Managed Device Security & Compliance
Keep business computers encrypted, monitored, updated and managed against a consistent security baseline—wherever your users work.
Business Computers Need to Be Managed, Not Just Protected
Antivirus is only one part of device security. Business computers also need consistent configuration, encryption, patching, compliance checks, monitoring and a reliable way for support teams to manage them.
As part of the KES Business User Pack, each included computer is enrolled into the KES managed-device service and configured against a standard security baseline. This helps reduce variation between devices and gives KES greater visibility when something falls outside the expected standard.
A Consistent Security Baseline for Every Managed Computer
Device Enrolment
Included computers are enrolled into Microsoft Intune and the KES remote-management platform so they can be configured, monitored and supported consistently.
BitLocker Encryption
Supported Windows computers are protected with BitLocker disk encryption to reduce the risk of business data being exposed if a device is lost or stolen.
Secure Boot
Compatible devices are required to use Secure Boot, helping protect the computer from unauthorised software loading before Windows starts.
Firewall and Antivirus Compliance
Managed computers are checked to confirm that firewall, antivirus and antispyware protection are active.
Patch Management
Windows security and quality updates are approved and installed through a controlled patch-management schedule.
Compliance Monitoring
Devices are assessed against the KES security baseline so that non-compliant computers can be identified and investigated.
Designed Around How People Actually Work
Each standard Business User Pack includes management and protection for up to two computers assigned to the same named user.
Main Computer
The user’s principal desktop or laptop is enrolled, monitored, protected and configured for their Microsoft 365 services.
Second Computer Where Required
Where the same user genuinely requires another desktop or laptop, the second computer can receive the same managed-device service.
The two-device entitlement applies to computers assigned to the same named user. Shared computers, reception devices, workshop PCs, spare computers and servers are handled separately.
Protection That Continues in the Background
Real-Time Endpoint Protection
Managed computers receive antivirus, endpoint detection and response, and ransomware-behaviour monitoring.
Automated Containment
Suspicious processes may be stopped automatically and affected devices can be isolated from the network to help prevent a threat spreading.
Security Alert Review
Relevant endpoint-security events are raised to KES for review and further investigation where required.
Tamper Protection
Security controls are protected against unauthorised changes or attempts to disable them.
Secure Remote Support
Authorised KES technicians can securely access managed devices to investigate faults and provide remote support.
Hardware and Software Inventory
KES maintains visibility of managed device hardware and installed software to support troubleshooting and lifecycle planning.
Updates Are Managed Through a Defined Schedule
Standard Windows security and quality updates are normally approved after an initial release period and deployed twice each week.
This gives updates time to settle before wider deployment while still maintaining a regular security-update cycle.
Computers are not normally restarted automatically after patching. Users receive reminders when a restart is required and should restart promptly so updates can complete.
Our standard patching approach includes:
- Twice-weekly installation windows
- Controlled approval of standard updates
- Monitoring of patch status and failures
- User restart reminders
- Separate assessment of major feature upgrades
- Exclusion of preview and prerelease updates
Protected Data with Centrally Managed Recovery
BitLocker helps protect data stored on supported Windows computers by encrypting the device drive.
TPM-Based Protection
Compatible devices use their Trusted Platform Module to protect the encryption keys without requiring a separate USB startup key.
Centrally Stored Recovery Information
Recovery information is stored centrally so KES can assist if Windows requests a BitLocker recovery password.
Compliance Visibility
KES can identify whether supported devices are reporting as encrypted and compliant with the required baseline.
Phones and Tablets Can Be Managed Where Required
Mobile phones and tablets are not included within the standard two-computer entitlement. Where appropriate, they can be enrolled into Microsoft Intune under an agreed mobile-device-management scope.
Mobile enrolment does not automatically include support for personal applications, mobile contracts, device hardware or every aspect of a personally owned device.
Explore the Other Layers of Protection and Support
Microsoft 365 Business Premium
Business email, productivity applications, identity protection and device-management capabilities.
Learn more →Endpoint Security and EDR
Real-time antivirus, behavioural detection and ransomware containment for managed computers.
Learn more →Remote Monitoring and Management
Proactive visibility, remote maintenance and secure support access for business computers.
Learn more →Endpoint Backup
Backup of agreed user-profile data on both included computers.
Learn more →Included IT Support
Pooled remote support and routine administration for users and managed devices.
Learn more →Business User Pack Onboarding
A structured process for bringing users, devices, security and backups under management.
Learn more →Do You Know Which Computers Are Secure and Compliant?
We can review your current device estate, identify gaps in encryption, patching and management, and show you how the Business User Pack brings those controls together.
Managed Device Security and Compliance FAQs
How many computers are included per user?
The Business User Pack includes management and security for up to two agreed business computers per licensed user.
What security is installed on managed computers?
Managed computers receive the agreed KES monitoring, antivirus, endpoint detection and response, patching, backup and management tools included within the Business User Pack.
Does KES encrypt business computers?
Where the computer and operating system support it, KES can configure and monitor device encryption as part of the agreed security baseline.
Does every computer have to meet the same security standard?
Managed computers are brought under a consistent baseline covering supported operating systems, security software, updates, encryption and monitoring. Exceptions are reviewed individually.
Are personally owned computers included?
Personally owned or unmanaged devices are not automatically included. KES will review whether a device is suitable for business use and whether it can safely be brought under management.
What happens if a computer is too old or unsupported?
Computers that cannot run a supported operating system or meet the required security baseline may need to be upgraded or replaced before they can be fully managed.
Does device management let KES see employees’ personal files?
No. The management tools are used to monitor security, device health, updates and agreed technical information. They are not intended to inspect ordinary personal documents or monitor employee activity.
Your Title Goes Here
Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.