Workstation Baseline
What every DTC-managed workstation gets, whatever the client and whatever tools we happen to use that year. Each line is a practice, the baseline we commit to, and what we use today. Industry differences (patch speed, platforms) are in How the Pillars Work — Baselines & Industry Profiles. How each line is implemented today is in the Workstation Baseline — Enforcement Map.
| Area | Practice and baseline | Today we use |
|---|---|---|
| Management | Every workstation is enrolled in our RMM before it is handed over. Settings are converged on a schedule, not configured once, and drift alerts. | NinjaOne, ninja-one-automation scripts |
| Hardware | Business-class hardware meeting the purchasing standard; no consumer editions of Windows. | Endpoint Hardware Purchasing Standard |
| Identity | Every device carries a permanent DTC identifier. | OUID |
| Local admin | One DTC local admin (dtcadmin), unique random password per device, rotated at least monthly. Builds use the temporary installadmin, which disables itself after 7 days of inactivity and is then removed. | LAPS rotation from the RMM — Credential Standard |
| Encryption | OS drive encrypted with the recovery key escrowed to the directory before encryption starts. A suspended or unprotected drive alerts. | BitLocker, escrow to AD / Entra ID |
| Threat protection | One managed EDR watched by a 24/7 SOC, plus one anti-malware engine with real-time protection on. Never a second security agent. | Blackpoint Cyber MDR, Microsoft Defender Antivirus |
| Firmware | Secure Boot on wherever the hardware supports it; Wake-on-LAN enabled so maintenance can run after hours; firmware and drivers kept current through the OEM's tooling. | Dell Command | Update / Configure |
| Patching | OS, drivers and third-party apps patched on the schedule for the client's industry profile. | RMM patch policies — MSA Windows OS Patching |
| Unapproved remote tools | Only DTC's sanctioned remote-access tools may be installed; anything else is detected and removed. | Shadow-IT detection and removal |
| Web & DNS protection | Laptops are protected off the network too. | DNSFilter roaming agent on DNSFilter sites |
| Remote work | Remote workers reach internal resources through zero-trust access, not a traditional VPN. | Cloudflare WARP |
| Backup | Workstations under a backup agreement are image-backed and verified per the backup pillar. | NinjaOne Backup — Backup & Data Protection Standards |
| Recovery | Windows can repair a bad-update boot failure without a technician on site. | Quick Machine Recovery — Windows Endpoints |
Security controls in more depth: Security Standards.