Workstation Baseline — Enforcement Map (ninja-one-automation)
The standard configuration every DTC-managed Windows workstation converges to. It is enforced by scripts in ninja-one-automation that run unattended under the NinjaOne agent, so this page states what the standard is and which script holds it. The script's static config block is where a value actually lives; if this page and a script disagree, raise it — one of them is wrong.
Rewritten 2026-10-05 from the scripts on main. The previous version described msft-windows-config-*.ps1 scripts on an enhancement/workstation-standards branch that no longer exist anywhere in the repo.
How the scripts are organised
Category → product → role. The role says how a script is wired in NinjaOne:
- configuration/ — converges the device to the standard; scheduled, idempotent, safe to re-run forever.
- inventory/ — reads state and publishes it to NinjaOne custom fields; the source for dashboards and conditions.
- conditions/ — one check, exit code only; wired as a NinjaOne Script Result condition.
- remediation/ — a one-shot fix attached to a condition or run on demand.
The standard
| Area | Standard | Enforced by |
|---|---|---|
| Identity | Every device carries a DTC OUID (UUIDv7, minted once, never changed). See OUID Standard. | endpoint/device/configuration/set-device-ouid.ps1 |
| Local admin | dtcadmin, 16+ random characters, rotated by LAPS; current and four previous passwords kept in secure NinjaOne fields. See Client Credential Administration Standard. | identity/local-identity/configuration/laps.ps1 |
| Disk encryption | BitLocker on the OS drive, TPM + 48-digit recovery password (created before encryption starts), XtsAes256. Recovery passwords escrowed to AD and/or Entra ID by join state. Suspended or unprotected volumes alert. | security/bitlocker/configuration/bitlocker-enable.ps1, bitlocker-resume.ps1; conditions bitlocker-suspended, bitlocker-unprotected, bitlocker-no-recovery-password; DC side identity/active-directory/configuration/ad-bitlocker-escrow-read-delegate.ps1 |
| EDR | Blackpoint Unified Agent v3 installed and healthy (legacy SNAP agent on older sites until migrated). | security/blackpoint/configuration/blackpoint-agent-v3-provision.ps1 |
| Anti-malware | Microsoft Defender Antivirus present, real-time protection always on, per-client exclusions applied. Core Isolation (HVCI) is disabled by default — without disabling Hyper-V/VBS — and re-enabled per device by unchecking defenderDisableCoreIsolation. | security/defender/configuration/defender-provision.ps1 |
| DNS filtering | On DNSFilter sites, laptops get the DNSFilter Roaming Client automatically; desktops only when flagged. See DHCP & DNS — Roaming Endpoints. | security/dnsfilter/configuration/dnsfilter-provision.ps1 |
| Remote access | Cloudflare WARP for remote workers, version-converged. See Remote Access. | network/cloudflare-warp/configuration/cloudflare-warp-provision.ps1 |
| Unapproved remote tools | RMM and remote-access tools not on the approved list are detected and removed (removal is dry-run unless Execute is set). Allowlist beats blocklist, per org/location/device. | security/shadow-it/inventory/shadow-it-detect.ps1, security/shadow-it/configuration/shadow-it-remove.ps1 |
| Downloads execution | AppLocker blocks executables launched from user download locations (audit, then enforce, per client). | security/applocker/inventory/applocker-download-block-inventory.ps1, …/remediation/applocker-download-block-remediate.ps1 |
| Firmware | Secure Boot on wherever the firmware allows it (UEFI); Wake-on-LAN enabled; Deep Sleep disabled. Secure Boot off on a UEFI machine alerts. Dell today; other OEMs pass through untouched. | endpoint/oem/configuration/oem-firmware-configure.ps1; security/secure-boot/* |
| OEM tooling & drivers | Dell Command | Update and Dell Command | Configure installed at the approved version; firmware and driver updates applied through them. | endpoint/oem/configuration/oem-update-tool-provision.ps1, endpoint/oem/remediation/oem-firmware-driver-update.ps1 |
| Image backup | Workstations confirmed for backup service get the NinjaOne image plan. See Backup & Data Protection Standards. | NinjaOne backup plan (configuration standard); backup/ninjaone-backup/configuration/lockhart-throttle.ps1 caps the backup agent's CPU |
| Recovery | Windows Quick Machine Recovery is always on. | See Windows Endpoints |
| Hygiene | Duplicate local profiles alert and can be removed; pending reboots are reconciled after boot; script logs pruned. | endpoint/user-profiles/*, maintenance/remediation/reboot-pending-reconcile.ps1, maintenance/remediation/clear-old-logs.ps1 |
Hardware
What a workstation must be before we buy it is in the Endpoint Hardware Purchasing Standard. Vendor-bundled security software is removed from the quote, not left uninstalled.
Not yet scripted
Anything we expect on a workstation that no script converges yet belongs here until it is automated, so the gap is visible rather than assumed covered. Known today: Lenovo and HP firmware/driver lanes (tooling exists, disabled — nothing drives it).
Related
- Security Standards — the endpoint security stack and why
- Windows In-Place Upgrade — procedure (Endpoint Operations)
- Automation Scripts — Source of Truth (ninja-one-automation)