Headlines refreshed Sun Oct 11, 11:45 AM ET (1 h ago) · content checked against vendor docs
⊞ Windows 11 security
Windows 11, locked down.
Windows 11 already ships with most of the protection a typical PC needs. Much of it is on by default, but it is easy to switch off by accident and hard to tell what state it is in. This guide covers each setting to check, the read-only command that shows its current state, and the official Microsoft page behind it. It applies to Windows 11 version 24H2 and later (25H2 and 26H2 are now out too). Every tip was checked against Microsoft Learn and Microsoft Support on 2026-10-11.
Confirm Microsoft Defender Antivirus is actually running
everyone
Defender is the built-in antivirus. If another antivirus product is installed or a setting was changed, Defender can quietly drop into passive mode.
Open Windows Security > Virus & threat protection. Real-time protection should be On. In PowerShell, check that RealTimeProtectionEnabled is True and AMRunningMode reads Normal.
Malware often tries to switch off antivirus before it does damage. Tamper protection blocks changes to Defender's key settings, including changes made through the registry, and changes pushed by management tools such as Group Policy can appear to succeed but are blocked.
Windows Security > Virus & threat protection > Virus & threat protection settings > Manage settings > Tamper Protection: On. Managed fleets set it in Intune or the Defender portal so it cannot be switched off locally. The check command returns True when it is on.
Run a Microsoft Defender Offline scan when you suspect a rootkit
everyone
Some malware hides while Windows is running. An offline scan reboots into a trusted environment and scans before that malware can load.
Windows Security > Virus & threat protection > Scan options > Microsoft Defender Antivirus (offline scan). Save your work first, because the PC restarts.
Turn on Controlled folder access to slow down ransomware
power user
Controlled folder access lets only trusted apps change files in protected folders such as Documents, Pictures and Desktop. Unknown programs are blocked from encrypting them.
Windows Security > Virus & threat protection > Ransomware protection > Controlled folder access. Start in Audit mode, review the blocked-app events, allow the apps you trust, then switch to Enabled.
Deploy Attack Surface Reduction (ASR) rules in audit mode first
admin
ASR rules block common attack behaviors. Examples are Office apps spawning child processes, credential theft from LSASS, and attackers dropping vulnerable signed drivers.
Pick rules from Microsoft's reference list. Add each one in AuditMode and watch for event ID 1122 (audited detections) in Event Viewer for a few weeks. Then switch the clean rules to Enabled (block). Add-MpPreference adds rules without overwriting the ones you already have. The example below audits 'Block abuse of exploited vulnerable signed drivers'.
Use Smart App Control, which can now be turned back on without a reinstall
everyone
Smart App Control blocks malicious and untrusted apps before they run. It used to need a clean install to turn back on. Microsoft Support now says recent Windows updates let you turn it on again from the Windows Security app without one.
Windows Security > App & browser control > Smart App Control settings > On. Exceptions: S mode devices need S mode turned off and a reset, and PCs with optional diagnostic data off still need a reset or reinstall. There is no way to let one specific app through, so if an important app is blocked you may have to turn Smart App Control off. In the check command, 0 = Off, 1 = Enforce, 2 = Evaluation.
Businesses: build App Control for Business policy from the Smart App Control template
admin
Application control is one of the most effective defenses against executable malware. The Smart App Control policy ships as an example you can extend to trust your line-of-business apps.
Start from %windir%\schemas\CodeIntegrity\ExamplePolicies\SmartAppControl.xml. Remove the 'Enabled:Conditional Windows Lockdown Policy' option. Deploy in audit mode, review the CodeIntegrity events, then enforce. On enterprise-managed devices, Smart App Control switches off within 48 hours unless the user turns it on first.
Open suspicious files in Windows Sandbox, not on your real desktop
power user
Sandbox is a disposable virtual machine that the hypervisor isolates from your PC. Everything in it is deleted when you close it.
