Security baseline for Windows 10 “Creators Update” (v1703) – DRAFT

Discussion in 'other security issues & news' started by WildByDesign, Jun 15, 2017.

  1. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Security baseline for Windows 10 “Creators Update” (v1703) – DRAFT

    Link: https://blogs.technet.microsoft.com...e-for-windows-10-creators-update-v1703-draft/


    Two interesting takeaways initially, though I am still reviewing the changes:

    • Exposing two more settings through the custom “MS Security Guide” ADMX to enforce protections for 32-bit processes and to “Turn on Windows Defender protection against Potentially Unwanted Applications.”
    • Setting to enforce SEHOP on all 32-bit apps. (64-bit apps already enforced by default)
    • Removing the “Untrusted Font Blocking” setting. We discuss the reasons for this change here.
     
    Last edited: Jun 15, 2017
  2. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    None of the links are working for me. Are they working for you?
     
  3. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Another interesting note is that these policies provided make it easier to apply LSA Protection (running lsass.exe as protected process-light).

    Also for disabling SMBv1 quick and easy.
     
  4. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    @Trooper My apologies, I forgot to add the main blog post to the first post. I've added main link at the top of my first post now. Sorry about that.
     
  5. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    This one in particular was a welcome read for me. Heaven knows that the always available potential and carried out disruptions through the way the font issue was made by default is plagued all earlier versions so this new approach taken must also be a relief for them from that albatross.
     
  6. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,508
    Not a problem! Thank you for posting this!
     
  7. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,440
    Location:
    Slovakia
    So simply put, just keep it on. They are recommending to disable it, because Microsoft webpages are using untrusted fonts. :argh:
     
  8. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Sure seems that way
     
  9. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Security baseline for Windows 10 “Creators Update” (v1703) – FINAL

    Link: https://blogs.technet.microsoft.com...e-for-windows-10-creators-update-v1703-final/

    The differences in this baseline from the v1703 draft version are:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.