Benchmark are configurable via Hexnode.

**Template Configuration:**

- [ Windows > Password](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-password-policy-for-windows/)
Password settingsConfigurationAllow simple valueDisabledPassword typeAlphanumeric passwordMinimum password length14Password ComplexityDigits, lowercase and uppercase lettersMinimum password age (in days)365Auto-lock (in minutes)15Password history24Failed attempt before wipe0- [ Windows > Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#basic-restrictions)
RestrictionsConfigurationAllow device functionalityCameraEnabledCortana voice assistantDisabledUse Cortana if device is lockedDisabledUse storage card and USB drivesEnabledTelemetrySend basic device info and security dataLocation servicesForce Location OffChange languageEnabledUsers can enable/disable WorkplaceEnabledUsers can change AutoPlay settingsEnabledAllow App SettingsSync SettingsEnabledAllow SignIn OptionsEnabledAllow News and InterestsDisabledMicrosoft feedback notificationsDisabledGame DVRDisabledAllow Network SettingsWi-FiEnabledBluetoothEnabledDiscover device over BluetoothEnabledUsers can turn VPN on/offEnabledConnect to VPN if on mobile networkEnabledConnect to VPN if roamingEnabledCellular data roamingEnabledAllow Security and Privacy SettingsManual MDM administration removalEnabledShow toast notification on lock screenEnabledAccount SettingsOneDrive file syncDisabled- [ Windows > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/restrictions-for-windows-devices/#advanced-restrictions)
RestrictionsConfigurationAllow device functionalityUsers can reset the deviceEnabledUsers can change date and timeEnabledUsers can change power and sleep settingsEnabledAllow Embedded ModeDisabledAllow RegionEnabledEnd task from Task ManagerEnabledProjection from deviceEnabledProjection to deviceEnabledRequire PIN for pairingFirst timeFile Explorer SettingsAllowed folder locationsAll folder locationsAllowed storage locationsAll storage locationsAllow App SettingsUnlock developer optionsDefaultAuto-update of store appsNot configuredSearch can use user locationDisabledAllow Network SettingsInternet SharingEnabledConnect to Wi-Fi Sense automaticallyDisabledConnect to external Wi-Fi networks manuallyEnabledWi-Fi DirectEnabledAllow Security and Privacy SettingsInstall provisioning packageEnabledMandate signed certificate for provisioning packageDisabledRemove provisioning packageEnabledReceive advertisements over BluetoothDisabledPair with other devices automaticallyEnabledOnline speech recognitionDisabledAllow apps to use Advertising IDEnabledUsers can download Windows beta updatesNot ConfiguredWindows AIAI Data AnalysisNot ConfiguredAccount SettingsBlock Microsoft accountsUsers cannot add or log on with Microsoft accountsUsers can change account settingsEnabledUsers can add non-Microsoft accountsEnabledUsers can connect using Microsoft accountsEnabled- [ Windows > Threat Management > Microsoft Defender ](https://www.hexnode.com/mobile-device-management/help/how-to-enable-windows-defender-settings-for-windows-pc-using-hexnode-mdm/)
Policy SettingsConfigurationMicrosoft Defender Application GuardMicrosoft Defender Application GuardEnabledClipboard behaviorCompletely turns Off the clipboard functionality for the Application GuardClipboard settingsAllow text copyingPrint behaviorNoneBlock non-enterprise contentDisabledData persistenceDisabledVirtual GPUDisabledSave files to hostDisabledCertificate ThumbprintsNot configuredAccess Camera and MicrophoneDisabledWindows Defender Security CenterEnable account protection UIEnabledEnable app and browser protection UIEnabledDisallow exploit protection overrideEnabledEnable Device security UIEnabledDisable TPM Firmware update warningDisabledShow the Security processor (TPM) troubleshooting areaEnabledDisable Clear TPM buttonDisabledHide the Secure boot areaDisabledNotificationsDisplay all notificationsEnable family UIEnabledEnable health UIEnabledEnable network UIEnabledEnable virus UIEnabledHide the Ransomware data recovery areaDisabledEnable customized toastsDisabledEnable in-app customizationDisabledCompany nameNot configuredEmail addressNot configuredPhone number/Skype IDNot configuredHelp portal URLNot configuredHide Windows Security notification area controlDisabled- [ Windows > Security > BitLocker ](https://www.hexnode.com/mobile-device-management/help/how-to-manage-bitlocker-with-hexnode-mdm/)
BitLocker SettingsConfigurationRequire encryption for OS and fixed data drivesEnabledHide warning about existing third-party encryptionDisabledAllow Standard User EncryptionDisabledRecovery Password rotationNot ConfiguredEscrow recovery password to Hexnode UEMEnabled**OS Drive Settings**Configure BitLocker OS drive policyEnabledConfigure encryption methodDisabledConfigure additional startup authentication settingsEnabledAllow BitLocker to be activated on devices without a compatible TPMDisabledConfigure advanced authentication options for devices with compatible TPMRequired Options: Startup PINMinimum PIN length6Configure pre-boot recovery message and URLDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordOnly Recovery PasswordSave BitLocker recovery information to Active Directory Domain Services (AD DS)Password and KeyBlock certificate-based data recovery agentDisabledHide recovery options on the deviceEnabledDo not enable BitLocker until recovery information is stored in AD DSEnabled**Fixed Drive Settings**Configure BitLocker fixed drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerDisabledConfigure recovery optionsEnabledUsers must generate a recovery key or passwordRecovery Key, Password or bothSave BitLocker recovery information to Active Directory Domain Services (AD DS)DisableBlock certificate-based data recovery agentEnabledHide recovery options on the deviceDisabledDo not enable BitLocker until recovery information is stored in AD DSDisabled**Removable Drive Settings**Configure BitLocker removable drive policyEnabledConfigure encryption methodDisabledBlock access to drives not protected by BitLockerEnabled- [ Windows > Configurations > Deploy Custom Configuration ](https://www.hexnode.com/mobile-device-management/help/custom-configuration-for-windows/)
Deploy Custom Configuration SettingsConfigurationEnforce atomic executionEnabled- [ Windows > Patches & Updates > Windows Update Preferences](https://www.hexnode.com/mobile-device-management/help/manage-windows-update-preferences-and-settings/)
SettingsConfigurationUpdate driversEnabledOptional UpdatesNot ConfiguredDownload updates over metered networkNot ConfiguredIgnore download limits for app updatesNot ConfiguredIgnore download limits for OS updatesNot ConfiguredAutomatic wake up for maintenanceEnabledDisable WUfB SafeguardsDisabledTarget productNot ConfiguredTarget versionNot ConfiguredFeature update uninstall period10 day(s)Pre-release buildsDisabledUpdate channelWindows Insider – Fast**Update Deferral**Defer Quality UpdatesEnabledDeferral period (Defer Quality Updates)0 day(s)Defer Feature UpdatesEnabledDeferral period (Defer Feature Updates)180 day(s)- [ Windows > Patches & Updates > Windows Update Experience](https://www.hexnode.com/mobile-device-management/help/configure-windows-update-end-user-experience/)
SettingsConfigurationMicrosoft App Update ServiceDisabledAutomatic update behaviorDisable user control, auto install and restart at a specified timeSchedule Frequency- First week of every month: Enabled
- Second week of every month: Enabled
- Third week of every month: Enabled
- Fourth week of every month: Enabled

