Continuous monitoring

Windows Agent

A lightweight agent that checks a Windows machine's security posture every hour: BitLocker, Secure Boot, antivirus health, and more. Only pass/fail results leave the device, scored in your Monitoring Hub as Healthy, At Risk, or Critical.

Posture checks on the device

The agent evaluates a baseline security-posture pack locally (osquery-based) about once an hour and posts only the results — no file contents or browsing data leave the machine.

Scoped device key

Runs on a Device Monitor key that can only submit device posture scans — it cannot run other tools or read any account data. Revoke the key and the agent stops.

Central visibility

Every scan appears in the Monitoring Hub with a Healthy / At Risk / Critical verdict and a full device report — filter by the Device monitor type to see your fleet.

What it checks today

The current baseline posture pack for Windows. A failed check's severity drives the report verdict: any high or critical failure marks the device Critical; lower-severity failures mark it At Risk; all passing marks it Healthy.Info checks are inventories and facts rather than pass/fail controls — they are reported for context and never count as failures.

  • Disk encryption (BitLocker) enabled on system drivecritical
  • UEFI Secure Boot enabledhigh
  • Antivirus enabled with up-to-date signatureshigh
  • User Account Control (UAC) enabledhigh
  • Remote Desktop (RDP) disabledhigh
  • SMBv1 protocol not enabledhigh
  • Automatic logon disabled (no stored logon password)high
  • Known EDR/AV agent runninghigh
  • All BitLocker-capable drives protectedhigh
  • Volume Shadow Copy service not disabledhigh
  • Windows Firewall reported healthy by Security Centermedium
  • Automatic updates reported healthy by Security Centermedium
  • No non-default SMB file shares exposedmedium
  • Unsigned or untrusted startup itemsmedium
  • Built-in Guest account disabledmedium
  • Backup mechanism present (backup agent or OneDrive folder backup)medium
  • Local password policy requires length >= 8 and complexitylow
  • Removable storage writes blocked by policyinfo
  • Startup items (inventory)info
  • Local administrator accounts (inventory)info
  • Device managed by MDMinfo
  • Consumer cloud file-sync clients installed (inventory)info
  • Remote-access and tunneling tools installed (inventory)info

Set up in four steps

  1. 1

    Create a Device Monitor key

    In the Monitoring Hub, create a new monitor with the type Device Monitor and set its seat assignment to the seated member who uses this machine. Copy the key when it's shown — it appears only once.

  2. 2

    Download the installer

    Use the download button above to get the signed .msi installer (EV code-signing certificate). SmartScreen may still flag a fresh release while the certificate builds reputation — verify the download against the SHA-256 checksum shown next to the button, then click More info → Run anyway if warned.

  3. 3

    Install and enroll with the key

    Run the installer, then enroll the agent from an elevated (Administrator) PowerShell. It prompts for the device key from step 1:

    PS> & "C:\Program Files\Blue Lantern Device Agent\bldeviceagentctl.ps1" enroll
    Device key (apk_bls_...):

    Paste the key at the prompt (input is hidden). Enrollment stores the key with a SYSTEM/Administrators-only ACL and registers the agent as a scheduled task that starts with Windows.

  4. 4

    Watch the reports come in

    The agent scans about once an hour. Each report shows up in the Monitoring Hub under the Device monitor type, with the hostname as the target and a click-through to the full device posture report.

Seats and billing

Device monitoring is seat-only. Assign the monitor to a seated member of your organization. See pricing.