Network Hardening Policies Option

Purpose

This article document shows how to enable “Network Hardening Policies Option” for MetaDefender Kiosk during system configuration and what changes will be applied.

Solution

To set up “Network Hardening Policies Option” in MD Kiosk, please read through the following guidance for step-by-step instructions.

Step 1. Access Kiosk WebMC, navigate to Settings, select System Hardening

Step 2. Enable Network Hardening Policies, then click Save Setting. A prompt will appear requesting a system restart.

Step 3: Restart the machine to apply the setting.

System changes when the option is enabled

When the Network Hardening Policies option is enabled, certain network-related services will be disabled to enhance system security. As a result, some Kiosk functionalities that rely on these services may be limited or unavailable. Below is a list of affected features

FeatureUse caseNetwork Hardening Policies is disabledNetwork Hardening Policies is enabled
ActivationActivate license online✔️
Engine UpdateUpdate scanning engine online✔️
File processing with the local CoreProcess files with the local MD Core✔️✔️
File processing with the remote CoreProcess files with the remote MD Core✔️
Active DirectoryLogin to Kiosk with Active Directory accounts✔️
Encrypted USBsProcess files on encrypted USBs✔️✔️
USBs with multiple partitionsProcess files in media multiple partitions✔️✔️
Virtual disks (VHD, VMDK, TIB)Process files on virtual disk (VHD, VMDK, TIB)✔️✔️
Phone, CD, DVD, Blue-ray, Floppy DiskProcess files on different media types (Phone/CD/DVD/Blu-ray/Floppy Disk)✔️✔️
MFT IntegrationProcess, send and retrieve files with MFT✔️
Shared folderCopy files and save session logs to a shared folder✔️
Secure connections (HTTPS)Enable Secure Connections (HTTPS)✔️✔️
WatchdogWatchdog to monitor the system behavior✔️✔️
Email notificationSend email notification for the scan completion✔️
SyslogIntegrate with syslog server✔️
System hardeningEnable other Kiosk system hardening options✔️✔️ (except for RDP feature)
Windows FirewallTurn on/off Windows Firewall service✔️❌ (Firewall service is disabled)
Network and IP AddressConfigure Kiosk's IP address✔️
Export/import Kiosk configurationsExport or import Kiosk configuration files✔️✔️
Kiosk Hardened Image UpgradeUpgrade Kiosk Hardened Image online or via Folder✔️

Following network-related services will be disabled:

ServiceDefault StatusWhen Network Hardening Policies is enabled
AJRouterManualDisabled
ALGManualDisabled
BFEAutomaticDisabled
BITSManualDisabled
CDPSvcManualDisabled
cloudidsvcManualDisabled
CscServiceManualDisabled
DhcpAutomaticDisabled
DnscacheAutomaticDisabled
DoSvcManualDisabled
dot3svcManualDisabled
DsSvcManualDisabled
DusmSvcManualDisabled
EaphostManualDisabled
edgeupdateAutomaticDisabled
edgeupdatemManualDisabled
fdPHostManualDisabled
FDResPubManualDisabled
IKEEXTManualDisabled
InstallServiceManualDisabled
Intel(R) Capability Licensing Service TCP IP InterfaceManualDisabled
iphlpsvcAutomaticDisabled
IpxlatCfgSvcManualDisabled
McpManagementServiceManualDisabled
MicrosoftEdgeElevationServiceManualDisabled
MSDTCManualDisabled
NcaSvcManualDisabled
NcbServiceManualDisabled
NcdAutoSetupManualDisabled
NetlogonManualDisabled
NetmanManualDisabled
netprofmManualDisabled
NetSetupSvcManualDisabled
NgcCtnrSvcManualDisabled
NgcSvcManualDisabled
NlaSvcAutomaticDisabled
nsiAutomaticDisabled
PeerDistSvcManualDisabled
PolicyAgentManualDisabled
PrintNotifyManualDisabled
QWAVEManualDisabled
RasManAutomaticDisabled
SharedRealitySvcManualDisabled
shpamsvcManualDisabled
SmsRouterManualDisabled
SNMPTRAPManualDisabled
SstpSvcManualDisabled
TrkWksManualDisabled
W32TimeManualDisabled
WcmsvcAutomaticDisabled
wcncsvcManualDisabled
WebClientManualDisabled
WEPHOSTSVCManualDisabled
WFDSConMgrSvcManualDisabled
WinHttpAutoProxySvcManualDisabled
WlanSvcAutomaticDisabled
wlpasvcManualDisabled
WManSvcManualDisabled
workfolderssvcManualDisabled
WPDBusEnumManualDisabled
WwanSvcManualDisabled
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard