Windows 10

Windows 10 Endpoint Security Matrix

Posted on Updated on

Microsoft has a good matrix and comparison chart of the security product features built-in with Windows 10 Professional and Enterprise.  Along with that matrix is a downloadable full comparison chart. What I really like about that full chart is that it compares Pro vs. Enterprise as a security function and capability, not just as a product name.  Recently, I was asked if I could map the capability to the product name.  As best as I could, below is the table that I created which marries those two by mapping the functionality to the product.  Minus the licensing portion (Pro vs. Enterprise E3 vs. Enterprise E5) that is.


Product feature(s)

Attack Surface Reduction controls
Integrity enforcement of operating system boot up process System Guard
Integrity enforcement of sensitive operating system components System Guard
Advanced vulnerability and zero-day exploit mitigations Exploit Guard + WDAV
Reputation based network protection for Microsoft Edge, Internet Explorer and Chrome SmartScreen
Host based firewall Firewall
Ransomware mitigations Exploit Guard + WDAV (with controlled folder access)
Hardware based isolation for Microsoft Edge Application Guard
Application control powered by the Intelligent Security Graph Application Control
Device Control (e.g.: USB) Exploit Guard (hypervisor code integrity), MDATP (additional security)
Network protection for web-based threats Exploit Guard
Enterprise management of hardware-based isolation for Microsoft Edge Application Guard enterprise controls defined for internal/external sites
Host intrusion prevention rules Exploit Guard (HIPS)
Customizable allow/deny lists (e.g.: IP/URL, Files, Certificates) Exploit Gard (network protection) using MDATP
Device-based conditional access MDATP integration with Intune device management
Centrally manageable tamper protection of operating system MDATP
Next Generation Protection
Pre-execution emulation executables and scripts WDAV
Runtime behavior monitoring WDAV
In memory anomaly and behavior monitoring WDAV + Exploit Guard
Machine learning and AI based protection from viruses and malware threats WDAV
Cloud protection for fastest responses to new/unknown webbased threats WDAV (block at first sight)
Protection from fileless based attacks WDAV + Exploit Guard
Advanced machine learning and AI based protection for apex level viruses and malware threats WDAV + MDATP
Advanced cloud protection that includes deep inspection and detonation MDATP
Emergency outbreak protection from the Intelligent Security Graph WDAV + MDATP
Monitoring, analytics and reporting for Next Generation Protection capabilities WDAV + MDATP
Endpoint Detection and Response
Behavioral-based detection for advanced and targeted attacks (post-breach) MDATP
Centralized security operations management with Windows Defender Security Center MDATP
Rich investigation tools MDATP
Forensic collection MDATP
Response actions MDATP
Advanced detonation service with deep file analysis MDATP
Upload of Indicators of Compromise (IOC) for custom alerts MDATP
Flexible hunting queries over historical data MDATP
Custom alerts via powerful advanced hunting queries MDATP
Discover and report SaaS app usage to MCAS MDATP
Machine risk level to trigger conditional access MDATP
Monitoring, analytics and reporting MDATP
Automatic Investigation and Remediation
Automated alert investigations using Artificial Intelligence MDATP
Automated remediation of advanced threats MDATP
Monitoring, analytics and reporting MDATP
Security Score
Assess and improve your organization security posture using Microsoft Secure Score for Windows MDATP
Threat Analytics shows your organizations exposure to threats MDATP
Security Management
Monitoring, analytics and reporting MDATP
Rich Power BI dashboards and reports MDATP
Enterprise-grade Extensibility and Compliance
Integrated endpoint protection for 3rd party platforms (macOS,Linux, iOS, Android) MDATP (Note that Microsoft now has a client for macOS)
Open Graph APIs to integrate with your solutions MDATP
Integration with Microsoft Advanced Threat Protection (ATP) products MDATP
ISO 27001 compliance MDATP
Geolocation and sovereignty of sample data MDATP
Sample data retention policy MDATP
Multi Factor and password-less Authentication
Industry standards based multifactor authentication Windows Hello for Business
Support for biometrics (Facial and Fingerprints) Windows Hello for Business
Support for Microsoft Authenticator Windows Hello for Business
Support for Microsoft compatible security key Windows Hello for Business
Supports for Active Directory and Azure Active Directory Windows Hello for Business
Credential Protection
Hardware isolation of single sign-in tokens Credential Guard
Centralized management, analytics, reporting, and operations Credential Guard + MDATP
Full Volume Encryption
Automatic encryption on capable devices Win10
Advanced encryption configuration options BitLocker
Removable storage protection BitLocker to Go
Direct Access & Always On VPN device Tunnel Win10
Centralized configuration mgmt, analytics, reporting, and security operations MBAM (standalone, SCCM, Intune, MEM) + MDATP
Data Loss Prevention
Personal and business data separation Windows Information Protection
Application access control Windows Information Protection
Copy and paste protection Windows Information Protection
Removable storage protection Windows Information Protection
Integration with Microsoft Information Protection Windows Information Protection

Getting Help and Support for the Microsoft Store for Business

Posted on

Are you looking to get some help and support with the Microsoft Store for Business?  One route that you can go through is directly in the business store portal (  Just as seen in the image below.


Windows 10 News You Can Use – August 2019

Posted on

Win10NewsLogo Windows 10 news you can use, August 2019 edition
Insights into Windows 10 deployment & management, security & compliance, and productivity & accessibility.
Also see other news related to Windows 10.