Requires Pro, Enterprise or Education (not supported on Home). Enable the 'Windows Sandbox' optional feature and reboot. Networking is ON by default. For untrusted files, use a .wsb configuration file that turns networking off and maps the folder read-only.
Turn on reputation-based protection (SmartScreen and PUA blocking)
everyone
SmartScreen warns about malicious sites and downloads. Potentially unwanted app (PUA) blocking stops adware and bundleware installers.
Windows Security > App & browser control > Reputation-based protection settings. Turn on 'Check apps and files', 'SmartScreen for Microsoft Edge', 'Potentially unwanted app blocking' and 'Phishing protection'.
A stolen laptop with an unencrypted drive gives away every file on it. On supported devices, Device Encryption turns on automatically when you first sign in with a Microsoft account or a work or school account. With a local account it does not. Check rather than assume.
Settings > Privacy & security > Device encryption (Home), or BitLocker drive encryption (Pro and up). In the check command, ProtectionStatus should read On. 'Off' means unprotected, which includes a suspended drive.
Know where your BitLocker recovery key is before you need it
everyone
Firmware updates, TPM resets or hardware changes can trigger a recovery prompt. Without the recovery key, the data is gone.
Personal devices: sign in at aka.ms/myrecoverykey with your Microsoft account and match the key ID. Work devices: the key should be backed up to Entra ID or AD. Print a copy and store it offline. The check command shows the protectors, including the recovery password, so run it privately.
Turn BitLocker on with a recovery password from the command line
admin
Scripted enablement keeps a whole fleet consistent and makes sure a recovery protector exists before encryption starts.
From an elevated prompt, turn on BitLocker for the OS drive and add a recovery password protector in one step. Back up the key to Entra ID or AD before you walk away. Use XTS-AES 256 if your policy requires it.
BIOS updates often suspend BitLocker for a reboot or two. While it is suspended, the encryption key sits on the disk as an unprotected 'clear key', so anyone with the drive can read it.
After firmware work, confirm ProtectionStatus is On (a suspended drive reads Off). If not, resume it.
Sign in with Windows Hello (PIN, face or fingerprint) instead of a password
everyone
Windows Hello credentials are generated inside the device's TPM, and the PIN never leaves the device. Windows Hello has built-in brute-force protection, so a PIN is not a weaker choice than a password.
Settings > Accounts > Sign-in options. Set up a PIN, plus Facial recognition or Fingerprint if your hardware supports it.
Passkeys are phishing-resistant. The private key never leaves your device, and it only works on the real site it was made for.
When a site offers 'create a passkey', save it to Windows Hello. Starting in Windows 11 24H2, Windows asks for your consent before an app can use passkeys. Review or change which apps are allowed in Settings > Privacy & security > Passkey access.
Turn on Administrator protection (new, off by default)
power user
Your admin account normally runs with a reduced token. With Administrator protection, each elevation needs Windows Hello approval and runs under a separate, hidden admin profile whose token is thrown away afterward. Malware can no longer silently gain admin rights.
It became available with update KB5120998 and is off by default. Use Windows Security > Account protection > Administrator protection (rolling out gradually), or the policy 'User Account Control: Configure type of Admin Approval Mode' = 'Admin Approval Mode with Administrator protection'. Restart afterward. Don't use it on Windows 365 Cloud PCs, Azure Virtual Desktop session hosts, or devices that need Hyper-V.
Most malware needs admin rights to dig in. A standard user account removes that by default and costs nothing.
Create a separate admin account for installs. Change your everyday account to Standard in Settings > Accounts > Other users. Elevate only when a prompt asks. If the check command prints a line, your account is in the local Administrators group.
Confirm Credential Guard is running on business machines
admin
Credential Guard keeps NTLM hashes and Kerberos tickets in an isolated, virtualization-protected process. That blocks pass-the-hash and pass-the-ticket theft.
