Security Reference Guide — Doc. 8726A Crestron Flex UC-ENGINE • 3
Operating System
The UC-ENGINE uses the Windows 10 IoT Enterprise operating system with Windows
Firewall enabled by default. Configuration of the operating system is required (see
"Network Configuration" below).
NOTE: Do not force Windows build 1909 or 2004 to Microsoft Teams devices. For more
information on supported versions, visit the Microsoft documentation.
Antivirus and Anti-Malware
Standard Windows 10 services including Windows Defender and Windows Firewall are
enabled by default and are updated automatically.
Network Configuration
The UC-ENGINE is configured with the following settings. Additional action may be taken
where applicable.
l DHCP: Standard DHCPconfiguration
l Wi-Fi®: enabled in Windows, but not supported on the UC-ENGINE.
l Hardening: The Crestron Flex UC-ENGINE may be hardened like any other Windows
device under the condition that all Crestron services and ports are left active. Skype
for Business and Microsoft Teams must be left accessible.
l Unneeded Accounts: The built-in Admin account can be removed or disabled as long
as the device is domain attached. Doing so allows administrators to use any domain-
level admin account to log in.
l File Share: No file share is enabled by default.
l Unneeded Ports: Any ports besides those listed on the Network Port List (on page9)
may be disabled.
l Unneeded Services: All Crestron services must be left enabled. Any standard
Windows services can be disabled as needed.
l Unneeded Applications: All Crestron applications must be left enabled. Any standard
Windows applications can be disabled as needed.
l Restriction of External (USB)Devices: No restriction of external USBdevices.
Physical covers are initially placed over the USBplugs.
l Authentication of External Devices (e.g. USB Type-C® Authentication Specification):
No authentication.
l Customer Supplied Software (e.g. Printer Drivers): Any utility software can be
installed, but should be tested for interference with other software.
l Customer Supplied Anti-Malware: Windows Defender anti-malware is included and
enabled as a standard feature. Further anti-malware systems may be added, but
should be tested for system breakage or slowdowns.