MANAGED DEVICES, CONSISTENTLY PROTECTED

Managed Device Security & Compliance

Keep business computers encrypted, monitored, updated and managed against a consistent security baseline—wherever your users work.

MORE THAN ANTIVIRUS

Business Computers Need to Be Managed, Not Just Protected

Antivirus is only one part of device security. Business computers also need consistent configuration, encryption, patching, compliance checks, monitoring and a reliable way for support teams to manage them.

As part of the KES Business User Pack, each included computer is enrolled into the KES managed-device service and configured against a standard security baseline. This helps reduce variation between devices and gives KES greater visibility when something falls outside the expected standard.

WHAT IS INCLUDED

A Consistent Security Baseline for Every Managed Computer

Device Enrolment

Included computers are enrolled into Microsoft Intune and the KES remote-management platform so they can be configured, monitored and supported consistently.

BitLocker Encryption

Supported Windows computers are protected with BitLocker disk encryption to reduce the risk of business data being exposed if a device is lost or stolen.

Secure Boot

Compatible devices are required to use Secure Boot, helping protect the computer from unauthorised software loading before Windows starts.

Firewall and Antivirus Compliance

Managed computers are checked to confirm that firewall, antivirus and antispyware protection are active.

Patch Management

Windows security and quality updates are approved and installed through a controlled patch-management schedule.

Compliance Monitoring

Devices are assessed against the KES security baseline so that non-compliant computers can be identified and investigated.

TWO COMPUTERS PER USER

Designed Around How People Actually Work

Each standard Business User Pack includes management and protection for up to two computers assigned to the same named user.

Main Computer

The user’s principal desktop or laptop is enrolled, monitored, protected and configured for their Microsoft 365 services.

Second Computer Where Required

Where the same user genuinely requires another desktop or laptop, the second computer can receive the same managed-device service.

The two-device entitlement applies to computers assigned to the same named user. Shared computers, reception devices, workshop PCs, spare computers and servers are handled separately.

SECURITY CONTROLS

Protection That Continues in the Background

Real-Time Endpoint Protection

Managed computers receive antivirus, endpoint detection and response, and ransomware-behaviour monitoring.

Automated Containment

Suspicious processes may be stopped automatically and affected devices can be isolated from the network to help prevent a threat spreading.

Security Alert Review

Relevant endpoint-security events are raised to KES for review and further investigation where required.

Tamper Protection

Security controls are protected against unauthorised changes or attempts to disable them.

Secure Remote Support

Authorised KES technicians can securely access managed devices to investigate faults and provide remote support.

Hardware and Software Inventory

KES maintains visibility of managed device hardware and installed software to support troubleshooting and lifecycle planning.

CONTROLLED PATCHING

Updates Are Managed Through a Defined Schedule

Standard Windows security and quality updates are normally approved after an initial release period and deployed twice each week.

This gives updates time to settle before wider deployment while still maintaining a regular security-update cycle.

Computers are not normally restarted automatically after patching. Users receive reminders when a restart is required and should restart promptly so updates can complete.

Our standard patching approach includes:

  • Twice-weekly installation windows
  • Controlled approval of standard updates
  • Monitoring of patch status and failures
  • User restart reminders
  • Separate assessment of major feature upgrades
  • Exclusion of preview and prerelease updates
ENCRYPTION AND RECOVERY

Protected Data with Centrally Managed Recovery

BitLocker helps protect data stored on supported Windows computers by encrypting the device drive.

TPM-Based Protection

Compatible devices use their Trusted Platform Module to protect the encryption keys without requiring a separate USB startup key.

Centrally Stored Recovery Information

Recovery information is stored centrally so KES can assist if Windows requests a BitLocker recovery password.

Compliance Visibility

KES can identify whether supported devices are reporting as encrypted and compliant with the required baseline.

MOBILE DEVICES

Phones and Tablets Can Be Managed Where Required

Mobile phones and tablets are not included within the standard two-computer entitlement. Where appropriate, they can be enrolled into Microsoft Intune under an agreed mobile-device-management scope.

Mobile enrolment does not automatically include support for personal applications, mobile contracts, device hardware or every aspect of a personally owned device.

BRING DEVICES UNDER CONTROL

Do You Know Which Computers Are Secure and Compliant?

We can review your current device estate, identify gaps in encryption, patching and management, and show you how the Business User Pack brings those controls together.

FREQUENTLY ASKED QUESTIONS

Managed Device Security and Compliance FAQs

How many computers are included per user?

The Business User Pack includes management and security for up to two agreed business computers per licensed user.

What security is installed on managed computers?

Managed computers receive the agreed KES monitoring, antivirus, endpoint detection and response, patching, backup and management tools included within the Business User Pack.

Does KES encrypt business computers?

Where the computer and operating system support it, KES can configure and monitor device encryption as part of the agreed security baseline.

Does every computer have to meet the same security standard?

Managed computers are brought under a consistent baseline covering supported operating systems, security software, updates, encryption and monitoring. Exceptions are reviewed individually.

Are personally owned computers included?

Personally owned or unmanaged devices are not automatically included. KES will review whether a device is suitable for business use and whether it can safely be brought under management.

What happens if a computer is too old or unsupported?

Computers that cannot run a supported operating system or meet the required security baseline may need to be upgraded or replaced before they can be fully managed.

Does device management let KES see employees’ personal files?

No. The management tools are used to monitor security, device health, updates and agreed technical information. They are not intended to inspect ordinary personal documents or monitor employee activity.

Your Title Goes Here

Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.