Skip to main content

August 21, 2026

Windows Health Attestation

As a Workspace ONE UEM admin, you can configure the compromised status definitions for Windows Desktop devices.

What can you do with the Windows Desktop Windows Health Attestation page?

The path to the settings page in the Workspace ONE UEM console is Groups & Settings > All Settings > Devices & Users > Microsoft > Windows > Windows Health Attestation.

With the Windows Health Attestation page, you can:

  • Configure a custom server for your Device Health Attestation service.
  • Select compromised status definitions, that when present, trigger a compromised status on your Windows devices.

Determine your Organization Group hierarchy

Before you review and modify settings, understand the two types of inheritance/override options for the organization group hierarchy available at the top and bottom of the settings page and determine your choices. For more information about these settings, see Override Versus Inherit Setting for Organization Groups.

  • Current Setting – Select whether to Inherit or Override the displayed settings. Inherit means use the settings of the current organization group's parent OG, while Override enables the settings for editing so you can modify the current OG's settings directly.
  • Child Permission – Select the available behavior of child organization groups that exist below the currently selected organization group. Inherit only means child OGs are only allowed to inherit these settings. Override only means they override the settings, and Inherit or Override means you can choose to inherit or override settings in child OGs that exist below the currently selected OG.

Compromised Status Definition

Health Attestation scans devices during startup for failures in device integrity. Use Health Attestation to detect compromised Windows Desktop devices while managed under Workspace ONE UEM.

In both BYOD and Corporate-Owned device deployments, it is important to know that devices are healthy when accessing corporate resources. The Windows Health Attestation Service accesses device boot information from the cloud through secure communications. This information is measured and checked against related data points to ensure that the device booted up as intended and is not victim to security vulnerabilities or threat. Measurements include Secure Boot, Code Integrity, BitLocker, and Boot Manager.

Workspace ONE UEM enables you to configure the Windows Health Attestation service to ensure device compliance. If any of the enabled checks fail, the Workspace ONE UEM compliance policy engine applies security measures based on the configured compliance policy. This functionality allows you to keep your enterprise data secure from compromised devices. Since Workspace ONE UEM pulls the necessary information from the device hardware and not the OS, compromised devices are detected even when the OS kernel is compromised.

Configure the Health Attestation for Windows Desktop Compliance Policies

Keep your devices secured by using Windows Health Attestation Service for compromised device detection. This service allows Workspace ONE UEM to monitor the device integrity during startup and take corrective actions.

  1. Navigate to Groups & Settings > All Settings > Devices & Users > Microsoft > Windows > Windows Health Attestation.

  2. Select Use Custom Server if you are using a custom on-premises server running Health Attestation. Enter the Server URL.

  3. Configure the Health Attestation settings:

    SettingsDescriptions
    Use Custom ServerSelect to configure a custom server for Health Attestation.

    This option requires a server running Windows Server 2016 or newer.

    Enabling this option displays the Server URL text box.
    Server URLEnter the URL for your custom Health Attestation server.
    Secure Boot DeactivatedEnable to flag compromised device status when Secure Boot is deactivated on the device.

    Secure Boot forces the system to boot to a factory trusted state. When Secure Boot is enabled, the core components used to boot the machine must have the correct cryptographic signatures that the OEM trusts. The UEFI firmware verifies the trust before it allows the machine to start. Secure boot prevents the startup if any it detects any tampered files.
    Attestation Identity Key (AIK) Not PresentEnable to flag compromised device status when the AIK is not present on the device.

    Attestation Identity Key (AIK) is present on a device, it indicates that the device has an endorsement key (EK) certificate. It can be trusted more than a device that does not have an EK certificate.
    Data Execution Prevention (DEP) Policy DeactivatedEnable to flag compromised device status when the DEP is deactivated on the device.

    The Data Execution Prevention (DEP) Policy is a memory protection feature built into the system level of the OS. The policy prevents running code from data pages such as the default heap, stacks, and memory pools. DEP is enforced by both hardware and software.
    BitLocker DeactivatedEnable to flag compromised device status when BitLocker encryption is deactivated on the device.
    Code Integrity Check DeactivatedEnable to flag compromised device status when the code integrity check is deactivated on the device.

    Code integrity is a feature that validates the integrity of a driver or system file each time it is loaded into memory. Code integrity checks for unsigned drivers or system files before they load into the kernel. The check also scans for users with administrative privileges running system files modified by malicious software.
    Early Launch Anti-Malware DeactivatedEnable to flag compromised device status when the early launch anti-malware is deactivated on the device.

    Early launch anti-malware (ELAM) provides protection for the computers in your network when they start up and before third-party drivers initialize.
    Code Integrity Version CheckEnable to flag compromised device status when the code integrity version check fails.
    Boot Manager Version CheckEnable to flag compromised device status when the boot manager version check fails.
    Boot App Security Version Number CheckEnable to flag compromised device status when the boot app security version number does not meet the entered number.
    Boot Manager Security Version Number CheckEnable to flag compromised device status when the boot manager security version number does not meet the entered number.
    Advanced SettingsEnable to configure advance settings in the Software Version Identifiers section.
  4. Select Save.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…