# 'Hardening' Windows

**URL:** https://discuss.privacyguides.net/t/hardening-windows/15750
**Category:** Questions
**Tags:** guide
**Created:** 2023-12-21T11:13:57Z
**Posts:** 115

## Post 1 by @Sprout3425 — 2023-12-21T11:13:57Z

Hello, good people at Privacy Guides (PG)! My post is in regard to Windows ‘hardening’. More specifically, I am currently using Windows 10 _Pro_, thus, I have been following this Windows guide: [https://deploy-preview-1659--privacyguides.netlify.app/windows/overview/](https://deploy-preview-1659--privacyguides.netlify.app/windows/overview/). I have numerous questions about this guide, no one is obliged to answer them, but I do appreciate it if you can. Also, I would like to thank the author of the guide, as well as the PG team, and the PG community, you are all very hospitable. I would also like to mention that I am a complete noob in this field, my ‘expertise’ is in the field of _biology_ and more generally _science_, and not in _computer science_. I am possibly way too deep into this.

To begin with, will this guide ever be officially released on PG? In addition, are there any recommendations that anyone has, that may not be covered in this guide?

Next, I will discuss some of the problems and questions I have related to this guide. Firstly, I have confirmed that my BitLocker recovery keys are being stored on my University Microsoft account, but not on any of my personal accounts, is this problematic? I assume the _Azure AD_ option here represents my University Microsoft account:

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/a/a9162ceb761611d1b73b8c9e9bf4224e6f0beda2.png)

I cannot remove these keys from my University Microsoft account, as I only have two options:

![image](//forum-uploads.privacyguidesusercontent.com/original/2X/8/8793e9984399c42645b813d10e301eb83adcf3d1.png)

Now, my primary question about this guide pertains to the following recommendation: ‘By Default Windows gives administrator access to the user account. Create another standard user account to reduce the attack surface enormously as most vulnerabilities today come from the fact that the user is always in administrator mode. In addition, you shouldn’t use the same password for standard and administrator account.’

If I’m not mistaken, isn’t the alternative recommendation: ‘If you don’t like managing a standard account, then enforce authentication for Administrator accounts too like Standard ones by following the guide by Wikihow. This way, Even administrators need to use Password to approve processes instead of just clicking Yes or No’, essentially as secure as the first one? The only difference between the two recommendations, seems to be that two different passwords are required in the first recommendation, compared to one in the alternative recommendation. Aside from this, are there any other technical differences?

Moreover, one might argue that the alternative recommendation becomes redundant if you simply lock your computer when stepping away, as an attacker that can unlock your computer, can already change administrative settings with the same password used to unlock your computer in the first place. In addition, since applying the alternative recommendation would still allow users to access your files if your computer was unlocked, this could give you a false sense of confidence, something mitigated by locking your computer.

I have another important question about the [guide](https://deploy-preview-1659--privacyguides.netlify.app/windows/overview/), regarding the Security policies for Bitlocker subtopic. I do not want to have to enter a PIN twice as is recommended by the guide. So, how do I get maximum protection using _group policies_, without having to enter a password twice? I assume I have to change some options differently compared to what the guide recommends, options which I assume I found in the _Require additional authentication at startup_ setting, under group policies. Should I change any other setting back to their defaults?

Also, the guide says: ‘Using MS edge or brave over Firefox. Edge is recommended with MDAG mode for secure browsing if security is your priority. Brave is recommended if content blocking is important for you (Brave shields)’, I am pretty sure not everyone here would agree with this.

I have yet another question (unfortunately, there are more to come) regarding Windows hardening, how do I disable my password as a sign in method, so that only a Windows Hello PIN can be used? I could not do so using the options below, and it might be important to note that I am currently using a local (not signed-in) administrator account, do I first need to log into my Microsoft account?

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/e/e9facbd5c0ea5be5f4cd5647092a5049113f49a8.png)

I have encountered an issue with this guide, or more likely I am misunderstanding the guide. The guide says: ‘To prevent other users from accessing your secondary data drives. Type gpedit.msc in Windows Run dialog box. Go to User Configuration \> Administrative Templates \> Windows Components \> File Explorer and set the Group Policy as below.’ When I do this, and I am on my local administrator account I can not open any file! How do I fix this?

My second last question is: I need help with the sandboxing portion of the guide, specifically _how_ do I use it, _when_ do I use it, the latter of which could be answered by including _why_ I should use it.

Finally, the guide claims it was inspired by this: [GitHub - beerisgood/Windows11\_Hardening: a collection about Windows 11](https://github.com/beerisgood/Windows11_Hardening). However, my question is why are there some recommendations not present in this guide, that are present in the GitHub guide? Furthermore, should I follow this other GitHub guide as well? Again, kudos, to this guide because unlike the GitHub guide it walks you through how to apply recommendations, rather than linking you to long articles.