Deployment & Management
  1. Evolving Windows 10 servicing and quality: the next steps. As part of our commitment to transparency, we are providing an overview of how we plan to further optimize the delivery of our next feature update. The next feature update for Windows 10 (known in the Windows Insider Program as 19H2) will be a scoped set of features for select performance improvements, enterprise features and quality enhancements.
  2. The next feature update for Windows 10 (internal code name: 19H2) will have a new update option that will be available to devices running Windows 10, version 1903. 19H2 will be a scoped release with a smaller set of enhancements focused primarily on select performance improvements, enterprise features, and quality enhancements. For commercial customers, read the article to understand the impacts.
  3. Windows Autopilot for existing devices now supports Hybrid Azure AD Join.
  4. Improving the Office app experience in virtual environments, including Windows 10 VDI and Windows Virtual Desktop.
  5. Use Desktop Analytics and machine learning to get current and stay current, now available in public preview. With Desktop Analytics, it’s easier to deploy with confidence and keep your PCs up to date with the latest Windows 10 capabilities your employees need.
  6. The blog for Windows Analytics has been retired. Visit the new Tech Community site for Desktop Analytics!
  7. Guide to try out Windows Autopilot white glove pre-provisioning with Windows 10, version 1903.
  8. MSIX Packaging Tool update – the July 2019 release includes popular customer asks, such as (1) support for apps that require restarts, (2) signing certification information as a global setting, and (3) setting the minimum version for converted apps to 1709 when you turn off enforce store versioning requirements.
  9. Getting started with FSLogix profile containers on Azure Files in Windows Virtual Desktop.
  10. Tactical considerations for creating Windows 10 deployment rings.
  11. Microsoft Intune is excited to announce the general availability of administrative templates support for Windows 10 device configuration profiles. This feature received wide adoption during the public preview because it helps Windows administrators use the settings they are familiar with in group policy editor when they transition to cloud-attached management.
  12. The Microsoft Mechanics team has published a series of video tutorials to show you how to prepare, deploy, and optimize Windows Virtual Desktop.
  13. Administrative Templates (.admx) for Windows 10 May 2019 Update (1903) now available.
  14. MSIX Labs and Training Videos – Now Available! The MSIX Training Labs contain a series of hands-on exercises geared at enabling people to become more familiar with different aspects of MSIX. From the MSIX packaging tool, to adding a package support framework, or just becoming familiar with some of the command line tools, the labs are a great place to get started for folks looking to learn more about MSIX.
  15. Upgrading Windows 10 devices with installation media different than the original OS install language. In this post, we will look at a scenario where a hypothetical multilingual organization wants to deploy Windows 10 to devices across multiple geographies in multiple languages. We’ll then outline the options that can be used to work around device install language issues and successfully deploy a Windows 10 feature update.
  16. Improvements for enterprises signing MSIX packages (Insider Preview). MSIX requires packages to be signed in order to be deployed. This helps us to offer integrity on the package being deployed and to ensure the contents being deployed are what was packaged from the developer or IT Pro.  While this is great, some customers found it problematic acquiring certificates within their enterprise.  In an upcoming Windows release will improve the tooling to enable signing of MSIX packages from your Azure Active Directory tenant.
Security & Compliance
  1. Microsoft Defender ATP alert categories are now aligned with MITRE ATT&CK framework tactics.
  2. Delivering major enhancements in Windows Defender Application Control with the Windows 10 v1903.
  3. Dismantling a fileless campaign: Microsoft Defender ATP next-gen protection exposes Astaroth attack.
  4. Microsoft Intune is excited to announce general availability of Windows MDM Security Baselines. A new version of security baselines is also being released at the same time, identified as MDM Security Baseline for Spring 2019 Update (19H1). This is a new template that includes several new settings and some other updates.
  5. Upgrading Windows 10 devices with installation media different than the original OS install language. In this post, we will look at a scenario where a hypothetical multilingual organization wants to deploy Windows 10 to devices across multiple geographies in multiple languages. We’ll then outline the options that you can use to work around device install language issues and successfully deploy a Windows 10 feature update.
  6. Microsoft Defender ATP (MDATP) supports network connection monitoring from different levels of the operating system network stack. A challenging case is when the network uses a forward proxy as a gateway to the internet. The proxy acts as if it was the target endpoint. In these cases, simple network connection monitors will audit the connections with the proxy which is correct but has lower investigation value. MDATP supports advanced HTTP level sensor. By enabling this sensor, MDATP will expose a new type of events that surfaces the real target domain names.
  7. Comprehensive protection for your credentials with Credential Guard and HVCI. The goal of Windows Defender Credential Guard is to make it incredibly difficult for malware to move laterally in an enterprise network and gain higher privileges. The theory is simple: prevent malware from stealing passwords, hopping boxes, and elevating privileges. An attacker is dead in the water if they can’t get credentials in the first place.
  8. Yet another step in building a world without passwords. Now announcing that you can go passwordless with the Public Preview of FIDO2 security keys support in Azure Active Directory. It means that you can now try out passwordless capabilities that allow you to roll out, at scale, FIDO2 security keys that will authenticate a user on a Windows 10 Azure AD joined device.
  9. Oftentimes, organizations require better control over their raw data. To answer this need, Microsoft Defender Advanced Threat Protection (MDATP) allows you to stream Advanced hunting events to Azure Event Hubs or to an Azure storage account. In this blog, I am going to demonstrate how to stream your Advanced hunting events to Azure storage account and set an Azure blob storage lifecycle rule to move old data to low-cost storage.
  10. Microsoft Defender ATP (MDATP) Evaluation lab is now available in public preview! The evaluation lab allows you to create up to three machines with a click of a button. Each machine is provisioned for you by Microsoft Defender ATP and is available for all your testing needs for three days. They’ll come with the latest and greatest Windows 10 installed, they’ll be onboarded to your environment, and configured with all the Microsoft security baseline settings in place in audit mode.
  11. Most machine learning models are trained on a mix of malicious and clean features. Attackers routinely try to throw these models off balance by stuffing clean features into malware. Monotonic models are resistant against adversarial attacks because they are trained differently: they only look for malicious features. The magic is this: Attackers can’t evade a monotonic model by adding clean features. To evade a monotonic model, an attacker would have to remove malicious features. One of the latest innovations in our protection technology is the addition of a class of hardened malware detection machine learning models called monotonic models to Microsoft Defender ATP‘s Antivirus.
  12. Protect your device from malware with Windows Sandbox. Have you ever downloaded a program from a website or opened an email attachment thinking it was from someone you know, only to find out it was infected with a virus? Such actions can wreak serious havoc. Windows Sandbox allows you to run a program or open a file while keeping it apart from your device—almost as if it were on a totally separate computer.
  13. Modern security teams need to proactively, efficiently, and effectively hunt for threats across multiple attack vectors. To address this need, we’re giving a glimpse of new capabilities coming soon to threat hunting technology currently available in Microsoft Defender Advanced Threat Protection (MDATP).
  14. How Windows Defender Antivirus integrates hardware-based system integrity for informed, extensive endpoint protection. Recently, the Microsoft Defender ATP (MDATP) research team found a malicious system driver enabling a token swap attack that could lead to privilege escalation. In this blog, we’ll share our analysis of the said attack and discuss how Windows Defender Antivirus uses its unique visibility into system behaviors to detect dangerous kernel threats.
  15. Microsoft Defender ATP (MDATP) includes a sandbox in each customer tenant, to detonate files in a safe environment and provides a rich and readable report of what the file can do – gain persistence, communicate to IP addresses, change the registry, etc… but in some case you want to run such analyses in your own sandbox or do reverse engineering work, with MDATP you can now download and inspect any file found on your network.
Productivity & Accessibility
  1. Video (0:58) – It’s easy to forget what we were working on, especially when it was days or weeks ago. Timeline for Windows 10 PCs helps you jump back into something you were doing – like working on a document or browsing a website.
  2. Sync your settings in Windows 10 allows some of the common personalization preferences to be synced to the cloud and applied to any PC you sign in to with your Microsoft account. By letting Windows 10 sync your settings, you can have a more consistent experience no matter which device you happen to be using.
  3. Windows 10 Tip: Your Phone app gives you more to do with messages and photos.
  4. Video (1:52) – Microsoft is moving past old ideas of sound design and designing sound with all senses in mind. Recognizing the way sound moves us, emotionally and physically, we are taking a different path to designing for sound holistically.
  5. Thanks to the Windows 10 May 2019 Update, you’ll be able to take full advantage of the newest version of the Sticky Notes app. With this most recent version, you can sync and backup notes across your phone, laptop and desktop — all your devices.
  6. Video (2:17) – Windows 101: Four simple ways to switch between Windows apps.
  7. Video (0:43) – Introduction to Dictation in Windows 10.Use dictation to convert spoken words into text anywhere on your PC. Dictation uses speech recognition, which is built into Windows 10, so there’s nothing you need to download or install to use it.
  8. Video (2:04) – Making the mouse pointers easier to see. These new settings aren’t just for users with low vision, learn the different ways you can use these settings.
  9. Windows 10 Tip: The release of Emoji version 12.0 aims to better represent people with disabilities. You’ll now see mechanical limbs, sign language and hearing aids; as well as manual and motorized wheelchairs and two different versions of service animals.
  10. Capture and share videos with Game bar. Did you know that you could do more than just gaming? Videos are everywhere. We watch them for instruction and entertainment. With Windows 10, it has become super easy to take screenshots of your screen using the Snip & Sketch tool. But what if you want to record live video action? Game bar can do that too.
In other news related to Windows 10…

Windows 10 news you can use, July 2019

Posted on


Win10NewsLogo Windows 10 news you can use, July 2019 edition. Insights into Windows 10 deployment & management, security & compliance, and productivity & accessibility.


