Table of contents
Collapse the table of content
Expand the table of content

Keep Windows 10 secure

Brian Lich|Last Updated: 1/31/2017
4 Contributors

Learn about keeping Windows 10 and Windows 10 Mobile secure.

In this section

Block untrusted fonts in an enterpriseTo help protect your company from attacks which may originate from untrusted or attacker controlled font files, we’ve created the Blocking Untrusted Fonts feature. Using this feature, you can turn on a global setting that stops your employees from loading untrusted fonts processed using the Graphics Device Interface (GDI) onto your network. Untrusted fonts are any font installed outside of the %windir%/Fonts directory. Blocking untrusted fonts helps prevent both remote (web-based or email-based) and local EOP attacks that can happen during the font file-parsing process.
Windows Hello for BusinessIn Windows 10, Windows Hello replaces passwords with strong two-factor authentication on PCs and mobile devices. This authentication consists of a new type of user credential that is tied to a device and a biometric or PIN.
Configure S/MIME for Windows 10 and Windows 10 MobileIn Windows 10, S/MIME lets users encrypt outgoing messages and attachments so that only intended recipients who have a digital identification (ID), also known as a certificate, can read them. Users can digitally sign a message, which provides the recipients with a way to verify the identity of the sender and that the message hasn't been tampered with.
Install digital certificates on Windows 10 MobileDigital certificates bind the identity of a user or computer to a pair of keys that can be used to encrypt and sign digital information. Certificates are issued by a certification authority (CA) that vouches for the identity of the certificate holder, and they enable secure client communications with websites and services.
Device Guard deployment guideDevice Guard is a combination of hardware and software security features that, when configured together, will lock a device down so that it can only run trusted applications. If the app isn’t trusted it can’t run, period. It also means that even if an attacker manages to get control of the Windows kernel, he or she will be much less likely to be able to run malicious executable code after the computer restarts because of how decisions are made about what can run and when.
Protect derived domain credentials with Credential GuardIntroduced in Windows 10 Enterprise, Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Unauthorized access to these secrets can lead to credential theft attacks, such as Pass-the-Hash or Pass-The-Ticket. Credential Guard helps prevent these attacks by protecting NTLM password hashes and Kerberos Ticket Granting Tickets.
Protect Remote Desktop credentials with Remote Credential GuardRemote Credential Guard helps you protect your credentials over a Remote Desktop connection by redirecting the Kerberos requests back to the device that's requesting the connection.
Protect your enterprise data using Windows Information Protection (WIP)With the increase of employee-owned devices in the enterprise, there’s also an increasing risk of accidental data leak through apps and services, like email, social media, and the public cloud, which are outside of the enterprise’s control. Windows Information Protection (WIP), previously known as enterprise data protection (EDP), helps to protect against this potential data leakage without otherwise interfering with the employee experience.
Use Windows Event Forwarding to help with intrusion detectionLearn about an approach to collect events from devices in your organization. This article talks about events in both normal operations and when an intrusion is suspected.
Override Process Mitigation Options to help enforce app-related security policiesUse Group Policy to override individual Process Mitigation Options settings and help to enforce specific app-related security policies.
VPN technical guideVirtual private networks (VPN) let you give your users secure remote access to your company network. Windows 10 adds useful new VPN profile options to help you manage how users connect.
Windows security baselinesLearn why you should use security baselines in your organization.
Security technologiesLearn more about the different security technologies that are available in Windows 10 and Windows 10 Mobile. For example, learn about AppLocker, BitLocker, and Security auditing.
Enterprise security guidesReview technology overviews that help you understand Windows 10 security technologies in the context of the enterprise.
Change history for Keep Windows 10 secureThis topic lists new and updated topics in the Keep Windows 10 secure documentation for Windows 10 and Windows 10 Mobile.

Windows 10 and Windows 10 Mobile

© 2017 Microsoft