Securing and maintaining an XPC endpoint
Windows is still there. It still needs to be looked after.
XPC controls what a user sees and can reach on a Windows PC. It is not a replacement for patching, antivirus/EDR or application control, and it does not make Windows immutable. Here is exactly what stays your responsibility, and what we recommend where you don't already have it covered.

XPC reduces interaction. It does not remove Windows.
XPC reduces unnecessary user interaction with the local Windows environment, but Windows still exists underneath and must continue to be patched, protected and managed. XPC does not replace Windows patching, antivirus or EDR, or application control, and it does not make Windows immutable.
The claim you will hear from every other vendor
Immutability is a marketing word doing the work of a security control.
Competing endpoints are usually sold on one idea: the operating system cannot be changed. It is worth asking what that actually covers before you let it decide the architecture of your estate.
Dual boot is not a smaller attack surface
Many Linux thin-client and desktop builds are deployed alongside Windows in a dual-boot arrangement, so the user chooses at power-on which operating system to start. That is two operating systems to patch, license, monitor and support, and the Windows side is usually the one left unmanaged. If a user can boot into an open Windows install, that install is also a convenient place to inspect, copy or alter the other partitions on the same disk — including the one described as immutable, because read-only at runtime is not the same as protected at rest. Said kindly and without criticism of any vendor: if the design ends with a bootable Windows partition on the machine anyway, it is usually simpler, cheaper and safer to keep one well-managed Windows environment and control what the user can do inside it.
Reset on reboot is recovery, not prevention
"Returns to a clean state every restart" describes what happens after the session, not what was possible during it. Credentials, data and outbound connections do not wait for a reboot.
Local browsers reintroduce persistence deliberately
Where the same products ship a local Chrome or Firefox and tell users they can keep bookmarks and install extensions, persistence has been added back on purpose. That can be a perfectly reasonable product decision — but by definition it is not an immutable endpoint.
Physical access is the same problem on any OS
Someone with the device in their hands and time to spend has options regardless of the operating system. Boot media, firmware settings and removable storage do not care which platform is installed.
It governs the image, not the application
Where immutability genuinely exists, it protects the operating-system image. It says nothing about what an approved application is then allowed to run, reach or send — which is where a large share of modern incidents actually happens.
The more useful question to put to any endpoint vendor is not "is the image immutable?" but "what stops an approved application from doing something it should not?"
What we would put up against an immutable image
A managed Windows endpoint with real application control is a defensible position.
None of this makes an immutable Linux endpoint a bad product. Where a minimal non-Windows device is genuinely the requirement, it is the right answer and we say so. But for most estates the stronger, cheaper and more auditable move is to control what applications may do on the Windows machines you already run.
Under normal policy, unchanged
What stays exactly where it is
XPC changes what the user sees and can reach. It does not take over these — they remain your responsibility, run with whatever tooling you already use.
Where the recommended tools sit
One included layer. Two recommended layers. One foundation that never moves.
Action1 and ThreatLocker are not part of XPC. They are shown here only to make clear where they would sit if you choose to run them.
Layer 1 — included
XPC
A controlled, brandable remote-workspace experience for the user.
Layer 2 — recommended, not included
Action1
Recommended patch management, where you don't already have a satisfactory solution.
Layer 3 — recommended, not included
ThreatLocker
Recommended application control — deny-by-default allowlisting and ringfencing of approved applications.
Foundation — unchanged
Windows
The existing Windows OS, drivers, agents, native remote-workspace clients and management environment remain in place.
Product philosophy
XPC deliberately stays focused on the endpoint experience. We recommend specialist products for specialist jobs.
Patch management and application control are mature, deeply specialised disciplines with their own vendors, consoles and support models. XPC does not try to reproduce them. Instead, it recommends proven tools for the gaps it does not fill — you choose whether to use them, run something else, or keep what you already have.
Recommended companion technologies
Where you don't already have a satisfactory solution
Recommended patch management
Where a customer does not already have a satisfactory patch management solution, XPC recommends Action1 for keeping Windows and third-party software up to date.
- Discovery of installed software and missing updates
- Windows and third-party application patching
- Scheduling that respects shift patterns and maintenance windows
Recommended application control
Where a customer does not already have a satisfactory application-control solution, XPC recommends ThreatLocker for deny-by-default allowlisting and ringfencing of approved applications.
- Deny-by-default allowlisting instead of detect-and-respond
- Ringfencing constrains what an approved application may reach
- Independent console, policy and support from ThreatLocker
Action1 and ThreatLocker are recommended companion technologies, not components of XPC. Neither is included in an XPC subscription, bundled with it, licensed through XPC, or delivered as a managed service by XPC. Referencing them here is not a partnership, integration or endorsement claim in either direction — they are independent products you may license and run yourselves, or substitute with an equivalent solution you already trust.
Common questions
Straight answers
See how XPC handles the endpoint experience
XPC and XPC Flex focus on the endpoint experience. Patching and application control stay with the tools you choose.