Deployment & Management
  1. Microsoft is often asked to help customers choose between Windows 10 Enterprise or Windows 10 Pro. Specifically to clarify the differences between the two editions, and the impact those differences might have to your organization. With that in mind, we decided to take a closer look at these conversations—and the key considerations when it comes to deciding between Windows 10 Enterprise and Windows 10 Pro for your organization—by talking with Nick and Shawn, two technical specialists focusing in Windows deployments.
  2. Webinar (59:52) – experts at Microsoft Core Services Engineering and Operations answered questions about their modern desktop and device management. They discussed the processes and tools used to support a wide range of scenarios as well as the use of Intune, SCCM, WUfB, Azure AD, and transition to modern management.
  3. Video (10:19) – A lot has evolved since the Windows Virtual Desktop (WVD) preview kicked off in March 2019. In this episode we review the progress the team has made to create a much easier Azure portal experience to setup and manage your WVD Host Pools.
  4. Video (1:05) – Will the new chromium-based Microsoft Edge still be connected to Windows updates? Chris Heilmann talks about how Microsoft Edge updates will be delivered going forward.–One-Dev-Question
Security & Compliance
  1. Video (58:40) – In today’s world, device health is a pillar of security. Unmanaged devices are a powerful entry point for malicious parties, and it is vital that only healthy devices can access critical apps and data. Learn about device health, device security at Microsoft, and key investment areas Microsoft are pursuing.
  2. Microsoft’s vision for Windows is one of a passwordless platform—a world where users don’t have to deal with the pains of a password. With the release of Windows 10, version 1903, we’re bringing Windows 10 closer to delivering our passwordless user and security promises, with new features that we’re excited for you to try.
  3. New documentation for building secure, privileged access workstations! Secured isolated workstations are critically important for the security of sensitive roles like administrators, developers, and operators of critical services. Build a secure client workstation with these detailed step by step instructions, including how to set up starting security controls.
  4. When hardening your deployment of Windows 10, how should you prioritize the hardware you buy, policies you enforce, controls you configure, and behavior your staff exhibit? To help you prioritize your endpoint hardening work, Microsoft is introducing a new taxonomy for security configurations for Windows 10.
  5. Beginning with Configuration Manager 1905 TP, you can install and manage the MBAM
  6. Inside out: Get to know the advanced technologies at the core of Microsoft Defender ATP next generation protection. Much like how MDATP integrates multiple capabilities to address the complex security challenges in modern enterprises, Windows Defender AV next-generation protection engines provide industry-best detection and blocking capabilities.
  7. The evolution of Microsoft Threat Protection, June update. Game-changing capabilities for endpoint security with Microsoft Defender ATP (MDATP): protections for macOS, live response (new incident response action for SecOps teams), and how to try out the live response feature.
Productivity & Accessibility
  1. Join us as we interview Windows enthusiasts around the world to hear how they’re putting Windows to work.
  2. Microsoft Edge Experiment: Battery Life | Windows 10 May 2019 Update.
  3. Video (0:18) on how to quickly share files with another PC during meetings.
  4. Video (3:43) on how wireless projection works in Windows 10.
  5. At Microsoft, we’re on a journey to empower every person on the planet, including people with disabilities, to achieve more. What’s new in the Windows 10 May 2019 Update for accessibility.
  6. New Windows 10 users – those who have new devices, new user accounts and clean installs – will see the new, greatly simplified, Start layout by default when they start up.
  7. Video (4:06) – Remember the small things with Microsoft Sticky Notes. This app makes it easy to unclutter your desktop and sync your notes securely across your devices, so you can access them on any device.
  8. Control the action with your eyes on Windows 10 PCs through four new games.
  9. Windows 10 Tip: light theme with the Windows 10 May 2019 Update.
  10. Video (2:53) – Volume conversions using the Calculator app.
  11. Easier navigation with Windows 10 tablet mode. Using Tablet mode in Windows 10 can make it easier to browse the web and it can also free up room on your screen. But it isn’t just for touchscreen devices. This article will go over how to enter/exit Tablet mode followed by an overview of the information needed to navigate it.
  12. Check out the most recent and greatest Edge features. From being able to mute tabs, to clutter-free printing, to various grammar tools.
In other news related to Windows 10…

Windows 10 News You Can Use – June 2019

Posted on

Win10NewsLogo Windows 10 news you can use, June 2019 edition

Providing insights into Windows 10 deployment & management, security & compliance, and productivity. Also see other news related to Windows 10.

What’s new in Windows 10, version 1903, and how to get it.

Calling all IT professionals! Join Microsoft on Tuesday, June 4th for a chance to get your questions about Windows 10 deployment, security, update management, device management, and productivity—and the latest Windows 10 feature update (1903)—answered by the experts behind the Windows 10 features and solutions built for IT.

