Skip to main content

Workstation Baseline — Enforcement Map (ninja-one-automation)

The standard configuration every DTC-managed Windows workstation converges to. It is enforced by scripts in ninja-one-automation that run unattended under the NinjaOne agent, so this page states what the standard is and which script holds it. The script's static config block is where a value actually lives; if this page and a script disagree, raise it — one of them is wrong.

Rewritten 2026-10-05 from the scripts on main. The previous version described msft-windows-config-*.ps1 scripts on an enhancement/workstation-standards branch that no longer exist anywhere in the repo.

How the scripts are organised

Category → product → role. The role says how a script is wired in NinjaOne:

  • configuration/ — converges the device to the standard; scheduled, idempotent, safe to re-run forever.
  • inventory/ — reads state and publishes it to NinjaOne custom fields; the source for dashboards and conditions.
  • conditions/ — one check, exit code only; wired as a NinjaOne Script Result condition.
  • remediation/ — a one-shot fix attached to a condition or run on demand.

The standard

AreaStandardEnforced by
IdentityEvery device carries a DTC OUID (UUIDv7, minted once, never changed). See OUID Standard.endpoint/device/configuration/set-device-ouid.ps1
Local admindtcadmin, 16+ random characters, rotated by LAPS; current and four previous passwords kept in secure NinjaOne fields. See Client Credential Administration Standard.identity/local-identity/configuration/laps.ps1
Disk encryptionBitLocker on the OS drive, TPM + 48-digit recovery password (created before encryption starts), XtsAes256. Recovery passwords escrowed to AD and/or Entra ID by join state. Suspended or unprotected volumes alert.security/bitlocker/configuration/bitlocker-enable.ps1, bitlocker-resume.ps1; conditions bitlocker-suspended, bitlocker-unprotected, bitlocker-no-recovery-password; DC side identity/active-directory/configuration/ad-bitlocker-escrow-read-delegate.ps1
EDRBlackpoint Unified Agent v3 installed and healthy (legacy SNAP agent on older sites until migrated).security/blackpoint/configuration/blackpoint-agent-v3-provision.ps1
Anti-malwareMicrosoft Defender Antivirus present, real-time protection always on, per-client exclusions applied. Core Isolation (HVCI) is disabled by default — without disabling Hyper-V/VBS — and re-enabled per device by unchecking defenderDisableCoreIsolation.security/defender/configuration/defender-provision.ps1
DNS filteringOn DNSFilter sites, laptops get the DNSFilter Roaming Client automatically; desktops only when flagged. See DHCP & DNS — Roaming Endpoints.security/dnsfilter/configuration/dnsfilter-provision.ps1
Remote accessCloudflare WARP for remote workers, version-converged. See Remote Access.network/cloudflare-warp/configuration/cloudflare-warp-provision.ps1
Unapproved remote toolsRMM and remote-access tools not on the approved list are detected and removed (removal is dry-run unless Execute is set). Allowlist beats blocklist, per org/location/device.security/shadow-it/inventory/shadow-it-detect.ps1, security/shadow-it/configuration/shadow-it-remove.ps1
Downloads executionAppLocker blocks executables launched from user download locations (audit, then enforce, per client).security/applocker/inventory/applocker-download-block-inventory.ps1, …/remediation/applocker-download-block-remediate.ps1
FirmwareSecure Boot on wherever the firmware allows it (UEFI); Wake-on-LAN enabled; Deep Sleep disabled. Secure Boot off on a UEFI machine alerts. Dell today; other OEMs pass through untouched.endpoint/oem/configuration/oem-firmware-configure.ps1; security/secure-boot/*
OEM tooling & driversDell Command | Update and Dell Command | Configure installed at the approved version; firmware and driver updates applied through them.endpoint/oem/configuration/oem-update-tool-provision.ps1, endpoint/oem/remediation/oem-firmware-driver-update.ps1
Image backupWorkstations confirmed for backup service get the NinjaOne image plan. See Backup & Data Protection Standards.NinjaOne backup plan (configuration standard); backup/ninjaone-backup/configuration/lockhart-throttle.ps1 caps the backup agent's CPU
RecoveryWindows Quick Machine Recovery is always on.See Windows Endpoints
HygieneDuplicate local profiles alert and can be removed; pending reboots are reconciled after boot; script logs pruned.endpoint/user-profiles/*, maintenance/remediation/reboot-pending-reconcile.ps1, maintenance/remediation/clear-old-logs.ps1

Hardware

What a workstation must be before we buy it is in the Endpoint Hardware Purchasing Standard. Vendor-bundled security software is removed from the quote, not left uninstalled.

Not yet scripted

Anything we expect on a workstation that no script converges yet belongs here until it is automated, so the gap is visible rather than assumed covered. Known today: Lenovo and HP firmware/driver lanes (tooling exists, disabled — nothing drives it).