Config Hardening for Windows
See how Windows endpoints are actually configured across every customer.
Run a read-only assessment of Windows security configuration across every customer. Get client, evidence and technician reports from the same assessment.
active controls across the shipped catalog
controls evaluated per device
assessment, no settings changed
from one assessment
Windows Config Hardening is a read-only assessment of Windows security configuration across customer environments, reporting weak, missing or inconsistent settings with client, evidence and technician reports from the same assessment.

Visibility across every device
You can't secure what you can't see. Config Hardening runs a read-only assessment of Windows security configuration so you can see weak, missing or inconsistent settings across every customer environment.
The same assessment produces a client-facing summary, an evidence report designed for auditor or insurer review, and an internal technician report. Your team decides which changes are right for each environment.
What Does ThreatMate Assess?
See how Windows security is actually configured across every customer.
Credential & Authentication Protections
Checks Windows protections that reduce credential theft and abuse, including credential-related policies, legacy authentication settings and other security controls.
Attack Surface Reduction
Identifies missing or weak Windows protections designed to limit common attacker techniques, including Microsoft Defender Attack Surface Reduction rules.
Disk Encryption
Checks BitLocker configuration and the live encryption state of Windows volumes to identify unprotected or weakly configured devices.
Network & Protocol Hardening
Finds risky or legacy Windows networking configurations, including controls such as SMB signing and older name-resolution or authentication protocols.
Windows Security Policies
Assesses local security policy, user rights, audit policy and other operating-system security settings that are difficult to review consistently across customers.
Microsoft Defender Configuration
Reviews Microsoft Defender security configuration alongside the Windows operating-system assessment.
Deep Windows Configuration Visibility
Config Hardening evaluates hundreds of security controls on every assessed endpoint and gives MSPs the detail to understand what is configured, what is missing and what needs attention.
controls per device depending on the Windows operating system.
active controls across the shipped Windows and Defender catalog.
distinct settings covered across the complete catalog.
assessment. ThreatMate measures configuration without making changes.
client, evidence and technician views from the same assessment.
see how findings map to frameworks including PCI DSS 4.0, HIPAA, SOC 2, ISO 27001, Essential Eight and CAN/DGSI 104.
Mappings help organize evidence and remediation work. They do not certify compliance.
Reduce Attack Surface
Every missing security control leaves another door open.
Config Hardening shows MSPs where Windows protections are missing, weak or inconsistent across their customer base, so they can prioritize the changes that reduce exposure without blindly applying the same configuration everywhere.
See Platform OverviewFrequently Asked Questions
Summary
- Read-only Windows security configuration assessment across every customer environment
- 2,342 active controls across the shipped catalog, with 449–622 evaluated per device depending on OS
- Client, evidence and technician reports from a single assessment
- Monitors disk encryption, antivirus, firewall, and Secure Boot status
- Detects unsigned processes and insecure services that expand attack surface
- Discovers installed security tools and agents to identify coverage gaps
- Evidence reports designed for auditor or insurer review
See how ThreatMate identifies and prioritizes risk for MSPs
15 minutes. No pressure. See how ThreatMate identifies and prioritizes risk for multi-tenant MSP operations.