MG SR Uc-Engine
MG SR Uc-Engine
MG SR Uc-Engine
Crestron product development software is licensed to Crestron dealers and Crestron Service Providers (CSPs) under a limited
nonexclusive, nontransferable Software Development Tools License Agreement. Crestron product operating system software is
licensed to Crestron dealers, CSPs, and end-users under a separate End-User License Agreement. Both of these Agreements can
be found on the Crestron website at www.crestron.com/legal/software_license_agreement.
The specific patents that cover Crestron products are listed online at www.crestron.com/legal/patents.
Certain Crestron products contain open source software. For specific information, please visit www.crestron.com/opensource.
Crestron, the Crestron logo, Crestron Fusion, and XiO Cloud are either trademarks or registered trademarks of Crestron
Electronics, Inc. in the United States and/or other countries. Intel is either a trademark or registered trademark of Intel
Corporation in the United States and/or other countries. Active Directory, Azure, Microsoft, Microsoft 365, Microsoft Dynamics
365, Microsoft Intune, Microsoft Teams, Office 365, Skype, and Windows are either trademarks or registered trademarks of
Microsoft Corporation in the United States and/or other countries. USB Type-C is either a trademark or registered trademark of
USB Implementers Forum, Inc. in the United States and/or other countries. Miracast and Wi-Fi are either trademarks or
registered trademarks of Wi-Fi Alliance. Zoom Rooms is either a trademark or registered trademark of Zoom Video
Communications, Inc. in the United States and/or other countries. Other trademarks, registered trademarks, and trade names
may be used in this document to refer to either the entities claiming the marks and names or their products. Crestron disclaims
any proprietary interest in the marks and names of others. Crestron is not responsible for errors in typography or photography.
B February 7, 2023 Significant update to all topics based on latest IH, JZ, MH
UC-ENGINE functions and specifications
SecurityDocs@crestron.com
System Specifications 2
Product Software - Security Features 2
User Authentication 2
Audit Logging 2
Connectivity 2
Software Updates and Patches 3
Operating System 3
Antivirus and Antimalware 3
Network Configuration 3
Third-Party Software 4
Microsoft Teams Rooms 4
Zoom Rooms 4
Network Infrastructure 5
Microsoft Network Architecture Diagrams 5
Network Port List 5
VLAN 7
Security Controls 8
Malware and Vulnerability Protection 8
Security Applications 8
Vulnerability Protection 8
Remote Connectivity 8
Role-Based Access Control 8
Password Security 8
Data Segregation 9
Cloud Storage 9
Physical Protection 9
Audit Logging 9
Data Protection 9
Security Best Practices 9
More Security Information 10
The UC-ENGINE comes preassembled on a bracket assembly as part of a Crestron Flex kit. Other
peripherals must be provided by the user. For more information on Crestron Flex kits, refer to the
Crestron Flex feature page.
The following diagram provides an example of devices and connections that are common within a
typical Crestron Flex system.
Security Policies
For general security policies, refer to the Crestron security web page.
NOTE: To view security features for other Crestron devices that may be included within a Crestron
Flex deployment (such as touch screens or AirMedia® presentation ), refer to the applicable security
documentation at security.crestron.com.
User Authentication
When using a Microsoft Teams device, two accounts are set up by default: a Microsoft Teams account
and a default Admin account for administrating the UC-ENGINE.
When using a Zoom Rooms device, two accounts are setup as default: a CrestUC account and a default
Admin account for administrating the UC-ENGINE.
CAUTION: The password for the default CrestUC or default Microsoft Teams account must not be
changed. If changed, the device will require a reimage.
Audit Logging
System tasks use Windows® standard audit logging. Security-related application tasks are logged and
stored in the audit log.
Connectivity
The UC-ENGINE supports connectivity to Microsoft Teams or Zoom Meeting services and can utilize the
following management portals:
l XiO Cloud® Provisioning and Management Service
l Crestron Fusion® Cloud Software
l Microsoft Teams Admin Center
l Zoom Admin Portal
l Microsoft Intune® Service
Optionally, Zoom devices may be managed through the Zoom admin portal. For more information, refer
to the Zoom Help Center article.
Operating System
The UC-ENGINE uses the Windows 10 IoT Enterprise operating system with Windows Firewall turned on
by default. Configuration of the operating system is required (refer to Network Configuration on page
3).