Deployment & Management
  1. Deployment rings: The hidden [strategic] gem of Windows as a service. In speaking with customers who have successfully changed their internal IT culture by moving from project to process, we’ve learned that one of the keys to a successful, more self-service, peer-support-driven model is to create deployment rings for Windows 10 feature updates, and the adoption and use of data driven insights and analysis, in conjunction with the deployment rings.
  2. Webcast Thursday 6/6/19: All you need to know about Windows Virtual Desktop.
  3. Ask Microsoft Anything event 6/12/19: Windows Virtual Desktop.
  4. All the news from Build 2019 on Microsoft Edge: A first look at new productivity concepts, privacy tools, and Internet Explorer mode for seamless enterprise compatibility.
  5. Video (0:50) introducing the future of Microsoft Edge.
  6. Microsoft Mechanics video (17:51) stay ahead of Windows and Office deployments and updates with SCCM. See what’s new, get an explanation on your desktop deployment options, and hear about proven guidance for automating the process to move forward from older versions of Windows and Office. Microsoft 365 Director Jeremy Chapman runs it all down – from app delivery updates, to networking enhancements, deeper tool integration and better user experiences.
  7. Video (30:40) in this really demo heave episode of The Endpoint Zone with Brad Anderson we look at when to use ConfigMgr and/or Intune and why co-management is a unique thing, that only Intune and ConfigMgr can do to manage Windows 10. Plus, why you would use them over other UEM solutions.
  8. Video (6:42) a Microsoft Mechanics look at the new Windows Autopilot capability called white glove in Windows 10 1903. Also, the latest Windows 10 Autopilot features that we’ve delivered in Windows 10 1809 and beyond.
  9. Increasing transparency: the Windows health dashboard. As part of our commitment to increasing transparency, the new Windows release health dashboard is now live, offering timely information on the current rollout status and known issues (open and resolved) across both feature and monthly updates. The new dashboard provides a single page for each currently supported version of Windows so you can quickly search for issues by keyword, including any safeguard holds on updates, see the current status of each issue, and find important announcements. Watch this video (3:43) introducing the new Windows release health dashboard.
  10. Starting with Windows 10, version 1903, devices utilizing the Update Compliance analytics service can now determine which of their managed devices are not receiving a feature update due to a hardware or software compatibility issue identified by Microsoft.
Security & Compliance
  1. Microsoft is excited to announce enhancements to BitLocker management capabilities in both Microsoft Intune and System Center Configuration Manager (SCCM), coming in the second half of 2019. Whether your management infrastructure is on-premises or in the cloud, robust BitLocker management is required for today’s enterprises to secure modern endpoints.
  2. With the release of Windows 10, version 1903, Windows Hello is a FIDO2 Certified authenticator. FIDO2 enables developers to leverage standards-based protocols and devices to provide users easy authentication to online services—in both mobile and desktop environments.
  3. Detecting credential theft through memory access modelling with Microsoft Defender ATP. MDATP, Microsoft’s unified endpoint protection platform, uses multiple approaches to detect credential dumping. In this post, we’ll discuss one of them: a statistical approach that models memory access to the Local Security Authority Subsystem Service (lsass.exe) process.
  4. Announcing the all new Attack Surface Analyzer 2.0! It can help you identify potential security risks introduced by changes to an operating system’s security configuration by identifying changes in key area.
  5. Windows 10 attack surface reduction (ASR) rules help prevent malware from infecting computers with malicious code. Some of these rules aim to reduce your attack surface while you’re using Office applications. We’re extending a few of these ASR rules to include Office 365 desktop apps from the Microsoft Store.
  6. Conducting a thorough forensic investigation of compromised machines is integral to incident response. However, it can be a challenging task because it requires the device to be in the corporate network and for additional software to be deployed, or for SecOps to have physical access to the device. That changes today, with the public preview of live response capabilities in Microsoft Defender ATP. Live response gives SecOps instantaneous access to a compromised machine regardless of location using a remote shell and gather any required forensic information.
  7. In “Step 9. Protect your OS” of the Top 10 actions to secure your environment blog series, we provide resources to help you configure Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) to defend your Windows, macOS, Linux, iOS, and Android devices from advanced threats.
  8. Windows Defender Application Guard, the hardware-based isolation technology on Windows 10 that allows Microsoft Edge to isolate browser-based attacks, is now available as a browser extension for Google Chrome and Mozilla Firefox.
  9. Announcing an update to Microsoft Defender ATP: unified indicators of compromise (IoCs) experience. We’ve unified several different IoC lists and made the lists more accessible for interactive (portal) and automated (API) use. In addition, we aligned all detection and enforcement means to honor the unified list. The new schema supports several actions such as allow, alert-only, and alert and block. It also supports RBAC for fine-grained control over user access.
  1. Although the default settings for power use will probably work fine for most people, knowing how to conserve your battery can come in handy. Read on to learn how to find your power icon, learn tips and tricks for saving your battery life, troubleshoot common scenarios, and stay in control of your power options.
  2. Windows 10 Tip: Microsoft Edge toolbar for PDF actions.
  3. Whether you’ve got your arms full of books or want to find an important document without scrolling through Search, Ease of Access dictation allows you to do it all hands-free.
  4. For IT Pros: After upgrading to Win10 Insider build #18272 or later, Windows Console (E.g. launch Cmd, PowerShell, WSL, etc.) supports zoom in-and-out features. Hit and hold CTRL while scrolling your mouse wheel / trackpad.  You’ll also notice that Console now honors your Light/Dark Theme settings: If you are using the Dark Theme, your Console’s scrollbar is also dark-themed!
  5. Windows 101: Turning on airplane mode in Windows 10.
In other news related to Windows 10…

Windows 10 News You Can Use – May 2019

Posted on Updated on

Win10NewsLogo Windows 10 news you can use, May 2019 edition

Providing insights into Windows 10 deployment & management, security & compliance, and productivity. Also see other news related to Windows 10.

The next generation of Microsoft Edge! In December, we announced our intention to adopt the Chromium open source project in the development of Microsoft Edge on the desktop. Our goal is to work with the larger Chromium open source community to create better web compatibility for our customers and less fragmentation of the web for all web developers. Today we’re embarking on the next step in this journey – our first Canary and Developer builds are ready for download on Windows 10 PCs. Canary builds are preview builds that will be updated daily, while Developer builds are preview builds that will be updated weekly. Beta builds will come online in the future. Support for Mac and all supported versions of Windows will also come over time.