Scheduled Install DayAny DayScheduled Install TimeNot ConfiguredSkip restart checksDisabledDisable pause updatesEnabledDisallow users to check for updatesDisabled**Notifications**Update notification levelDefault Windows NotificationNotifications during Active HoursNot ConfiguredAuto-restart notificationsNot Configured**Deadlines**Configure update deadlinesDisabledConfigure restart deadlinesDisabledConfigure engaged restart deadlinesDisabled

 

 

POS Device Policy

A pre-configured policy template for securing point-of-sale (POS) devices with the necessary security configurations and restrictions.

**Template name:** POS Device Policy

**Description:** Secure POS devices by enforcing pre-configured security configurations.

**Template Configuration:**

- [iOS > Basic Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-ios-mdm-restrictions-using-hexnode-mdm/)
RestrictionsConfigurationAllow Device FunctionalityCameraEnabledFaceTimeEnabledScreen captureEnabledAllow Remote Screen ObservationEnabledTouch IDEnabledSiriEnabledAllow Siri while device is lockedEnabledVoice dialingEnabledAutomatic sync while roamingEnabledAllow Application SettingsInstall appsDisablediTunes StoreEnabledForce user to enter iTunes store password for each purchaseEnabledIn-app purchasesEnabled;Trust enterprise appEnabledUsers can modify enterprise app trustEnabledBackup enterprise-deployed iBooksEnabledSync managed app data with iCloudDisabledYouTubeEnabledSafariEnabledAutofillEnabledFraud warningDisabledJavaScriptEnabledBlock pop-upsEnabledAccept cookiesAlwaysAccess Passbook when the device is lockedDisabledAdd friends in Game CenterEnabledAllow iCloud SettingsBackupEnabledSync documentsEnabledPhoto StreamEnabledShare photo streamsEnablediCloud photo libraryEnabledSync enterprise book metadata across devicesEnabledAllow Security and Privacy SettingsLock screen notificationsEnabledToday View on lock screenEnabledControl Center on lock screenEnabledOver the air PKI updatesEnabledLimit ad trackingDisabledSend diagnostic data to AppleEnabledAccept untrusted TLS certificateEnabledForce encrypted backupDisabledShow notification on Apple Watch if wornDisabledAllow Explicit ContentExplicit music, podcasts and iTunes servicesEnablediBooks store eroticaDisabledRating regionUnited StatesMoviesAllow All MoviesTV ShowsAllow All TV ShowsAppsAllow All Apps- [iOS > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-ios-mdm-restrictions-using-hexnode-mdm/#advanced-restrictions)
RestrictionsConfigurationAllow Device FunctionalityAirDropEnabledApps can modify cellular data usageEnabledAdd or remove Touch ID/Face IDEnablediMessageEnabledRCS messagingEnabledGame CenterEnabledMultiplayer gamingEnabledInstall configuration profileEnabledHandoffEnabledDefinition lookupEnabledPredictive keyboardEnabledAuto-correct wordsEnabledSuggest words on misspellingsEnabledQuickPath KeyboardEnabledKeyboard shortcutsEnabledUSB Drive Access in Files AppEnabledNetwork Drive Access in Files AppEnabledPair with Apple WatchEnabledModify diagnostic data submission settingsEnabledModify Bluetooth settingsEnabledUse voice to typeEnabledForce Wi-Fi ONEnabledConnect to MDM-configured Wi-Fi networks onlyDisabledUsers can modify Personal Hotspot settingsEnabledCreate VPN configurationEnabledAirPrintEnabledConnect with iBeaconEnabledStore AirPrint credentials in KeychainEnabledUse trusted certificates for secure printingDisabledModify cellular plan settingsEnabledeSIM ModificationEnabledOutgoing eSIM transferEnabledLive VoicemailEnabledForce preserve eSIM on eraseDisabledAuto dimmingEnablediPhone