It is on by default on domain-joined Windows 11 22H2+ devices that meet the license and hardware requirements. Enterprise and Education support it; Pro does not. In the check command, an output containing 1 means Credential Guard is running. Test apps first: NTLMv1 single sign-on, Kerberos DES and unconstrained delegation stop working.
LSA protection stops unprotected processes from reading LSASS memory or injecting code into it. That is where credential-dumping tools go.
Windows Security > Device security > Core isolation details > Local Security Authority protection: On, then restart. Admins can set RunAsPPL to 2 (no UEFI lock) or 1 (UEFI lock); this is enforced on Windows 11 22H2 and later. Before enforcing on a fleet, audit plug-ins and drivers first and look for CodeIntegrity events 3065 and 3066.
The same local admin password on every PC means one stolen hash opens them all. Windows LAPS is built into Windows. It sets a unique, rotating password per device and backs it up to Entra ID or AD.
Configure the LAPS policy (backup directory, password age, complexity) through Intune or GPO. Read passwords with Get-LapsAADPassword (Entra) or Get-LapsADPassword (AD), and limit who has the read permission. Reset-LapsPassword forces an immediate rotation.
Sudo (Windows 11 24H2+) lets you elevate one command from a normal terminal, so you don't keep an admin shell open. Microsoft warns it can become a privilege-escalation path in some configurations. The default mode runs the elevated command in a new window; 'Inline' mode is the most convenient but carries the most risk.
Settings > System > Advanced > Enable sudo. Keep 'In a new window' (forceNewWindow), the default, unless you understand the inline risks. To set the mode from the command line, run the change command from an elevated prompt.
Memory integrity uses the hypervisor to check kernel-mode code before it runs. That blocks many driver-based and kernel exploits. It is on by default on most new Windows 11 devices.
Windows Security > Device security > Core isolation details > Memory integrity: On, then restart. If an incompatible driver blocks it, update or remove that driver rather than leaving the feature off. In the check command, an output containing 2 means memory integrity is running.
Attackers load legitimately signed but vulnerable drivers to get kernel access ('bring your own vulnerable driver'). The blocklist stops known bad ones. It has been on by default since the Windows 11 2022 update. Microsoft updates the list quarterly and ships it in the monthly Windows updates.
Windows Security > Device security > Core isolation details > Microsoft Vulnerable Driver Blocklist: On. It is forced on when Memory integrity, Smart App Control or S mode is on. Admins who want the newest list can deploy Microsoft's downloadable blocklist through App Control for Business. Also turn on the ASR rule 'Block abuse of exploited vulnerable signed drivers'.
Confirm Secure Boot is on and has the 2023 certificates
power user
The original 2011 Secure Boot certificates began expiring in June 2026. PCs without the 2023 certificates still boot and still get normal Windows updates, but they can no longer receive new security protections for the early boot process.
Check that Secure Boot is on. Then check whether the 'Windows UEFI CA 2023' certificate is in the db. Install pending Windows updates and any OEM firmware update. Most devices get the new certificates automatically. Run the check command from an elevated PowerShell.
Check — read-only
Confirm-SecureBootUEFI; [System.Text.Encoding]::ASCII.GetString((Get-SecureBootUEFI db).bytes) -match 'Windows UEFI CA 2023'
Check the overall hardware security level in one place
everyone
Windows Security's Device security page summarizes core isolation, the security processor (TPM), Secure Boot and data encryption. It is a quick way to see whether the hardware protections are actually active.
Windows Security > Device security. Read the Hardware security capability line at the bottom, and open each card that shows a warning. The check command reports the TPM state from an elevated PowerShell.
The firewall blocks unsolicited inbound connections. Turning it off 'just to test' and forgetting is one of the most common misconfigurations.
Windows Security > Firewall & network protection. Domain, Private and Public should all read 'Firewall is on'. Mark café and hotel Wi-Fi as a Public network.