Deployment & Management
  1. Introducing the Microsoft Edge Insider Channels. The new Microsoft Edge builds are available through preview channels that we call “Microsoft Edge Insider Channels.” We are starting by launching the first two Microsoft Edge Insider Channels, Canary and Dev, which you can download and try at the Microsoft Edge Insider site. These channels are available starting today on all supported versions of Windows 10, with more platforms coming soon.
  2. Windows defines two main policies, Quick removal and Better performance, that control how the system interacts with external storage devices such as USB thumb drives or Thunderbolt-enabled external drives. Beginning in Windows 10 version 1809, the default policy is Quick removal. In earlier versions of Windows, the default policy was Better performance.
  3. The benefits of Windows 10 Dynamic Update. Dynamic Update can help organizations and end users alike ensure that their Windows 10 devices have the latest feature update content (as part of an in-place upgrade)—and preserve precious features on demand (FODs) and language packs (LPs) that may have been previously installed. Further, Dynamic Update also eliminates the need to install a separate quality update as part of the in-place upgrade process. From an IT perspective, using Dynamic Update reduces the need to apply separate updates to recently installed systems and makes it easier to get your devices up to date with the latest available quality update in one step.
  4. Configuring Windows 10 defaults via Windows Autopilot using an MSI.
  5. Configuring even more Windows 10 defaults via Windows Autopilot using an MSI.
  6. Microsoft Helps video (1:30) on how to create a report of Mobile Device Manager (MDM) logs to diagnose enrollment or device management issues in Windows 10 devices managed by Intune.
  7. Microsoft Helps video (10:27) on tips to manage and deploy updates for Surface and Window 10, including allowing firmware and security updates while holding off on feature updates as your organization evaluates each new release of Windows 10. This video walks through 5 management practices: an Overview of Defer Feature Updates, Windows feature update cycle, Office and Windows Configuration Manager update cycle, security updates, and Update compatibility with apps and hardware.
  8. Microsoft Helps video (6:11) on how Windows Autopilot can transform how you deploy Surface and Windows 10 devices in your organization. Windows Autopilot set ups and pre-configures new devices, getting them ready to use. You can also use Windows Autopilot to reset, repurpose and recover devices. We’ll cover how it works as well as the user experience once they receive the device. Content includes: traditional vs. modern deployment, how Autopilot works, and setting up a device.
Security & Compliance
  1. Microsoft Defender ATP built-in threat summary and health reports. The threat protection reporting dashboard provides alert information over time, as well as aggregated threat protection views. Knowing the trends and summaries in your organization can help identify where focused improvements can be made.
  2. Third-party kernel drivers are becoming a more appealing target for attackers and an important area of research for security analysts. A vulnerability in a signed third-party driver could have a serious impact: it can be abused by attackers to escalate privileges or, more commonly, bypass driver signature enforcement—without the complexity of using a more expensive zero-day kernel exploit in the OS itself. We discovered such a driver while investigating an alert raised by Microsoft Defender Advanced Threat Protection’s kernel sensors. In this blog post, we’d like to share our journey from investigating one Microsoft Defender ATP alert to discovering a vulnerability, cooperating with the vendor, and protecting customers.
  3. Microsoft Threat Experts is the managed threat hunting service in Microsoft Defender Advanced Threat Protection (ATP). It provides security operations centers (SOCs) with expert-level oversight and analysis to help ensure that critical threats in their unique environments are identified, investigated, and resolved. Get more details about the service here: Announcing Microsoft Threat Experts. Today, we are announcing the general availability of Microsoft Threat Experts targeted attack notification capability. Targeted attack notification, one of Microsoft Threat Experts’ two components, provides proactive hunting, prioritization, and alerts that are tailored to organizations. These alerts include as much information as can be quickly delivered to bring attention to critical threats, including timeline, scope of breach, and methods, to further empower SOCs to identify and respond to threats quickly and accurately.
  4. Introducing the security configuration framework: A prioritized guide to hardening Windows 10.
  5. Preview! Windows Defender Application Guard as browser extensions in Google Chrome and Mozilla Firefox. To extend our container technology to other browsers and provide customers with a comprehensive solution to isolate potential browser-based attacks, we have designed and developed Windows Defender Application Guard extensions for Google Chrome and Mozilla Firefox.
  6. MDATP Threat & Vulnerability Management now publicly available! This is a new Microsoft Defender ATP component that helps effectively identify, assess, and remediate endpoint weaknesses and provides both security administrators and security operations teams with unique value, including: real-time endpoint detection and response (EDR) insights correlated with endpoint vulnerabilities, invaluable machine vulnerability context during incident investigations, built-in remediation processes through Microsoft Intune and SCCM.
  7. At the RSA conference, we announced the general availability for Microsoft Defender ATP’s integration with Microsoft Cloud App Security – delivering a native integration to discover the cloud apps used in your organization. This is the first step towards enabling a seamless, zero deployment, native cloud app security solution that works any time any-where.
  8. Announcing the general availability of Microsoft Defender ATP APIs – a rich and complete set of APIs geared to fulfill the needs of security operations teams, enabling interoperability with enterprise security applications and automation. These capabilities enable customers to integrate and orchestrate defenses across their solution stack and management systems to orchestrate Microsoft Defender ATP; enabling security teams to effectively respond to modern threats.
  9. In an ideal world, all your critical devices would be seen by, reported on, and protected by Microsoft Defender ATP, however we’re aware that there are legitimate scenarios where devices simply can’t be connected to the Internet or a management service. As such, we have released a whitepaper with all the info you need to understand how security is impacted by the unique challenges of being disconnected. It talks about the types of disconnected devices, and — most importantly — provides guidance on the various features and protection technologies you can use from Microsoft to protect these disconnected devices.
  1. Windows 10 Tip: Dark theme in File Explorer.
  2. Windows 10 Tip: Snip & Sketch. Since it’s available in the Microsoft Store, Snip & Sketch can update faster and more frequently. It’s already had four app updates with new features since it was introduced in the October 2018 Update.
  3. Windows 10 Tip: What’s new in Skype (consumer) for Windows 10 PCs.
  4. Windows 10 makes wireless projection
  5. Stay organized with Sticky Notes in Windows 10.
  6. Customize Microsoft Edge for better browsing.
  7. Video (4:05) Windows 10 wireless projection makes it easy to present your work, share memories, and watch your favorite movies on a big screen without stepping out the door.
  8. Video (2:48) Windows 101: Windows Calculator for easy length conversions.
  9. Windows 10 Tip: See your top sites in the Jump List.
In other news related to Windows 10…

Windows 10 News You Can Use – April 2019

Posted on

Win10NewsLogo Windows 10 news you can use, April 2019 edition

Providing insights into Windows 10 deployment & management, security & compliance, and productivity.

Helping IT reduce costs, increase security, and boost employee productivity, by Jared Spataro, Corporate Vice President for Microsoft 365.

Deployment & Management
  1. Windows 10, version 1809 designated for broad deployment.
  2. Minimize the impact of Windows 7 and Office 2010 End of Support on your business – a Microsoft webinar (recorded 3/21/19) will explore how businesses of all sizes can achieve more by shifting to a modern desktop.
  3. Installing and using DTrace, a dynamic tracing framework that allows an admin or developer to get a real-time look into a system either in user or kernel mode. Using these dynamically inserted trace points, you can filter on conditions or errors, write code to analyze lock patterns, detect deadlocks, etc.
  4. Announcing the public preview of Microsoft Windows Virtual Desktop. Now, all customers can access this service—the only service that delivers simplified management, a multi-session Windows 10 experience, optimizations for Office 365 ProPlus, and support for Windows Server Remote Desktop Services (RDS) desktops and apps. With Windows Virtual Desktop, you can deploy and scale your Windows desktops and apps on Azure in minutes and enjoy built-in security.
  5. On this [Microsoft Mechanics] show (12:43), we’ll take a closer look at Windows Virtual Desktop, now in public preview. See how you can give your users the only Windows 10 multi-session experience virtualized in the cloud and available on any device. Scott Manchester demonstrates how WVD delivers the best Office experience with multi-session virtual scenarios that virtualize persistent storage in a multi-session environment. Keep watching for a sneak peak of the next generation admin experience for WVD in the Azure portal.
  6. With the public preview for Windows Virtual Desktop now available, we wanted to provide a quick overview of the steps required to get your environment up and running.
  7. In this [Microsoft Mechanics] show (16:17), CVP Brad Anderson demonstrates cold-booting his personal, highly-managed and secured Windows 10 device in under 20 seconds. We’ll also show new options to get to managed remote Windows sessions and apps across devices using the new Windows Virtual Desktop. And we show new streamlined management experiences for Microsoft 365 administrators as well as what you can do to set baseline protections and device configurations quickly using built-in Security Baselines in Microsoft Intune.
  8. What’s new to manage and secure your devices with Configuration Manager and Microsoft Intune.


