Platform Feature

    Config Hardening for Windows

    See how Windows endpoints are actually configured across every customer.

    Run a read-only assessment of Windows security configuration across every customer. Get client, evidence and technician reports from the same assessment.

    2,342

    active controls across the shipped catalog

    449–622

    controls evaluated per device

    Read-only

    assessment, no settings changed

    Three reports

    from one assessment

    Windows Config Hardening is a read-only assessment of Windows security configuration across customer environments, reporting weak, missing or inconsistent settings with client, evidence and technician reports from the same assessment.

    Configuration hardening report showing where the risk is across Windows security areas such as Attack Surface Reduction, Microsoft Defender and Windows Firewall

    Visibility across every device

    You can't secure what you can't see. Config Hardening runs a read-only assessment of Windows security configuration so you can see weak, missing or inconsistent settings across every customer environment.

    The same assessment produces a client-facing summary, an evidence report designed for auditor or insurer review, and an internal technician report. Your team decides which changes are right for each environment.

    Windows 10Windows 11Windows Server 2019Windows Server 2022Windows Server 2025Microsoft Defender baseline

    What Does ThreatMate Assess?

    See how Windows security is actually configured across every customer.

    Credential & Authentication Protections

    Checks Windows protections that reduce credential theft and abuse, including credential-related policies, legacy authentication settings and other security controls.

    Attack Surface Reduction

    Identifies missing or weak Windows protections designed to limit common attacker techniques, including Microsoft Defender Attack Surface Reduction rules.

    Disk Encryption

    Checks BitLocker configuration and the live encryption state of Windows volumes to identify unprotected or weakly configured devices.

    Network & Protocol Hardening

    Finds risky or legacy Windows networking configurations, including controls such as SMB signing and older name-resolution or authentication protocols.

    Windows Security Policies

    Assesses local security policy, user rights, audit policy and other operating-system security settings that are difficult to review consistently across customers.

    Microsoft Defender Configuration

    Reviews Microsoft Defender security configuration alongside the Windows operating-system assessment.

    Deep Windows Configuration Visibility

    Config Hardening evaluates hundreds of security controls on every assessed endpoint and gives MSPs the detail to understand what is configured, what is missing and what needs attention.

    449–622

    controls per device depending on the Windows operating system.

    2,342

    active controls across the shipped Windows and Defender catalog.

    1,117

    distinct settings covered across the complete catalog.

    Read-only

    assessment. ThreatMate measures configuration without making changes.

    Three reports

    client, evidence and technician views from the same assessment.

    Framework mappings

    see how findings map to frameworks including PCI DSS 4.0, HIPAA, SOC 2, ISO 27001, Essential Eight and CAN/DGSI 104.

    Mappings help organize evidence and remediation work. They do not certify compliance.

    Reduce Attack Surface

    Every missing security control leaves another door open.

    Config Hardening shows MSPs where Windows protections are missing, weak or inconsistent across their customer base, so they can prioritize the changes that reduce exposure without blindly applying the same configuration everywhere.

    See Platform Overview
    FAQ

    Frequently Asked Questions

    Summary

    • Read-only Windows security configuration assessment across every customer environment
    • 2,342 active controls across the shipped catalog, with 449–622 evaluated per device depending on OS
    • Client, evidence and technician reports from a single assessment
    • Monitors disk encryption, antivirus, firewall, and Secure Boot status
    • Detects unsigned processes and insecure services that expand attack surface
    • Discovers installed security tools and agents to identify coverage gaps
    • Evidence reports designed for auditor or insurer review
    Schedule Your Demo

    See how ThreatMate identifies and prioritizes risk for MSPs

    15 minutes. No pressure. See how ThreatMate identifies and prioritizes risk for multi-tenant MSP operations.