Windows devices
Oneleet manages company-owned Windows devices through the Oneleet Agent — a lightweight background service that starts reporting within minutes of installation. Admins get continuous visibility into each device’s security posture, can enforce security settings across the fleet, and can take action remotely when a device is lost, being offboarded, or needs attention.
There are no certificates, vendor portals, or enrollment infrastructure to set up first: install the agent, have the employee sign in with their work email, and the device appears in the Oneleet Dashboard.
What Oneleet can do today
Section titled “What Oneleet can do today”Continuous security checks
Section titled “Continuous security checks”The agent checks each device’s security posture every few minutes and reports results to the device view, where they roll up into the device’s compliance status:
- Disk encryption — BitLocker is enabled and the system drive is fully encrypted;
- Firewall — Windows Firewall is enabled across all network profiles (domain, private, and public);
- Screen lock — device locking is enabled;
- Local user accounts — which accounts exist, which have administrator rights, and which are disabled;
- Device inventory — hardware model and serial number, OS version and build, and storage capacity.
Organizations using Oneleet MDM also receive extended inventory such as battery health. See Data collection for the full list of what the agent reports.
Because these checks feed Oneleet’s compliance monitors directly, a failing device shows up as an actionable gap in your compliance program — not just a row in a device list.
One-click remediation
Section titled “One-click remediation”When a check fails, admins can often fix it remotely instead of walking the employee through system settings:
- enable BitLocker on the system drive (XTS-AES-256 with a TPM protector);
- turn Windows Firewall back on for every network profile;
- re-enable screen locking.
The fix is applied by the agent on the device and the check re-reports automatically. Enabling BitLocker remotely requires a TPM and a Pro, Enterprise, or Education edition of Windows.
Device configuration policies
Section titled “Device configuration policies”Admins can enforce Windows security settings fleet-wide from the Configuration Profiles tab, with per-device overrides when a specific machine needs different values:
- Screen lock — inactivity timeout, require password on wake, and the grace period before the password is required;
- Removable storage — block removable media devices;
- Credential protection — run the Windows credential subsystem (LSASS) as a protected process, hardening the device against credential-theft tooling.
A CIS-aligned secure-defaults baseline can be applied in one click as a starting point. Policies reach online devices within about 15 minutes, and the agent continuously re-checks them afterward: if a setting drifts from policy, the agent restores it automatically and reports the correction back to Oneleet.
Corrections appear in the device activity log as Windows registry setting corrected, in each workspace whose policy sets that value. Open one to see the registry value the agent changed in the Result section. If something on the device keeps changing a setting back, the log lists that setting’s correction about once an hour instead of on every check. A correction the agent makes from a policy you just replaced, before it picks up the new one, isn’t listed.
The agent only applies configuration policies carrying a valid Oneleet signature for that device, and it checks that signature when it downloads the policy. Policies refresh automatically while the device is online. If a refresh fails or returns something the agent can’t verify, the device keeps enforcing the last policy it accepted rather than falling back to an unverified one.
Device configuration policies are part of Oneleet MDM. Contact Oneleet to enable them for your organization.
Updates to Oneleet’s required agent configuration are included in the same automatic refresh. Tenant policies and device overrides keep their precedence; changes to the recommended secure-defaults baseline don’t overwrite settings you’ve already chosen.
Remote wipe
Section titled “Remote wipe”Remote wipe performs a full factory reset of the Windows device, removing company data and user profiles. This is a destructive action and should be used only when the device should no longer keep company data.
Use this when:
- a device is lost or stolen and should be treated as unrecoverable;
- an employee has left the company and the device needs to be reset;
- a device is being prepared for reassignment, return, or disposal.
Restart
Section titled “Restart”Restart lets an admin reboot a Windows device remotely. The signed-in user sees a warning before the restart so they can save their work.
Use this when:
- a user is having an issue and a restart is the next troubleshooting step;
- a device needs to restart after configuration changes;
- the user cannot easily restart the device themselves.
Manage local user accounts
Section titled “Manage local user accounts”Admins can manage a device’s local Windows accounts remotely: create an account (optionally with administrator rights), disable or re-enable it, reset its password, or delete it.
Use this when:
- offboarding an employee and their local account should be disabled immediately;
- reclaiming a device and IT needs its own administrator account on it;
- a user is locked out and needs a password reset.
Install applications
Section titled “Install applications”Upload installers up to 500 MB. The file extension must match the installer format.
Admins can push software to a Windows device from the Oneleet Dashboard. Upload a .msi or .exe installer to the Applications tab on the Devices page, give it a name and version, and set the options the installer needs to run unattended: Windows Installer properties for an .msi, command-line arguments such as /S for an .exe, and an optional timeout. Then open the device, go to its Apps tab, and choose Install application to pick an application from the catalog.
Use this when:
- a new device needs the company’s standard tools;
- a security tool has to be rolled out to a device;
- a user needs an application they can’t install themselves.
Installing applications requires Oneleet ESPM and Oneleet MDM to be enabled for your workspace. The device must be managed and run Oneleet Agent version 2.4.0 or later. The agent downloads the installer over a time-limited signed link, verifies its checksum, and runs it with the options you set. Uploading a file your workspace already has reuses the existing catalog entry. While an install of an application is pending or in progress on a device, another install of the same application on that device is rejected.
Every action above is recorded in the device activity log, and the agent keeps itself up to date after installation — see the Oneleet MDM introduction for these shared capabilities.
Choose which devices are managed
Section titled “Choose which devices are managed”Use MDM enrollment rules to include devices by people group or make device-specific exceptions. Excluding a BYOD device keeps security monitoring active while preventing remote management and automatic fixes.
After you exclude a device, the agent stops enforcing your organization’s configuration policies after its next successful policy download from Oneleet, which happens within about 15 minutes while the device is online. Until then, it keeps re-applying the policies it already has, and a device that stays offline or can’t reach Oneleet may keep enforcing them indefinitely. Settings the agent already applied stay in place.
On a device that’s also linked to another Oneleet workspace, per-device overrides apply only while every linked workspace manages the device.
Getting started
Section titled “Getting started”- Have the employee open the Oneleet Portal and download the Oneleet Agent for Windows from the Devices tab.
- Run the installer (administrator rights are required) and sign in with the work email address.
- The device appears in the Oneleet Dashboard under Devices, with security checks reporting within a few minutes and configured device policies applying automatically when the device is included in MDM.
The agent supports Windows 10 and later (x64). See Setup for detailed install and uninstall steps.
Offboarding a device
Section titled “Offboarding a device”When a Windows device leaves service or changes hands:
- disable or reset the departing employee’s local account if the device is being reclaimed;
- use remote wipe if the device is being reset, returned, or disposed of;
- archive the device or mark it out of scope in the dashboard once it is no longer part of your fleet.
If you are unsure whether a device should be wiped or removed from management, contact Oneleet support before taking action.