Security & Compliance
  1. On November 29, 2018, MITRE published the results of their evaluation of several endpoint detection and response (EDR) solutions, testing them against a chain of attack techniques commonly associated with the APT3 activity group. MITRE avoided direct vendor comparisons, but this has not prevented participating vendors from claiming victory and leveraging the results in aggressive marketing campaigns. The evaluation highlighted Windows Defender Advanced Threat Protection’s (Windows Defender ATP) distinct, superior capabilities when compared with other participating vendors.
  2. Microsoft Intune security tasks extend Microsoft Defender ATP’s Threat & Vulnerability Management. Effectively identifying, assessing, and remediating endpoint weaknesses is pivotal in running a healthy security program and reducing organizational risk. Today, we are happy to introduce Microsoft Intune security tasks, a new one-click remediation capability in Microsoft 365 that bridges security stakeholders—security administrators, security operations, and IT administrators—by allowing them to collaborate and seamlessly remediate threats. This capability will extend the newly announced Microsoft Defender Threat & Vulnerability Management (TVM), a new component of Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP, previously Windows Defender ATP) that uses a risk-based approach to the discovery, prioritization, and remediation of endpoint vulnerabilities and misconfigurations.
  3. Introducing a risk-based approach to threat and vulnerability management. Threat & Vulnerability Management, a new, built-in capability that uses a risk-based approach to the discovery, prioritization, and remediation of endpoint vulnerabilities and misconfigurations. This capability is coming to Microsoft Defender Advanced Threat Protection (ATP), our industry-leading unified endpoint security platform with an updated name that reflects the newly announced expanded coverage.
  4. Announcing Microsoft Defender ATP for Mac. Today, we’re announcing our advances in cross-platform next-generation protection and endpoint detection and response coverage with a new Microsoft solution for Mac. Core components of our unified endpoint security platform, including the new Threat & Vulnerability Management also announced today, will now be available for Mac devices.
  5. Tamper protection in Microsoft Defender ATP is a new setting available which provides additional protections against changes to key security features, including limiting changes that are not made directly through the app. Enabling this feature prevents others (including malicious apps) from changing important protection features such as (a) Real-time protection, (b) Cloud-delivered protection, (c) IOAV, (d) Behavior monitoring. The feature also prevents the deletion of security intelligence updates and the disabling of the entire antimalware solution.
  1. Windows 10 Tip: Look up definitions for words in web pages, books and PDFs.
  2. Announcing the Open Sourcing of Windows Calculator. This includes the source code, build system, unit tests, and product roadmap. Our goal is to build an even better user experience in partnership with the community. We are encouraging your fresh perspectives and increased participation to help define the future of Calculator.
  3. Find my device is a feature introduced in the 2015 Windows 10 update, allows you to locate your Windows device if it goes missing. The best part about Find my device is that it’s completely safe to use, and automatically included in Windows 10.
  4. Windows 10 Tip for Microsoft Edge: Increase text spacing, choose themes and colors, and how to use the learning tools.
  5. Manage and use virtual desktops like a pro in Windows 10.
  6. Make Windows easier to see: bigger text and mouse pointer.
  7. Windows 10 Tip: Improve focus as you read web articles.
  8. Windows 101: Three ways to personalize your PC background.
  9. Whiteboard in Teams meetings integration, ink grab and ink beautification are here!
  10. Cloud clipboard: Copy & paste across your Windows 10 devices.
In other news related to Windows 10…

Windows 10 News You Can Use – March 2019

Posted on

Win10NewsLogo Windows 10 news you can use, March 2019 edition

Providing insights into Windows 10 deployment & management, security & compliance, and productivity.

Are you looking understand that ROI for your investment in a Microsoft 365 modern desktop? Then look no further as Microsoft has created an interactive ROI model based upon a Forrester Consulting case study, “The Total Economic Impact Of The Modern Desktop With Microsoft 365” (as commissioned by Microsoft). By filling in simple values, you can determine a high-level estimate of the economic impact on your specific environment of migrating from on-premise third-party and Microsoft solutions to Microsoft 365 modern desktop.

Deployment & Management
  1. The perils of using Internet Explorer as your default browser. When enough is enough for technical debt and why customers shouldn’t just stay status quo.
  2. MSIX: Package Support Framework. Part One – The Blueprint.
  3. We are excited to announce MSIX is now including support for Windows 10 versions 1709 and 1803, in addition to 1809 that is already supported. The new support enables distribution of MSIX packages within your enterprise using tools like System Center Configuration Manager, Microsoft Intune, PowerShell, double-click file deployments or installing directly from the APIs. This change does not include distribution from the Microsoft Store or Microsoft Store for Business, which will still require Windows 10 1809 or later.
  4. Want more information on the Microsoft Managed Desktop service? Microsoft has updated the MMD website and added a useful new e-book on the service.
  5. With Windows 10, there was never actually a Semi-Annual Channel (Targeted), or SAC-T, release; rather, SAC-T merely reflected a milestone for the semi-annual release. Beginning with Windows 10, version 1903 (the next feature update for Windows 10), the Windows 10 release information page will no longer list SAC-T information for version 1903 and future feature updates. Instead, you will find a single entry for each new SAC release. If you use Windows Update for Business, then read these guidelines for how this change will reflect the removal of the SAC-T nomenclature.
  6. Modern Desktop podcast – Windows 10 Application Compatibility. This episode (47:48) focuses on one of the biggest perceived pain points we hear from organizations getting ready for Windows 10 – Application Compatibility. We talk with Aleks Lopez and Robyn Nolan about the Windows Desktop App Assure program, as well as Chris Jackson, @appcompatguy, about the history of application compatibility over the various versions of Windows and where organizations are today.
  7. Windows 10 monthly quality updates are cumulative, containing all previously released fixes to ensure consistency and simplicity. Microsoft introduces a new technique to build compact software update packages that are applicable to any revision of the base version, and then describe how Windows 10 quality updates uses this technique.
Security & Compliance
  1. Tips to keep your devices and data safe using these simple security best practices.
  2. The keystone to good security hygiene is limiting your attack surface. Attack surface reduction (ASR) is a technique to remove or constrain exploitable behaviors in your systems. In this blog, we discuss the two ASR rules introduced recently and cover suggested deployment methods and best practices.
  3. We have been recommending the use of TLS 1.2 and above for some time. To help provide guidance, we are pleased to announce the release of the Solving the TLS 1.0 Problem, 2nd Edition white paper. The goal of this document is to provide the latest recommendations that can help remove technical blockers to disabling TLS 1.0 while at the same time increasing visibility into the impact of this change to your own customers.
  4. Announcing Microsoft Threat Experts! This new managed threat hunting service in Windows Defender Advanced Threat Protection. It provides proactive hunting, prioritization, and additional context and insights that further empower Security Operations Centers to identify and respond to threats quickly and accurately.
  1. Microsoft puts people first by offering a wide range of Windows 10 accessibility features for users of many different abilities. Known internally as the Windows Accessibility team, the Input for Everyone team draws back a curtain for you to peek behind the scenes. Learn how Windows engineers are building accessibility features for all of us.
  2. In this video (1:53), meet Brett Humphrey, a Senior Program Manager on the Windows Accessibility team to learn more about his experience of going through school and using technology with low vision and translating Windows to people with different abilities.
  3. Video (2:15) – Windows Narrator gets more accessible with QuickStart. The new Narrator QuickStart app teaches users with low vision and blindness how to navigate Windows, browse the web, and learn more with Narrator user guide.
  4. Windows 10 Tip: AI-powered PowerPoint Designer gets smarter.
  5. In Windows 10, the People app allows you to forge better connections with your primary contacts by keeping you in the loop about important dates, upcoming commitments, and recent conversations.
  6. Windows 101: Four ways to customize your taskbar.
  7. Windows 101: Unleash Windows superpower with right click. The right click on your mouse is capable of more than you know. Use it to gain instant access to all kinds of features and unleash your potential for productivity.
  8. Video (2:57) – Minimize distractions with Windows 10 Focus assist. Don’t let interruptions get in the way of your productivity. Windows 10 Focus assist acts as a gatekeeper, so distractions remain at bay.
In other news related to Windows 10…


Windows 10 News You Can Use – February 2019

Posted on

Win10NewsLogo Windows 10 news you can use, February 2019 edition

Providing insights into Windows 10 deployment & management, security & compliance, and productivity. Also see other news related to Windows 10.

