IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Support / MSP 4.1.8 C10-H2

MSP 4.1.8 security and setup

Windows file version 4.1.8.3 · Updated October 6, 2026

All documentation · Support center

Choose Automatic or Manual settings

In Server Administration, Security & Communications, choose the communication profile. Automatic fills the recommended controls. Manual retains edited control values. Neither selection activates the listener: save settings and restart the MSP Server service. Certificate prerequisites and validation still apply.

Profile requirements

OFF uses HTTP. Standard defaults to TLS 1.2/1.3 without mTLS, request signing or revocation checks. Enhanced adds CA trust, request signing and API certificate revocation. High Assurance requires TLS 1.3, mTLS, signing, revocation and CA-chain trust. DoD-Aligned also enforces its Windows FIPS prerequisite. The DoD-Aligned label is a technical profile, not certification.

Certificate choices are alternatives

Choose one option: an existing server certificate, import a server PFX, or create a Standard lab certificate. Continue performs the selected action. Then check the address and certificate; export the public certificate when clients need it. A lab certificate is for Standard testing and requires explicit client trust. Never distribute the private server PFX to clients.

Verify the running listener

Check Settings (Preflight) checks configuration before activation; it does not verify the live listener. After saving and restarting, run Verify Current Secure Connection from the client. Confirm TLS, authentication and server security status for the intended profile. Reverify after changing profiles.

Protect the database connection

For a recognized ITAF-managed local PostgreSQL installation, use Prepare managed database TLS and review its confirmation. Keep VerifyFull and the matching CA file. API TLS and database TLS are separate. A generated local database CA may not offer revocation information; investigate that specific database test failure rather than weakening API profile requirements.

Client connection setup

Use Guided setup for device request, administrator approval and importing the approved setup on the requesting device/account. Manual setup exposes the connection fields for administrator-supplied values. Verify the live connection after either method.

Integration settings

Air-gapped mode blocks the integration webhook test; it is not Windows network isolation. The human-approval checkbox records a preference; it does not enforce an approval workflow. An optional HTTPS webhook receives a small test message when Test Integration Webhook is clicked. Save the settings before testing.

Download the complete text guide