mirroringEnabledCall recordingEnabledAllow App SettingsInstall app from App StoreDisabledInstall apps from third-party app marketplacesEnabledInstall apps from webEnabledRemove appsDisabledRemove system appsEnablediBooks storeEnabledApple MusicEnablediTunes RadioEnabledNewsEnabledPodcastsEnabledDownload all purchased apps automaticallyEnabledLock appsEnabledHide appsEnabledAllow Security and Privacy SettingsActivation LockDisabledModify an accountEnabledErase content and settingsEnabledSiri can access user-generated contentEnabledFind My FriendsEnabledFind My DeviceEnabledModify Find My FriendsEnabledUse profanity filterDisabledShow web results using Spotlight SearchEnabledModify Restrictions/Screen TimeEnabledModify passcodeEnabledModify device nameEnabledUsers can modify default browserEnabledModify wallpaperEnabledUsers can turn notifications on/offEnabledForce Automatic Date and TimeDisabledAutofill PasswordsEnabledRequest passwords from nearby devicesEnabledShare passwords via Airdrop Passwords featureEnabledAllow USB accessories when lockedDisabledPrevent pairing with non-Configurator hostsDisabledShared iPad temporary sessionEnabledAllow Apple IntelligenceGenmojiEnabledImage PlaygroundEnabledImage WandEnabledPersonalized Handwriting ResultsEnabledWriting ToolsEnabledMail SummaryEnabledChatGPT integrationEnabledChatGPT user account sign-inEnabled- [**iOS > App Management > Blocklist/Allowlist**](https://www.hexnode.com/mobile-device-management/help/how-to-block-apps-on-ios-devices-using-hexnode-mdm/)
    Policy SettingAppsAllowlistSettingsPhoneFaceTime
- [**Android > Basic Restrictions**](https://www.hexnode.com/mobile-device-management/help/set-up-android-mdm-restrictions-using-hexnode-mdm/#basic-restrictions)
    Policy SettingsConfigurationAllow Device FunctionalityCameraEnabledUSB Mass StorageEnabledUSB file transferDisabledHome buttonEnabledPower OffDisabledSafe modeEnabledAirplane modeEnabledLock screen shortcutsEnabledWidgets on lock screenEnabledScreen OrientationAllow user to chooseScreen TimeoutKeep Current SettingsAllow Network SettingsWi-FiEnabledForce Wi-FiEnabledBluetoothEnabledForce BluetoothDisabledMobile data/td> EnabledTetheringEnabledUSB tetheringEnabledBluetooth tetheringEnabledPortable Wi-Fi hotspotUsers can chooseData roamingEnabledConnect to 2G networkEnabledAllow Location SettingsMock locationEnabledGPSEnabledForce GPS to fetch locationEnabledAllow Sync SettingsBackup serviceDisabledSecurity OptionsAllow MDM Administration removalDisabled
- [Android > Advanced Restrictions](https://www.hexnode.com/mobile-device-management/help/set-up-android-mdm-restrictions-using-hexnode-mdm/#advanced-restrictions)
Policy SettingConfigurationAllow Device functionalityMicrophoneEnabledScreen captureDisabledClipboardDisabledShare via other appsEnabledUsers can adjust volumeEnabledMake a callEnabledReceive callsEnabledUSB Host StorageEnabledAllow input methodsEnabledAllow SettingsDeveloper modeEnabledUSB debuggingEnabledModify settingsEnabledPower saving modeEnabledUsers can enable location sharingEnabledFactory ResetEnabledAdvanced Factory ResetEnabledRead any connected physical external mediaEnabledDisable screen lock if the screen was turned offDisabledConfigure VPNEnabledAutomatically power off a device when power cable is detachedDisabledAutomatically power on a device when power cable is connectedDisabledDate and Time SettingsSet date and time automaticallyEnabledSet time zone automaticallyEnabledAllow users to modify date, time and time zoneEnabledTime formatKeep Current SettingsLock Screen CustomizationsLock