Windows devices
Oneleet manages company-owned Windows devices through the Oneleet Agent — a lightweight background service that starts reporting within minutes of installation. Admins get continuous visibility into each device’s security posture, can enforce security settings across the fleet, and can take action remotely when a device is lost, being offboarded, or needs attention.
There are no certificates, vendor portals, or enrollment infrastructure to set up first: install the agent, have the employee sign in with their work email, and the device appears in the Oneleet Dashboard.
What Oneleet can do today
Section titled “What Oneleet can do today”Continuous security checks
Section titled “Continuous security checks”The agent checks each device’s security posture every few minutes and reports results to the device view, where they roll up into the device’s compliance status:
- Disk encryption — BitLocker is enabled and the system drive is fully encrypted;
- Firewall — Windows Firewall is enabled across all network profiles (domain, private, and public);
- Screen lock — device locking is enabled;
- Local user accounts — which accounts exist, which have administrator rights, and which are disabled;
- Device inventory — hardware model and serial number, OS version and build, and storage capacity.
Organizations using Oneleet MDM also receive extended inventory such as battery health. See Data collection for the full list of what the agent reports.
Because these checks feed Oneleet’s compliance monitors directly, a failing device shows up as an actionable gap in your compliance program — not just a row in a device list.
One-click remediation
Section titled “One-click remediation”When a check fails, admins can often fix it remotely instead of walking the employee through system settings:
- enable BitLocker on the system drive (XTS-AES-256 with a TPM protector);
- turn Windows Firewall back on for every network profile;
- re-enable screen locking.
The fix is applied by the agent on the device and the check re-reports automatically. Enabling BitLocker remotely requires a TPM and a Pro, Enterprise, or Education edition of Windows.
Device configuration policies
Section titled “Device configuration policies”Admins can enforce Windows security settings fleet-wide from the Device Policies tab, with per-device overrides when a specific machine needs different values:
- Screen lock — inactivity timeout, require password on wake, and the grace period before the password is required;
- Removable storage — block removable media devices;
- Credential protection — run the Windows credential subsystem (LSASS) as a protected process, hardening the device against credential-theft tooling.
A CIS-aligned secure-defaults baseline can be applied in one click as a starting point. Policies reach online devices within about 15 minutes, and the agent continuously re-checks them afterward: if a setting drifts from policy, the agent restores it automatically and reports the correction back to Oneleet.
Device configuration policies are part of Oneleet MDM. Contact Oneleet to enable them for your organization.
Remote wipe
Section titled “Remote wipe”Remote wipe performs a full factory reset of the Windows device, removing company data and user profiles. This is a destructive action and should be used only when the device should no longer keep company data.
Use this when:
- a device is lost or stolen and should be treated as unrecoverable;
- an employee has left the company and the device needs to be reset;
- a device is being prepared for reassignment, return, or disposal.
Restart
Section titled “Restart”Restart lets an admin reboot a Windows device remotely. The signed-in user sees a warning before the restart so they can save their work.
Use this when:
- a user is having an issue and a restart is the next troubleshooting step;
- a device needs to restart after configuration changes;
- the user cannot easily restart the device themselves.
Manage local user accounts
Section titled “Manage local user accounts”Admins can manage a device’s local Windows accounts remotely: create an account (optionally with administrator rights), disable or re-enable it, reset its password, or delete it.
Use this when:
- offboarding an employee and their local account should be disabled immediately;
- reclaiming a device and IT needs its own administrator account on it;
- a user is locked out and needs a password reset.
Every action above is recorded in the device activity log, and the agent keeps itself up to date after installation — see the Oneleet MDM introduction for these shared capabilities.
Getting started
Section titled “Getting started”- Have the employee open the Oneleet Portal and download the Oneleet Agent for Windows from the Devices tab.
- Run the installer (administrator rights are required) and sign in with the work email address.
- The device appears in the Oneleet Dashboard under Devices, with security checks reporting within a few minutes and any configured device policies applying automatically.
The agent supports Windows 10 and later (x64). See Setup for detailed install and uninstall steps.
Offboarding a device
Section titled “Offboarding a device”When a Windows device leaves service or changes hands:
- disable or reset the departing employee’s local account if the device is being reclaimed;
- use remote wipe if the device is being reset, returned, or disposed of;
- archive the device or mark it out of scope in the dashboard once it is no longer part of your fleet.
If you are unsure whether a device should be wiped or removed from management, contact Oneleet support before taking action.