Network Configuration
The UC-ENGINE is configured with the following settings. Additional action may be taken where
applicable.
l DHCP: A standard DHCP configuration is provided.
l Wi-Fi® Communications: Wi-Fi communications are turned on in Windows, but not supported on
the UC-ENGINE.
l Hardening: The UC-ENGINE may be hardened like any other Windows device under the condition
that all Crestron services and ports are left active. Microsoft Teams or Zoom Rooms must be left
accessible.
l Unneeded Accounts: The built-in Admin account can be removed or disabled as long as the device
is domain attached. Doing so allows administrators to use any domain-level admin account to log
in.
l File Share: No file share is turned on by default.
l Unneeded Ports: Any ports besides those listed on the Network Port List on page 5 may be
disabled.
l Unneeded Services: All Crestron services must remain turned on. Any standard Windows services
can be turned off as needed.
l Unneeded Applications: All Crestron applications must remain turned on. Any standard Windows
applications can be turned off as needed.
l Restriction of External (USB) Devices: There is no restriction of external USB devices. However,
Crestron recommends only connecting USB devices that are included in the Crestron Flex kit, sold
by Crestron, or are certified for use with Crestron Flex systems.
l Authentication of External Devices (such as USB Type-C® Authentication Specification): No
authentication is provided.
Third-Party Software
All third-party and open source software and licenses used in Crestron applications are detailed in the
EULA included with the device. The UC-ENGINE is shipped with either a Microsoft Teams Rooms system
or a Zoom Rooms system. Each of these applications are created and owned by Microsoft® or Zoom
respectively.
All updates to the Microsoft Teams Rooms application, including security and feature updates, are
automatically installed by the Windows Store. All security and feature updates are delivered in this
manner. Users may not manually install updates to the Microsoft Teams Rooms application.
Configuration of the Microsoft Teams Rooms application is done by selecting the Settings option under
the More button on the main interface screen.
For information on the configuration options available, refer to the Microsoft Teams Rooms
Deployment Guide.
NOTE: UC-ENGINE devices running Microsoft Teams are Microsoft Autopilot ready, which allows for
fast provisioning and deployment of Microsoft Teams Room systems. Tenant management and
conditional access policies should be reviewed as part of a secure deployment. For more information
on Microsoft Autopilot, refer to Microsoft® Autopilot Support on Crestron Flex Teams UC-ENGINES.
Zoom Rooms
The Zoom Rooms app is a customized Zoom Meetings client created by Zoom specifically for room
systems. The application is preinstalled as part of the device image created by Crestron and starts
automatically as the main interface on the UC-ENGINE when it is in Zoom mode.
All updates to the Zoom Rooms application can be applied either manually or automatically through the
Zoom admin portal. Crestron also periodically provides updates to the Zoom Rooms application that
can be installed manually on the UC-ENGINE. However, Crestron does not publish all Zoom Rooms
updates.
Miracast A/V AirMedia 4570/UDP End User Device The default port
Workstations for Miracast
A/V, only open
during video
presentation
Miracast RTSP AirMedia 7236/TCP Device End User Default port for
Workstations Miracast RTSP
VLAN
In order to ensure proper functionality, ensure the display devices and UC-ENGINE are on the same
VLAN.
Security Applications
The following Microsoft applications are included on the Crestron Flex UC-ENGINE:
l Enhanced Mitigation Experience Toolkit (EMET)
l AppLocker
l Backup Solutions
l User Account Control
l Windows Defender
Vulnerability Protection
If vulnerabilities or other issues are found, a patch will be made available to customers. If the patch is
not urgent, the Crestron support team will work with the customer to identify a time to apply the patch.
If the patch fixes a critical vulnerability, the customer will be informed when the patch will be applied.
Upon identifying an attack, immediate steps will be taken to close access as soon as possible. Once the
attack is halted, forensic analysis will be taken to identify any customer data that may have been
accessed. Customers will then be alerted about the impact of the attack and any of their data that may
have been accessed.
Remote Connectivity
Remote users' activities are logged by Crestron and may be reviewed as needed. No third parties are
granted access to this information.
Password Security
Ensure all used passwords meet following criteria:
For front-end XiO Cloud account user passwords, single sign-on (SSO) may be used, allowing for
corporate password policies to be applied. For back-end accounts, two-factor authentication is used.
Data Segregation
The UC-ENGINE segregates data as follows.
Cloud Storage
All data stored in the cloud is kept in a multitennant database.
Physical Protection
All physical servers are managed by Microsoft Azure in the eastern and western United States.
Authenticated remote access to servers is limited to named members of Crestron's engineering and
operations teams. Access to business premises containing servers is managed by Microsoft Azure.
Access to Crestron facilities is limited to invited guests and employees with badge access.
Audit Logging
Standard Windows security logging and auditing is used. Crestron applications write all security events
to text based log files on the system that can be manually audited by administrators.
Data Protection
Data transmitted via Crestron cloud-based software such as the XiO Cloud service is encrypted over
TLS 1.2 (AES 256 in transit, AES 128 at rest). The device does not sent PHI (Protected Health
Information) or PII (Personally Identifiable Information), only NPI (Non-Personal Information) such as
business contact information classified as such in the United States. Data at rest is protected with
encrypted hard disks. No data is stored on company servers.
Software development follows OWASP (Open Web Application Security Project) best practices.