Screen CameraEnabledTrust Agents for Smart LockEnabledLock Screen NotificationsEnabledFingerprint UnlockEnabledIris ScannerEnabledFace UnlockEnabledUnredacted NotificationsEnabledAllow App SettingsInstall appsEnabledUninstall appsEnabledControl appsEnabledGoogle Play StoreEnabledVerify apps before installDisabledInstall apps from unknown sourcesEnabledApp Runtime PermissionsDefaultParent profile app linkingEnabledAllow cross-profile app communicationDisabledFactory Reset Protection (Google Account Verification)DefaultAccessibility SettingsAccessibility servicesEnabledAccessibility servicesDisabled- [**Kiosk Lockdown > iOS Kiosk Lockdown > Multi App**](https://www.hexnode.com/mobile-device-management/help/how-to-enable-multiple-app-kiosk-mode-in-ios/)
    **Apps added in kiosk**: Settings, Phone, FaceTime
- [**Kiosk Lockdown > Android Kiosk Lockdown > Multi App**](https://www.hexnode.com/mobile-device-management/help/enable-multi-app-kiosk-mode-android-devices/)
    **Apps added in kiosk**: Google Chrome
- [**Kiosk Lockdown > Android Kiosk Lockdown > Peripheral Settings**](https://www.hexnode.com/mobile-device-management/help/how-to-enable-peripheral-settings-for-android-devices-locked-in-kiosk-mode/)
    Policy SettingConfigurationUsers can turn Wi-Fi on/offDisabledConnect to and switch between saved Wi-Fi networksDisabledAdd hidden Wi-Fi networksDisabledUsers can delete Wi-Fi networksDisabledUsers can disconnect from currently connected networkDisabledShow all available Wi-Fi networksDisabledAuto-exit Wi-Fi settings page inDisabledWi-Fi HotspotDisabledUsers can configure Wi-Fi hotspotDisabledUsers can turn mobile data on/offDisabledUsers can choose preferred network typeDisabledAllow users to turn Bluetooth on/offDisabledAirplane modeDisabledUsers can enable accessibility settingsDisabledDisplayDisable system barsDisabledEnable status barDisabledKeep screen OnEnabledBrightnessKeep current brightnessHardware/software buttonsUsers can turn device OffEnabledDisable volume buttonDisabledEnable Recent apps buttonDisabledAdvanced LockLock task modeDisabledSystem InfoDisabledHome buttonDisabledNotificationsDisabledRecent apps buttonDisabledGlobal actionsDisabledActivate Lock task mode on reboot while the device is lockedDisabledHexnode MDM SettingsShow option to manually exit kiosk lockdownDisabledGrant Hexnode MDM any newer permissions manuallyDisabledSync device with MDMDisabledShow device and server informationDisabledApp SettingsAccess app catalogs in kioskDisabledShow blocked package name on the deviceEnabledDisable app crash reportingDisabledClear apps from background when user leaves the appDisabledEnable required app installation in kioskDisabledLocationUsers can add location notesDisabledMessengerView messages sent by adminDisabledOther optionsAllow users to turn flashlight on/offDisabledAllow users to modify device passwordDisabledFloating iconDisabledTap & Swipe gestureDisabledTriple tap on the top-right corner of the screen to show device and server details optionDisabledTriple tap on the top-right corner of the screen to show peripheral settingsDisabled
- [**Kiosk Lockdown > Android Kiosk Lockdown > Kiosk Exit Settings**](https://www.hexnode.com/mobile-device-management/help/how-to-exit-android-kiosk-mode-in-hexnode-mdm/)
    Policy SettingsConfigurationAllow manually exiting kiosk modeEnabledNumber of taps to display the popup to enter the exit passcode10Exit manually from kiosk mode while an app is openDisabledReboot and tap to exit from kiosk modeEnabledRelaunch app20 seconds after rebootAuto-enable kiosk modeDisabled

