Skip to content
FirstSIDocs

Machine security status

Antivirus, EDR, patches, SMBv1, BitLocker, Windows firewall and LAPS on every workstation and server, with a score per machine and for the fleet; time, DHCP and DFS-R in the Infrastructure tab.

A workstation with no active antivirus, a server with no patch for three months, SMBv1 left open: these gaps go unnoticed until the day they get used. The Security status screen collects these points on every machine and turns them into a score.

What you need

The collection is done by the agent's AssetMonitor module, every 6 hours, and 3 minutes after it starts. The agent must be at version 2026.10.11.3 or later (see Manage agents). It reads the state of Windows without changing anything, and collects no BitLocker recovery key and no LAPS password.

Reading the screen

Open Asset Monitor → Security status (#/am/securite).

The Machines tab shows the Fleet score and its curve over 90 days, one counter per rule (click one to filter the list) and the Machines, most exposed first table. Each column carries a dot: AV, Sig. (signatures), EDR, Tamper (tamper protection), Patch (patches), SMB1, BitL., FW (firewall), LAPS and Report.

You can filter by type (workstation, server, domain controller), by text, or tick Failing only. Clicking a machine opens its details: findings, open incidents, score over 90 days, and the state collected for antivirus, patches, BitLocker, SMBv1, firewall and LAPS.

The rules

RuleGapSeverity
SECU-ANTIVIRUSno active antivirus (neither Defender in real time nor a third-party antivirus)critical on a server or a controller, high on a workstation
SECU-SIGNATURESsignatures older than 3 days; older than 7 daysmedium; high
SECU-EDRDefender for Endpoint installed but stopped or disabledhigh
SECU-FALSIFICATIONtamper protection disabledmedium
SECU-CORRECTIFSlast patch more than 45 days ago; more than 90 days; reboot pending for more than 7 daysmedium; high; medium
SECU-SMB1SMBv1 server enabled; client onlyhigh; medium
SECU-BITLOCKERsystem volume of a physical workstation not encryptedmedium (see below)
SECU-PARE-FEUdomain profile disabled; all profiles disabledmedium; high
SECU-LAPSneither legacy LAPS nor Windows LAPSlow, no incident
SECU-RELEVEno report for 48 hoursmedium

On a server, Defender in passive mode is a low finding with no incident: the third-party antivirus that replaces it cannot be seen on a server.

Gaps of medium severity and above open an incident in the SIEM from the first report, and close it when they go away. Low gaps do not open one. For SECU-RELEVE, only a server or a controller opens an incident: a workstation that is switched off is flagged without an alert.

BitLocker

The rule only applies to physical workstations. Servers, domain controllers and virtual machines are marked "Not applicable".

Workstation's situationWhat happens
Never seen encrypted by FirstSImedium finding, counted in the score, no incident
Seen encrypted, then no longer encryptedmedium finding with an incident

That is deliberate: a fleet that has not encrypted its workstations should not trigger one alert per workstation, whereas a workstation that loses its encryption deserves a look. FirstSI only knows the reports it has received: a workstation unencrypted from its first report is classed as "never seen encrypted".

The score

Each machine starts at 100. Each failing rule takes off 40 (critical), 25 (high), 10 (medium) or 3 (low), down to 0 at the lowest.

The Fleet score is the weighted average of machines that reported within the last 30 days: a domain controller counts 3, a server 2, a workstation 1.

Machines with no active antivirus or a stopped EDR also appear in the To handle list on the dashboard.

Infrastructure tab

The same report contains the machine's time, DHCP scopes (if the role is installed) and DFS-R replication (if the service is running). These rules are not part of the score.

RuleGapSeverity
INFRA-HEUREoffset beyond 60 s from the time source; beyond 300 smedium; high
INFRA-HEUREdomain member set to its internal clockmedium
INFRA-DHCPactive scope more than 85% used; more than 95%medium; high
INFRA-DFSRreplicated folder in a state other than normalhigh
INFRA-DFSRDFS-R errors in the last 24 hoursmedium

The Time, DHCP and DFS-R by machine table only shows machines that have this data.

Frequently asked questions

"No security report received yet". The AssetMonitor module is not active on the machine, or the agent is too old.

A workstation has a third-party antivirus, but the AV column is red. The third-party antivirus has not registered as active with Windows Security Center. Check its state on the workstation.

A server shows "Not applicable" for BitLocker. That is deliberate: the rule only applies to physical workstations.

Source: · FirstSI Docs · updated 2026-10-11