Configuration guide: Operating systems - Stability, security, and compliance
Introduction
This library pack will help you monitor and manage various operating systems to ensure their stability, compliance, and performance. This page will guide you through the structure of the content.
Content list and dependency
This library pack contains the following content and dependencies:
OS Stability, Compliance, and Security
Helps to monitor and manage various operating systems to ensure their stability, compliance, and performance
Get XProtect status
Provides information about the status of the macOS XProtect (macOS built-in antivirus software) automatic update setting on macOS devices.
Required to populate specific dashboard widgets.
Get firewall options
Provides information about the status of the macOS firewall on macOS devices.
Required to populate specific dashboard widgets.
Get BitLocker information
Returns basic information on BitLocker protection status.
Required to populate specific dashboard widgets.
Get encryption information
Gets an APFS file system disk encryption and decryption information in addition to checking whether FileVault is enabled or not.
Required to populate specific dashboard widgets.
Get macOS updates and restart information
Gets information about macOS devices - the number of days since the last restart, whether there are pending updates, a list of names of pending updates, and others.
Required to populate specific dashboard widgets.
Test pending reboot
Checks if the device is waiting to reboot for an update.
Required to populate specific dashboard widgets.
Set firewall options
Configures firewall settings under System Preferences - Security & Privacy - Firewall on macOS devices.
Set XProtect status
Configures the XProtect status under System Preferences - Software Update - Advanced on macOS devices.
Install Windows update
Installs a ‘.msu’ patch on Windows devices.
Invoke Windows update
Restarts Windows Update and BITS services on Windows devices and forces the device to check for updates.
Set auto updates
Configures additional macOS automatic update settings under System Preferences - Software Update - Advanced on macOS devices.
Get Windows Feature update diagnosis
Executes Microsoft tool SetupDiag.exe, that process Windows Feature update log files and returns a list of possible failure reasons or upgrade confirmation.
Enable BitLocker Encryption
Enables BitLocker encryption on the device's system drive.
OS targeted quality update version
Defines the target quality update versions of Windows and macOS operating systems.
Required to populate specific dashboard widgets.
OS supported version
Determines which Windows and macOS operating system versions, editions, and builds are supported.
Required to populate specific dashboard widgets.
OS targeted feature update version
Defines the target feature update versions of Windows operating systems. Typically, this custom field requires version updates every month.
Required to populate specific dashboard widgets.
Configuration guide
To effectively use this library pack, the content must be installed and configured appropriately. Below are some suggested steps to install and configure the content properly before use.
Step 1) Install library pack content
Go to the Nexthink Library and install all required content.
Step 2) Configure remote actions
Navigate to the manage remote action administration page to review and edit your remote actions.
We recommend the following configurations for these remote actions:
Get XProtect status
Scheduled, daily
Get firewall options
Scheduled, daily
Get BitLocker information
Scheduled, daily
Get encryption information
Scheduled, daily
Get macOS updates and restart information
Scheduled, daily
Test pending reboot
Scheduled, daily
Set firewall options
Manual, can be triggered on multiple devices
Enable or disable macOS firewall status
Allow or refuse built-in software to receive incoming connections
Allow or refuse downloaded signed software to provide services accessed form the network
Allow or reject ICMP connections to the computer
Set XProtect status
Manual, can be triggered on multiple devices
Enable or disable macOS XProtect status on the device
Install Windows update
Manual, can be triggered on multiple devices
Provide URL or UNC path to the update (.msu) file
Invoke Windows update
Manual, can be triggered on multiple devices
Set auto updates
Manual, can be triggered on multiple devices
Enable or disable macOS 'Check for updates' setting.
Enable or disable macOS 'Download new updates when available' setting.
Enable or disable 'Install macOS Updates' setting.
Enable or disable 'Install app updates from the App store' setting.
Get Windows Feature update diagnosis
Manual, can be triggered on multiple devices
Configure the absolute path to the location of SetupDiag.exe tool on the target device. For example "C:\temp\SetupDiag.exe"
Enable BitLocker Encryption
Manual, can be triggered on multiple devices
Enable or disable the 'Enforce AD backup' setting.
Define the drive encryption type used by BitLocker.
Define the encryption method used by BitLocker: 'Aes128', 'Aes256', 'XtsAes128' or 'XtsAes256'
Step 3) Configure custom fields
Navigate to the manage custom fields administration page to review and edit your custom fields.
Operating system versions in the custom fields below are subject to change due to regular patches released by vendors and Apple and Microsoft support policies.
Typically, these versions need to be updated in the custom fields once a month to ensure you have the most current patch versions.
We recommend the following configurations for these custom fields:
OS targeted quality update version
os_targeted_quality_update_version
macos_sonoma
device
macos_ventura
device
macos_monterey
device
windows_10_quality_update
device
windows_11_quality_update
device
OS targeted feature update version
os_targeted_feature_update_version
windows_10_feature_update
device
windows_11_feature_update
device
OS supported version
os_supported_version
macos_unsupported_version
device
macos_supported_version
device
windows_unsupported_version
device
windows_supported_version
device
Usage guide
Your content is now configured and ready to be used. For usage overview and recommendations, you can visit the usage guide:
Usage guide: Operating systems - Stability, security, and compliance
Last updated