The full Aegis surface

Every control you can turn on — MFA, MDM, kiosk, DLP, activity, escrow. Pick a tab.

Windows logon MFA

Credential Provider after password. Push to mobile, TOTP, verified push codes, offline packs when travel mode is granted.

  • Push / TOTP / offline codes
  • Hello coexistence (policy-aware)
  • IP / geo deny ranges
  • Kill-switch on push deny
  • Verify TrustScore gate (optional)
MFA phone approve at Windows logon
Phone approve

Phone approve

Push challenge with optional verification code.

Method choose

Method choice

Push or authenticator — clear UX.

Windows Hello

Hello coexistence

Policy-aware — we do not fake Hello PIN remote reset.

Push flow

Push flow

Agent + API + mobile notification path.

Success

Approved logon

Session continues only after MFA success.

Biometric

Biometric assist

Where OS allows — honest about limits.

MDM control plane

Groups → Control Policies → Assignment → Exclude → Device status. Restrictive-OR merge. Agent reconciles about every 20 seconds.

  • Multi-group targeting
  • Priority merge + excludes win
  • Observed state / drift
  • Scope admins & conflict rules
  • Profiles presets (one-click)
Fleet MDM operations
Fleet risk

Fleet Risk

Live for + attack signals every 30s.

Ops

Command Center

Capability map of the full IBES surface.

Profiles

Profiles

AppKiosk, VdiOnly, LockedDesktop, AirGap.

Evidence

Evidence

Audit trail for MFA and MDM actions.

Endpoint lockdown

USB deny, shell restrictions, Store block, registry tools, firewall enforce, AppLocker whitelist Audit→Enforce.

  • USB scope: All / Devices / Users
  • Control Panel / Settings / CMD / PowerShell
  • Protected allowlist paths always kept
  • Microsoft Store remove policy
USB deny
USB

USB deny

Removable storage blocked by policy.

Shell

Shell lockdown

Hardened Explorer / Run / tools.

AppLocker

AppLocker whitelist

Audit then Enforce with protected OS paths.

Browser & channel DLP

URL allowlist mode, block extensions / downloads / uploads, clipboard and print channel blocks. Not CNIC/PAN content sniff — honest channel DLP.

Browser lockdown

AppKiosk & VDI thin client

Intune Assigned Access breaks Temp→mstsc apps (V2Cloud). Aegis AppKiosk clears Assigned Access, keeps Temp writable, allows mstsc, auto-starts Win32 path. VdiThinClient hides drives and clips redirect.

Full kiosk page

Kiosk VDI
Thin client

Thin client

Local save paths restricted.

Devices

Device modes

LockedDesktop · SingleApp · AppKiosk · VDI.

Cross platform

Mac soft controls

FileVault / media soft kiosk (honest scope).

Presence + Social Media watch

Daily active / idle / locked minutes. Curated social catalog: Facebook, Instagram, X, TikTok, YouTube, LinkedIn, Reddit, WhatsApp, Discord, and more. Not keylogging.

Activity page

Social activity

Lifecycle & stolen device

Lost Mode (hostname confirm), restart/shutdown, force password change, Windows Update ring, software inventory + upgrade, GeoIP last city — not GPS theatre.

Lifecycle
Lock

Remote lock

Command queue → agent LockWorkStation.

Lost Mode

Lost Mode

Lock + crypto wipe honesty + SyncNow.

Alerts

Admin alerts

Tamper, Lost Mode, encryption drop emails.

Encryption, escrow, compliance

Require BitLocker, escrow recovery passwords, hostname-confirm reveal, drive inventory, uninstall / tamper key.

Security model

Encryption

Complete image index

All product visuals used across Aegis — one place to scan coverage.

Device fleet

Windows endpoints under Aegis.

Windows logon

Credential provider surface.

macOS

Soft controls where supported.

Self-hosted

On-prem / Lightsail friendly.

Enterprise rollout

Pilot → Enforce path.

Pilot guide

Start with Audit whitelist.

Map features to your groups.

aegis.securegentools.com — talk to SecureGen about a pilot OU.

Get started