Skip to content
A security specialist reviewing endpoint patch and execution-control dashboards
XPC-Plus

The endpoint that knows exactly what it is allowed to do.

XPC-Plus keeps Windows exactly where it is, then closes the two gaps that most endpoint estates never really close: unpatched software and uncontrolled execution. One subscription, one managed outcome, three layers working on the same endpoint.

$17 per endpoint / month

$17

Per endpoint / month

One price for the XPC experience layer, fully managed patching and fully managed deny-by-default execution control.

3

Layers, one endpoint

Experience control, patch remediation and execution control applied together instead of bought, integrated and staffed separately.

$0

OS migration cost

No Linux, no re-imaging and no second endpoint operating system. Windows stays installed, patched and managed underneath.

Three layers. One endpoint.

Control what users see. Patch what is installed. Control what can execute.

Each layer solves a problem the others cannot. Bought separately they are three products, three consoles and three ongoing workloads. In XPC-Plus they are one subscription and one managed outcome.

Layer 01
XPC

Control the experience

The user sees only what they are meant to see.

XPC replaces the general-purpose Windows desktop with one locked, brandable access screen that presents the connections you approve — Citrix, RDP, AVD, Windows 365, Horizon, WorkSpaces, Parallels RAS or a browser workspace. Windows stays underneath, patched and managed as normal.

  • One access screen instead of a full desktop
  • No local desktop wandering, no stray installs by habit
  • XPC Mode and XPC-Lite Mode for different levels of lockdown
  • Configured centrally from the XPC Cloud Portal
Layer 02
Action1

Eliminate patch neglect

Patch everything you are trusting.

Locking the user experience does not patch the software still installed on the machine. XPC-Plus includes fully managed patching and vulnerability remediation using Action1, covering Windows and the third-party applications that are most often left behind — browsers, runtimes, remote-access clients and helper agents.

  • Continuous discovery of installed software and missing updates
  • Windows and third-party application patching, managed for you
  • Remediation applied on a schedule that respects shift patterns
  • Patch and vulnerability status visible per endpoint
Layer 03
ThreatLocker

Control what can execute

Trust less — even after approval.

The third layer moves the endpoint from “block what we recognise as bad” to “only run what has been approved”. XPC-Plus includes fully managed deny-by-default execution control using ThreatLocker, so unapproved applications, scripts and libraries do not run in the first place.

  • Deny-by-default application control rather than detect-and-respond
  • Approved software still constrained in what it may reach
  • Unapproved scripts and libraries denied by policy
  • Policy authored and maintained by us, not handed to you as homework

XPC-Plus incorporates technology from

Action1ThreatLocker

Action1 and ThreatLocker are trademarks of their respective owners. XPC is not affiliated with, or endorsed by, either company.

The XPC-Plus security stack

Every layer between the user and the hardware, accounted for

Nothing here replaces Windows. Each layer governs a different part of what the endpoint is allowed to do.

User

One access screen. No general-purpose desktop to wander around in.

XPC experience layer

Presents and launches only approved connections. Brandable, centrally configured.

Execution control

Deny-by-default application control and ringfencing (ThreatLocker).

Patch and vulnerability remediation

Managed Windows and third-party patching (Action1).

Windows

Kept, patched and managed. Familiar to users, familiar to your team.

Hardware

The PCs and thin clients you already own, kept in service longer.

Action1

Layer 02 — patching

Patch everything you are trusting

A locked access screen does not patch the software still installed underneath it. The browser, the remote-desktop client, the runtimes and the helper agents on a thin-client-style endpoint are exactly the components an attacker would prefer you forgot about — and on shared or unattended PCs, nobody is there to notice an update never landed.

XPC-Plus includes fully managed patching and vulnerability remediation, so patch currency is an outcome you are buying rather than a task you are hoping someone had time for.

ThreatLocker

Layer 03 — execution control

Trust less — even after approval

Patching closes known holes. Execution control changes the default answer to “something new wants to run”. Instead of assessing whether it looks malicious, XPC-Plus denies anything that has not been approved.

This is not a replacement for the antivirus, EDR or identity controls your policy or insurer requires. It reduces what can run at all, which is a different and complementary job.

Allowlisting and ringfencing

Allowlisting decides what runs. Ringfencing decides what it may do next.

Most people meet application control as a list of approved programs. That is only half of it. Approving an application does not mean the application should be able to reach every file, every network path and every other program on the machine. Deny-by-default control lets an approved application do its job and nothing beyond it.

An approved tool, an unapproved action

A legitimate scripting engine is genuinely needed by an installed application. Left alone, it can also be driven to fetch and run something else. Constrained, it does the job it was approved for and cannot be turned into a delivery mechanism.

An approved application, unapproved reach

An approved productivity application has no business enumerating a finance file share. Constraining its reach limits the damage a compromised or misused process can do, even though the application itself remains approved.