With Windows 7 end of support coming in one year—January 14, 2020—and Office 2010 close behind, there’s an opportunity right now to be proactive about what’s next. 2019 is the year to make the shift to a modern desktop. Changes and upgrades in technology are inevitable, and there’s never been a better time to start putting in motion the things you need to do to shift your organization to a modern desktop with Microsoft 365. As you think about this upgrade, this is a time to consider how your approach can set you up for the future to deliver an incredible experience for your users that is empowering and secure.

Deployment & Management
  1. To streamline update management and eliminate the need for on-premises infrastructure to deploy feature and quality updates, Microsoft CSEO implemented Windows Update for Business (WUfB). It provides centralized management and reduces the level of effort required to keep Windows 10 devices up to date. With WUfB we can control how and when Windows 10 devices at Microsoft receive updates, configure restart policies for enforcement, and use analytics services to monitor our update compliance. See this case study on keeping Windows 10 devices up to date with Microsoft Intune and Windows Update for Business.
  2. Starting with the next major update we’re making a few changes to how Windows 10 manages disk space. Through reserved storage, some disk space will be set aside to be used by updates, apps, temporary files, and system caches. Our goal is to improve the day-to-day function of your PC by ensuring critical OS functions always have access to disk space.
  3. Application compatibility in the Windows ecosystem. In this installment of Microsoft’s quality blog series, Mete Goktepe from the Windows Application Compatibility team describes the various programs and technologies used to improve app compatibility.
  4. What’s new in Windows 10 management support with Microsoft Intune (January 2019).
  5. Updated and improved documentation and guidance! Find the tools and resources you need to deploy and support Windows as a service in your organization.
  6. Starting with Windows 10, v. 1809, WinPE is an add-on to the Windows Assessment and Deployment Kit (ADK). Previously it was included in the ADK. To get Windows PE, install the ADK, and then install the WinPE addon.
  7. Simplifying device management with Microsoft Intune and Windows Autopilot. Case studies for adoption within the education sector.
Security & Compliance
  1. Announcing Windows Defender Application Guard availability in Windows 10 Professional. Now, like Windows 10 Enterprise users, Windows 10 Pro users can navigate the Internet in Application Guard knowing their systems are safe from common web-based attacks. It is available now to our awesome Windows Insider community to give it a try and provide feedback. Plus a guide on steps to enable this cutting edge experience on the latest Windows Insider Preview build.
  2. Windows Defender ATP automated machine tagging in just a few simple steps. This blog explains how the APIs for WDATP can help a SOC analyst triage alerts more efficiently.
  3. Windows Defender ATP integrates with Microsoft Information Protection to discover, protect, and monitor sensitive data on Windows.
  4. Microsoft Intune introduces MDM Security Baselines to secure the modern workplace. Microsoft has years of experience publishing security baselines as Group Policy Objects in the Security and Compliance Toolkit (SCT). Customers have trusted this toolkit for years to provide templates to configure security baselines through Group Policy. Microsoft Intune now brings the same collective knowledge and expertise to secure the modern desktop with MDM security baselines. These security baselines in the Intune service leverage the greatly expanded manageability of Windows 10 using Mobile Device Management (MDM).
  1. Windows 10 Tip: Microsoft Forms to create, run and analyze results from surveys and quizzes.
  2. Windows 10 Tip: Using the Your Phone app to get instant access to your Android phone’s photos and texts on your computer – no need to dig for your phone to text or email yourself photos.
  3. Windows 10 Tip: Timeline for phone. Timeline makes it way easier to find what matters to you across your devices. You can also pick up what you were doing – even if it was on your iOS or Android device – on your Windows 10 PC when you’re ready to get back to it.
  4. Copy and paste across Windows 10 devices using cloud clipboard.
  5. Love Snipping Tool? Snip & Sketch allows you to do even more with your snips. Watch this video (3:38) to learn about its history and what the most recent update means for you.
  6. Transfer your photos from phone to PC without a cable.
  7. To protect against device loss or damage and to provide anywhere access to files, we recommend storing them in Office 365. Last June we announced Known Folder Move (KFM) in OneDrive for customers on Windows 7, 8.1 and Windows 10. Known Folder Move provides an easy way to redirect your desktop documents and folders to OneDrive, making OneDrive the default location for those files. Today we are announcing a new capability that makes it easier for you to create and save your Word, Excel, or PowerPoint document directly to the cloud. When you go to save an Office365 document, the new dialog box will default to OneDrive or SharePoint Online. And if you forget to save a new document before exiting, you will also see this updated save experience.
  8. Windows 10 Tip: Track multiple time zones with world clock.
  9. Windows 10 Tip: New pen gestures make it easier to edit Word documents.
  10. A faster and easier way to stay on top of your tasks – Cortana with Microsoft To-Do.
  11. With the Windows 10 October 2018 Update, Narrator (Windows screen reader) has become more accessible. The new Narrator QuickStart app teaches users with low vision and blindness how to navigate Windows, browse the web, and learn more with Narrator user guide.
In other news related to Windows 10…

Windows 10 News You Can Use – January 2019

Posted on Updated on

Win10NewsLogo Windows 10 news you can use, January 2019 edition

Providing insights into Windows 10 deployment & management, security & compliance, and productivity. Also see other news related to Windows 10.

Do you deploy, configure, secure, manage, and monitor devices and client applications in an enterprise environment? Do you manage identity, access, policies, updates, and apps and collaborate with the M365 Enterprise Administrator to design and implement a device strategy that meets the business needs of a modern organization? Are you familiar with M365 workloads and proficient in deploying, configuring, and maintaining Windows 10 and non-Windows devices and technologies? If so, it’s time to earn your Modern Desktop Administrator certification!

