Every control you can turn on — MFA, MDM, kiosk, DLP, activity, escrow. Pick a tab.
Credential Provider after password. Push to mobile, TOTP, verified push codes, offline packs when travel mode is granted.


Push challenge with optional verification code.

Push or authenticator — clear UX.

Policy-aware — we do not fake Hello PIN remote reset.

Agent + API + mobile notification path.

Session continues only after MFA success.

Where OS allows — honest about limits.
Groups → Control Policies → Assignment → Exclude → Device status. Restrictive-OR merge. Agent reconciles about every 20 seconds.


Live for + attack signals every 30s.

Capability map of the full IBES surface.

AppKiosk, VdiOnly, LockedDesktop, AirGap.

Audit trail for MFA and MDM actions.
USB deny, shell restrictions, Store block, registry tools, firewall enforce, AppLocker whitelist Audit→Enforce.


Removable storage blocked by policy.

Hardened Explorer / Run / tools.

Audit then Enforce with protected OS paths.
URL allowlist mode, block extensions / downloads / uploads, clipboard and print channel blocks. Not CNIC/PAN content sniff — honest channel DLP.

Intune Assigned Access breaks Temp→mstsc apps (V2Cloud). Aegis AppKiosk clears Assigned Access, keeps Temp writable, allows mstsc, auto-starts Win32 path. VdiThinClient hides drives and clips redirect.


Local save paths restricted.

LockedDesktop · SingleApp · AppKiosk · VDI.

FileVault / media soft kiosk (honest scope).
Daily active / idle / locked minutes. Curated social catalog: Facebook, Instagram, X, TikTok, YouTube, LinkedIn, Reddit, WhatsApp, Discord, and more. Not keylogging.

Lost Mode (hostname confirm), restart/shutdown, force password change, Windows Update ring, software inventory + upgrade, GeoIP last city — not GPS theatre.


Command queue → agent LockWorkStation.

Lock + crypto wipe honesty + SyncNow.

Tamper, Lost Mode, encryption drop emails.
Require BitLocker, escrow recovery passwords, hostname-confirm reveal, drive inventory, uninstall / tamper key.

All product visuals used across Aegis — one place to scan coverage.

Windows endpoints under Aegis.

Credential provider surface.

Soft controls where supported.

On-prem / Lightsail friendly.

Pilot → Enforce path.

Start with Audit whitelist.
aegis.securegentools.com — talk to SecureGen about a pilot OU.
Get started