 

 

Website Kiosk for Android TV

A pre-configured policy to set up a website kiosk on Android TVs.

**Template name:** Website Kiosk for Android TV

**Description:** Lock down your Android TVs to a specific website using website kiosk mode.

**Template Configuration:**

- **[Kiosk Lockdown > Android Kiosk Lockdown > Single App](https://www.hexnode.com/mobile-device-management/help/lock-android-devices-single-app-kiosk-mode/)**
    **Apps added**: Hexnode MDM Portal (*Web App*)
- [Kiosk Lockdown > Android Kiosk Lockdown > Launcher](https://www.hexnode.com/mobile-device-management/help/how-to-set-up-kiosk-launcher-on-android-devices-with-hexnode/)
    Policy SettingsConfigurationAuto-LaunchSelect appHexnode MDM PortalApp auto-launch delay20 secondsCustomizationsCustomize kiosk launcherDisabledIcon sizeMediumFont sizeSmallTitle bar height10 % of screen heightLogo height50 % of title bar heightLogo width25 % of screen widthTitle fontHelveticaTitle height50 % of title bar heightTitle colorDefaultTitle bar background colorDefaultLogo-title alignmentLeft
- **[Kiosk Lockdown > Android Kiosk Lockdown > Kiosk Exit Settings](https://www.hexnode.com/mobile-device-management/help/how-to-exit-android-kiosk-mode-in-hexnode-mdm/)**
    Policy SettingsConfigurationAllow manually exiting kiosk modeEnabledNumber of taps to display the popup to enter the exit passcode10Exit manually from kiosk mode while an app is openDisabledReboot and tap to exit from kiosk modeEnabledRelaunch app20 seconds after rebootAuto-enable kiosk modeDisabled