Network protection extends SmartScreen-style blocking to every app, not just Edge. It stops connections to known phishing, malware and command-and-control hosts.
From an elevated PowerShell, start in AuditMode, review the events, then set Enabled (block mode). Managed fleets configure it in Intune endpoint security.
Manage business updates with Windows Update client policies (formerly Windows Update for Business)
admin
Microsoft renamed 'Windows Update for Business' to 'Windows Update client policies'. The policies let you ring updates, set deferrals and enforce deadlines without running WSUS.
Through GPO or Intune, set quality-update deferrals (max 30 days), feature-update deferrals (max 365 days) and compliance deadlines. Pausing is limited to 35 days. Use Windows Autopatch on top of these policies if you want Microsoft to orchestrate the rings.
Browsers, PDF readers, runtimes and archivers are attacked as often as Windows is. winget (Windows Package Manager) can list and update most of them in one step.
Run 'winget upgrade' to list available updates, which changes nothing. Run 'winget upgrade --all' to install them. Install new software with 'winget install' from the default sources instead of random download sites.
Compare your settings to the Microsoft Security Baseline
admin
Microsoft publishes a tested baseline for each Windows release. The Security Compliance Toolkit currently includes Windows 11 v24H2, v25H2 and v26H2 baselines. It is the fastest way to find settings that differ from Microsoft's recommendations.
Download the Security Compliance Toolkit. Unzip the baseline for your Windows 11 version and Policy Analyzer. Use Policy Analyzer to compare your GPOs or local policy against the baseline. Apply it with GPO or Intune security baselines after testing.
Audit a single machine with HardeningKitty (audit mode only)
power user
HardeningKitty scores a PC against curated finding lists, including Microsoft baselines and CIS-style lists, and writes a CSV report. Audit mode only reads settings.
Install the module from the project's GitHub. Run Audit mode from an elevated PowerShell and read the report. HailMary mode WRITES settings and can break systems; its built-in backup is not a full system backup, so take an image first. The project was written for English Windows, and results may be wrong in other languages.
Sysmon records process creation with full command lines, network connections, driver loads, process access and more in the Windows event log. That gives you the detail to investigate an incident.
Download Sysmon from Sysinternals and install it with a filtered configuration file. Events land in Applications and Services Logs > Microsoft > Windows > Sysmon > Operational. Forward them to your SIEM.
Persistence is how malware survives a reboot. Autoruns shows every auto-start location (Run keys, services, scheduled tasks, drivers, WMI and more) in one view.
Run Autoruns as administrator. Use the 'Hide Signed Microsoft Entries' option to focus on third-party items, and check VirusTotal results for anything unfamiliar. Uncheck an entry rather than deleting it until you're sure. The command-line version (check command) lists all entries as CSV with hashes and signature checks, hiding Microsoft entries.
Inspect suspicious processes with Process Explorer
power user
Task Manager hides a lot. Process Explorer shows parent/child process trees, loaded DLLs and open handles, which makes an odd process much easier to trace.
Run as administrator. Turn on signature verification and VirusTotal checks from the Options menu. Unsigned processes running from user-writable folders deserve a closer look.
With Administrator protection on, elevations are logged as ETW events. Event 15031 records an approved elevation and 15032 a denied, failed or timed-out one. That gives you an audit trail of who ran what as admin.
Enable the Microsoft-Windows-LUA ETW provider (GUID {93c05d69-51a3-485e-877f-1806a8731346}) with logman or WPR. Filter on event IDs 15031 and 15032, and open the .etl file in Windows Performance Analyzer.
Follow CISA's Known Exploited Vulnerabilities list for Windows
admin
KEV lists the CVEs that attackers are actively exploiting. Patching those first is the highest-value move when you can't patch everything at once.
Filter the KEV catalog for vendor 'Microsoft' and product 'Windows'. Compare it to your patch status. Each entry carries a remediation due date; treat it as a priority guide.