Aegis

Who signed in decides what the PC can do.

Lock-screen MFA. Live policy on the desktop. One Windows agent from SecureGen Tools.

Phone approve for Windows logon
Approve at logon
Fleet operations console
Fleet under policy
VDI kiosk desk
Kiosk that still opens RDP
Activity and presence wall
Who was active — and where

The problem

A password is a shared secret. Aegis makes the human show up.

Stolen credentials open the shell. Soft MDM waits for the next reboot. Assigned Access breaks the cloud RDP apps your desks actually use. Aegis closes those gaps on one agent.

MFA phone approve next to Windows lock screen
01 — Verify

No shell until someone says yes.

After the password, Aegis sits in the Windows credential provider. Push to phone. Authenticator. Offline packs for travel. Deny the push — the session never starts.

Verify deep dive →
Security operations fleet view
02 — MDM

Policy that sticks in seconds, not after reboot.

Groups, priorities, excludes. USB off. AppLocker on. Browser channels locked. The agent reconciles about every twenty seconds so the desk matches the console.

MDM deep dive →
Locked-down VDI thin client desk
03 — AppKiosk

Lock the desk. Keep cloud RDP alive.

Intune Assigned Access cages break apps that write a Temp .rdp and launch mstsc. AppKiosk clears that cage: soft locked desktop, writable Temp, auto-start your V2Cloud-style client.

Kiosk & VDI →
Activity and social usage visualization
04 — Activity

Active. Idle. Locked. Plus where the browser went.

Daily presence from the agent. Social Media watch estimates time on Facebook, Instagram, X, YouTube, LinkedIn and more from browser history — honest estimates, not keylogging.

Activity & Social →

Full surface

Everything Aegis covers

Windows logon MFAPush · TOTP · offline packs Desired-state MDMGroups · merge · drift USB denyAll · device · user scope AppKiosk + VDITemp→RDP · thin client Browser & DLPUpload · clipboard · print Presence & SocialActive · idle · site minutes Escrow & tamperBitLocker · uninstall key Lost ModeStolen device playbook

Security model

Encryption escrow. Tamper key. Labels you can trust.

BitLocker recovery when you need it. Uninstall protection so users cannot quietly remove the agent. Console labels say ON, LIVE, READY, or OFF — same truth for pilots and audits.

Read the security model
Encrypted device on executive desk

Aegis

Put it on a real Windows desk this week.

SecureGen Tools runs the pilot with you — Verify, MDM, or AppKiosk first. You choose the desk that hurts most.