Approved software, unapproved children

Many attacks work by using something already trusted to launch something new. Controlling what an approved process may launch removes that route without removing the software people rely on.

Examples above are conceptual illustrations of how allowlisting and ringfencing differ. They are not descriptions of any specific incident, product configuration or customer environment.

The security loop

Discover, remediate, control, contain, present

Endpoint security fails at the point where it becomes someone’s recurring chore. XPC-Plus turns the loop into a service that runs whether or not your team had a quiet week.

01

Discover

Find what is actually installed and what is actually missing patches — on every endpoint, continuously.

02

Remediate

Apply Windows and third-party updates on a managed schedule so the gap closes instead of ageing.

03

Control

Allow only approved applications, scripts and libraries to execute at all.

04

Contain

Constrain what approved software may reach, so an approved process cannot be repurposed freely.

05

Present

Show the user one clean access screen, so the endpoint stays the endpoint you configured.

Then it starts again — continuously, as a managed service.

An IT operations team reviewing endpoint status together

Managed, not abandoned

Stop babysitting it

XPC-Plus is not a promise that endpoints never need attention again. It is a promise that the recurring work — chasing patches, curating allowlists, reviewing what changed — is run by us as a managed service, so it happens whether or not your team had a quiet week.

Patch policy, schedules and exceptions maintained for you
Application-control policy authored, tuned and reviewed for you
Approval requests handled as part of the service
Endpoint status summarised per device in the XPC Cloud Portal
Your team keeps oversight and the final say on policy

The upgrade path

An upgrade, not a project

XPC-Plus applies to endpoints already running XPC. There is no re-imaging, no user migration and no change to the connection the user sees.

  1. 1

    Log in to the XPC Cloud Portal

    The same portal you already use to manage XPC endpoints. Nothing new to install for administrators.

  2. 2

    Choose the endpoints to upgrade

    Select individual endpoints, a device group, or the whole organisation. MSP-grade tenants can upgrade per customer organisation or in bulk across every organisation they manage.

  3. 3

    Enable XPC-Plus

    The patching and execution-control layers are deployed and enrolled to the selected endpoints. No re-imaging, no user migration and no change to the connection the user sees.

  4. 4

    Watch the status

    Each endpoint reports its XPC-Plus state: protection enrolled, patch level, pending remediation and execution-control policy applied.

Per-endpoint status

What the portal shows you

  • XPC-Plus enabled or not, per endpoint
  • Patch level and outstanding remediation
  • Execution-control policy applied and version
  • Recent denied-execution activity
  • Approval requests awaiting decision

XPC-Plus is provisioned per organisation from the XPC Cloud Portal. Talk to us to enable it on your tenant and we will confirm lead time and onboarding for your endpoints.

XPC and XPC-Plus

Which tier fits the endpoint in front of you

Standard XPC assumes you already run patching and endpoint security and simply want the experience layer. XPC-Plus is for the endpoints where you would rather that work were handled for you.

CapabilityXPC — $2XPC-Plus — $17
Locked, brandable access screenIncludedIncluded
Any remote platform (Citrix, RDP, AVD, W365, Horizon, WorkSpaces, RAS)IncludedIncluded
Central management in the XPC Cloud PortalIncludedIncluded
Windows kept, patched and managed underneathYes — using your existing toolingYes — patching managed by us
Windows and third-party patch remediationYour existing RMM or patch toolingFully managed (Action1)
Software and vulnerability discoveryYour existing toolingContinuous, included
Deny-by-default application controlNot includedFully managed (ThreatLocker)
Ringfencing of approved applicationsNot includedIncluded
Policy authoring and ongoing tuningYour teamRun as a managed service
Price$2 per PC / month$17 per endpoint / month

Where it earns its place

The endpoints that benefit most

Regulated and audited environments

Finance, health, legal and government teams that must show patch currency and demonstrate that only approved software executes.

Shared and unattended endpoints

Shift-worked desks, clinical rooms, classrooms, kiosks and reception PCs where nobody owns the machine and nobody notices drift.

Small teams with no security staff

Organisations that need the outcome of a patching programme and an application-control programme without hiring for either.

MSPs standardising a security posture

One upgrade, applied per customer organisation, giving every managed estate the same patching and execution-control baseline.

XPC-Plus questions

Straight answers

The Plus capabilities run on either XPC architecture

Managed patching and deny-by-default application control are independent of how the endpoint presents Windows, so you choose the architecture the endpoint needs and add the Plus layer on top.

XPC-Plus

$17

per endpoint / month

The Plus security and management layer on the standard XPC architecture, where the traditional Windows desktop is replaced for maximum lockdown.

XPC-Lite-Plus

$19

per endpoint / month

The same Plus layer on the XPC Lite compatibility architecture, where the underlying Windows environment keeps operating — hidden from the user — for applications and services that require it.

Three layers. One endpoint. $17 per month.

Keep Windows, keep your peripherals, keep your team’s skills — and stop carrying patching and application control as recurring work.