 

 

Kiosk Lockdown for Android TV

A policy template to lock down Android TV to a set of apps using pre-configured kiosk configurations.

**Template name:** Kiosk Lockdown for Android TV

**Description:** Lock down your Android TV to a handful of applications.
**Template Configuration:**

- **[Kiosk Lockdown > Android Kiosk Lockdown > Multi App](https://www.hexnode.com/mobile-device-management/help/enable-multi-app-kiosk-mode-android-devices/)**
    - **Apps added**: YouTube for Android TV
    - **Customizations**: Icon size (Medium)
- **[Kiosk Lockdown > Android Kiosk Lockdown >Kiosk Exit Settings](https://www.hexnode.com/mobile-device-management/help/kiosk-settings-on-chromeos/)**
    Policy SettingsConfigurationAllow manually exiting kiosk modeEnabledNumber of taps to display the popup to enter the exit passcode10Exit manually from kiosk mode while an app is openDisabledReboot and tap to exit from kiosk modeEnabledRelaunch app20 seconds after rebootAuto-enable kiosk modeDisabled

 

 

Android TV Security Settings

A policy template to secure Android TV using password policies and restrictions.

**Template name:** Android TV Security Settings

**Description:** Secure Android TV by enforcing password rules and restrictions.

**Template Configuration:**

- **[Android > Password > Device Password](https://www.hexnode.com/mobile-device-management/help/password-policy-for-android/)**
    Policy SettingsConfigurationMinimum password complexityNoneCustomize password complexityEnabledPassword ComplexityAlphanumericMinimum Passcode Length8Auto-lock after5
- **[Android > Restrictions > Basic](https://www.hexnode.com/mobile-device-management/help/set-up-android-mdm-restrictions-using-hexnode-mdm/#basic-restrictions)**
    Policy SettingsConfigurationAllow Device FunctionalityCameraEnabledUSB Mass StorageEnabledUSB file transferDisabledHome buttonEnabledPower OffDisabledSafe modeEnabledAirplane modeEnabledLock screen shortcutsEnabledWidgets on lock screenEnabledScreen OrientationAllow user to chooseScreen TimeoutKeep Current SettingsAllow Network SettingsWi-FiEnabledForce Wi-FiEnabledBluetoothDisabledForce BluetoothDisabledMobile dataEnabledTetheringEnabledUSB tetheringEnabledBluetooth tetheringEnabledPortable Wi-Fi hotspotUsers can chooseData roamingEnabledConnect to 2G networkEnabledAllow Location SettingsMock locationEnabledGPSEnabledForce GPS to fetch locationEnabledAllow Sync SettingsBackup serviceEnabledSecurity OptionsAllow MDM Administration removalEnabled

 

 

To create a policy from the template,
-------------------------------------

To create a policy from the template, you can either copy the template to **My Policies**, or else you can choose the template directly while creating a new policy.

To choose the template directly while creating a policy,

1. In the Hexnode portal, go to **Policies**.
2. Click on **New Policy** and select the template that you want to use.
3. Go to **Policy Targets** > **+Add Devices** > choose the devices to which the policy has to be associated.
4. Click on **Ok > Save**.

To copy the template to My Policies,

1. In the Hexnode portal, go to **Policies > Templates**.
2. Select the template that you want to copy and click on **Manage**.
3. Click on Copy to **My Policies**.
4. Go to **Policy Targets** > **+Add Devices** > choose the devices to which the policy has to be associated.
5. Click on **Ok > Save**.

Apart from devices, you can also associate the policy to Device Groups, Users, User Groups and Domains.