Deployment & Management
  1. Microsoft 365 enables customers to shift to a modern desktop experience puts it at the heart of workplace transformation. A modern desktop with Windows 10 and Office 365 not only offers the most productive and most secure computing experience, it also saves IT time and money, and allows for a focus on driving business results. For many companies, their specific needs require a modern desktop be virtualized. To help extend our virtualization capabilities and provide an even richer experience for Microsoft 365 customers, we are excited to announce the acquisition of FSLogix. FSLogix is a next-generation app-provisioning platform that reduces the resources, time and labor required to support virtualization. From small businesses to very large global enterprises across numerous industries, FSLogix solutions enhance customer experience and productivity, while reducing support requirements for IT departments.
  2. Microsoft is excited to announce that we are named a Leader for Enterprise Mobility + Security (EMS) in the inaugural Forrester Wave: Unified Endpoint Management, Q4 2018. Forrester notes in the report that, Microsoft’s release of co-management in late 2017 has bolstered the company’s ability to serve advanced Windows 10 management use cases and provides a flexible path for customers to test out modern management. Forrester also recognizes Microsoft for having the some of the strongest security capabilities in the evaluation of 12 vendors.
  3. Traditionally, the desktop management scenario for most enterprises has been one where all users and devices are located on-site with a direct network connection. That’s been the state of things for years. But the workplace is changing. More of your users work remotely full-time; some never set foot in your physical facilities. If you do the initial setup for a Windows 10 device on-premises, you start out in control. But if those devices are distributed to your remote workforce, how do you maintain control? How do you make sure user devices are secure and up-to-date while keeping the update process simple and hassle-free? In short, you implement a modern desktop management strategy.
  4. New Microsoft site for the latest information and guidance on Windows as a Service! Find the tools and resources you need to help deploy and support WaaS in your organization.
  5. Renaming Windows 10 devices using Microsoft Intune
  6. Windows Transport converges on two Congestion Providers: Cubic and LEDBAT. In the heart of the Windows kernel there is a networking stack. At the heart of the networking stack there is a layer called Transport and Transport contains a suite of algorithms called Congestion Providers. This post takes a look at the difference between the two along with a deeper view into the difference between them using the example of a software update being delivered by SCCM.
  7. Evaluating Windows 10 Delivery Optimization and its impact to your network at the device level as well as across the organization with Windows Analytics’ Update Compliance.
  8. Gartner: Rethink Windows 10 Long Term Servicing Branch (LTSB / LTSC) Deployment Based on Microsoft’s Updated Guidance – refreshed August 2018.
  9. Modern desktop servicing: the year in review. Since Windows 10 first shipped, and the Windows as a service model was introduced, we have heard you talk about three common concerns: application compatibility, end user interruption, and network bandwidth impact. I’m happy to report that, in 2018, we made significant progress in addressing each of these concerns.
  10. New! Microsoft 365 Modern Desktop podcast channel.  In this series, we’ll explore the good, the bad, and yes the ugly of servicing and delivery for Windows 10 and Office ProPlus. We’ll talk about modern desktop management through Enterprise Mobility, security, even Cloud attached and co-managed environments.
  11. Driver quality in the Windows ecosystem. Ensuring Windows 10 works great with all the devices and accessories our customers use is a top priority for our team. There are millions of configurations of hardware and driver combinations in the Windows ecosystem, allowing for great customer choice and unlocking opportunity for partners. We work closely with this broad mix of partners to test new drivers, monitor health characteristics over time, and make Windows and our ecosystem more resilient architecturally. In this blog, part of our series on the Windows approach to quality, Tom Frankum from our Silicon, Graphics and Media team will provide more detail about the work we do to improve Windows driver quality.
  12. Modern desktop servicing: the year in review. 2018 was a pivotal year for the modern desktop and the servicing transformation journey we have been taking with you and your organization. With that in mind, I thought it would be good to look back and recap the progress that has been made, highlight significant events, and provide insight into what 2019 has in store.
Security & Compliance
  1. Analysis of cyberattack on U.S. think tanks, non-profits, public sector by unidentified attackers. Microsoft customers using the complete Microsoft Threat Protection solution were protected from the attack. Behavior-based protections in multiple Microsoft Threat Protection components blocked malicious activities and exposed the attack at its early stages. Office 365 Advanced Threat Protection caught the malicious URLs used in emails, driving the blocking of said emails, including first-seen samples. Meanwhile, numerous alerts in Windows Defender Advanced Threat Protection exposed the attacker techniques across the attack chain.
  2. Insights from the MITRE ATT&CK-based evaluation of Windows Defender ATP. In MITREs evaluation of endpoint detection and response solutions, Windows Defender Advanced Threat Protection demonstrated industry-leading optics and detection capabilities. The breadth of telemetry, the strength of threat intelligence, and the advanced, automatic detection through machine learning, heuristics, and behavior monitoring delivered comprehensive coverage of attacker techniques across the entire attack chain.
  3. Video (1:57) on the Windows channel on YouTube features how Windows Information Protection (WIP) helps prevent users from accidentally copying work data to personal sites.
  4. Remote Use of Local Accounts: LAPS Changes Everything. Aaron Margosis of Microsoft revisits the question about whether and when to block the use of local accounts, particularly for remote administration.
  5. Microsoft has put a lot of effort in Hyper-V security. Hyper-V, and the whole virtualization stack, runs at the core of many of our products: cloud computing, Windows Defender Application Guard, and technology built on top of Virtualization Based Security (VBS). Read more from Microsoft’s Security Research & Defense about the first steps in Hyper-V security research including an intro to the virtualization stack, the debugging environment, and addressing the attack surface inside and outside the hypervisor.
  6. One of our goals in the Microsoft Security Response Center (MSRC) is to be more transparent with security researchers and our customers on the criteria we use for determining when we intend to address a reported vulnerability through a security update. Our belief is that improving transparency on this topic helps provide clarity on how we assess risk, sets expectations for the types of vulnerabilities that we intend to service, and facilitates constructive dialogue as the threat landscape evolves over time. In September 2018, the first version of the security servicing criteria for Windows was announced; it’s expected that this will be a living document that evolves over time as Microsoft continues the dialogue with the community on this topic.
  7. Windows Defender ATP has protections for USB and removable devices. We know, unfortunately, that people will plug in devices with unknown history (and that there are also attackers out there who directly attempt to control devices without relying on social engineering). These devices could be the source of malware infections that use USB and other removable devices to get initial access to a system or network. This vector of attack falls under social engineering in this case, appealing to our weakness for shiny things: when we see a free item were inclined to take it. To help protect against these attacks, you can prevent any removable device from being seen and interacted with by blocking users from using any removable device on the machine.
  8. Tackling phishing with signal-sharing and machine learning.With ML-based detection of malicious PDF files used for phishing, Windows Defender ATP uses multiple layers of machine learning models to correctly identify malicious content. Most attacks are caught by the first few layers, which swiftly make a verdict and protect customers at first sight during the early stages of attacks. More sophisticated attacks may need the more complex classifiers in further layers, which take more time but make sure additional protections catch attacks that evade the first, faster classifiers.
  9. Mitigating Spectre variant 2 with Retpoline on Windows.
  10. How many times have you downloaded an executable file, but were afraid to run it? Have you ever been in a situation which required a clean installation of Windows, but didn’t want to set up a virtual machine? Windows Sandbox is a new lightweight desktop environment tailored for safely running applications in isolation.
  1. Microsoft Edge: Making the web better through more open source collaboration.
  2. Introducing the Office app for Windows 10! Last year, we updated with a new experience focused on two simple things: helping users get the most out of Office and getting them back into their work quickly. The streamlined site has clearly resonated with customers, and now more than 40 percent of Office 365 web users start their work by visiting Starting today, we’re bringing this experience to Windows 10 in the form of an app, simply called Office. It’s now available to Windows Insiders (Fast) and will roll out to all Windows 10 users soon. The app itself is free and it can be used with any Office 365 subscription, Office 2019, Office 2016, or Office Online—the free web-based version of Office for consumers.
  3. Windows 10 Tip: Name your tile folders. To create a tile folder in Start, just drag one tile on top of another for a second, then release. Continue dropping as many tiles into the folder as you’d like. When you expand the folder, you’ll see a new option to name it.
  4. Windows key is the most powerful button on your keyboard. The Windows community shows you how to effectively search and find anything on your computer using only it. Whether you’re looking for that image you saved to one of your folders or need to look up weather for your trip, Windows key can help.
  5. Five Microsoft Edge features to boost productivity while browsing.
  6. Microsoft Whiteboard advancements: now more colorful and customizable than ever.
  7. Windows 10 Tip: the Windows 10 October 2018 Update comes SwiftKey intelligence.
  8. Windows 10 Tip: Schedule items by dragging a task to your calendar.
  9. Windows 10 Tip: Find files quickly using Quick access.
  10. Windows 10 Tip: Get Tips in Windows and online.
In other news related to Windows 10…