Also sorry I forgot, merry xmas everyone!

---

## Post 2 by @anon97654407 — 2023-12-25T14:21:51Z

> [@Sprout3425](#):
>
> To begin with, will this guide ever be officially released on PG?

It should soon :tm:

> [@Sprout3425](#):
>
> Also, the guide says: ‘Using MS edge or brave over Firefox. Edge is recommended with MDAG mode for secure browsing if security is your priority. Brave is recommended if content blocking is important for you (Brave shields)’, I am pretty sure not everyone here would agree with this.

Some would agree and some won’t. Like the guide preview says : ‘If security is your priority’. If it isn’t your priority, then use the regular options recommended here.

> [@Sprout3425](#):
>
> My second last question is: I need help with the sandboxing portion of the guide, specifically _how_ do I use it, _when_ do I use it, the latter of which could be answered by including _why_ I should use it.

Sandboxing really sucks on Windows, while on Linux, we have Flatpaks which have decent sandboxing and macOS having their own things. At Windows, we have nothing, though it seems to be in the works.

> **[Windows 11 Will Sandbox Your Desktop Apps for More Security](https://www.howtogeek.com/894617/windows-11-will-sandbox-your-desktop-apps-for-more-security/)**
>
> Could this be the end of browser vulnerabilities affecting your PC?

Speaking of the guide itself, when I have used Windows 11 a year ago. Most of the apps available in the MS Store just aren’t sandboxed.

---

## Post 3 by @Sprout3425 — 2023-12-26T03:55:55Z

Update on:

> [@Sprout3425](#):
>
> Next, I will discuss some of the problems and questions I have related to this guide. Firstly, I have confirmed that my BitLocker recovery keys are being stored on my University Microsoft account, but not on any of my personal accounts, is this problematic? I assume the _Azure AD_ option here represents my University Microsoft account:
> 
> ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/a/a9162ceb761611d1b73b8c9e9bf4224e6f0beda2.png)
> 
> I cannot remove these keys from my University Microsoft account, as I only have two options:

I was able to solve this, basically when you setup `BitLocker` after encrypting your OS you are asked for three backup options, do **not** click the `save to your Azure AD account` option, unless you want to save these keys on your ‘business’ and/or educational account. Plus, if you change your mind you can always go back to BitLocker and click the `backup your recovery key` option. If you do click the `save to your Azure AD account` option, the only way to undo this as I unfortunately found out, was to decrypt and then re-crypt my entire OS being careful not to select this option. I hope this is highlighted in the guide!

One thing to note is that my previous BitLocker keys are still stored on my University Microsoft account (Azure AD account), however, I do not know if they are still operational.

---

## Post 4 by @Sprout3425 — 2023-12-26T03:58:13Z

Update on:

> [@Sprout3425](#):
>
> I have another important question about the [guide](https://deploy-preview-1659--privacyguides.netlify.app/windows/overview/), regarding the Security policies for Bitlocker subtopic. I do not want to have to enter a PIN twice as is recommended by the guide. So, how do I get maximum protection using _group policies_, without having to enter a password twice? I assume I have to change some options differently compared to what the guide recommends, options which I assume I found in the _Require additional authentication at startup_ setting, under group policies. Should I change any other setting back to their defaults?

I can confirm that you have to enter a BitLocker PIN and then your start up password/PIN to enter your computer. This is honestly not a huge deal. Just make them the same if you want.

---

## Post 5 by @Sprout3425 — 2023-12-26T04:10:55Z

Only a few **important** unanswered questions remain (as well as, some other un-important questions not listed here), which I have condensed. Firstly:

> [@Sprout3425](#):
>
> Currently when Windows opens I have two sign in options, which are PIN + password, so, **how do I disable my password as a sign in method, so that only a Windows Hello PIN can be used?**

Secondly:

> [@Sprout3425](#):
>
> The guide says: ‘To prevent other users from accessing your secondary data drives. Type gpedit.msc in Windows Run dialog box. Go to User Configuration \> Administrative Templates \> Windows Components \> File Explorer and set the Group Policy as below.’ **When I set this group policy as instructed, and I am on my local (offline) administrator account, I can not open any file (like the C: drive or documents)! How do I fix this?**

My final question could be considered un-important:

> [@Sprout3425](#):
>
> The guide states that it was inspired by [this](https://github.com/beerisgood/Windows11_Hardening). However, my question is why are there some recommendations not present in this guide, that are present in the ‘beerisgood’ (a silly name) guide? Should I follow this other GitHub guide as well?

Correct me if I am wrong, but @anon55142611 are you the creator of this guide and could you offer any help?

---

## Post 6 by @anon34108895 — 2023-12-26T06:33:48Z

Firstly, the recommend approach is to use [Yubikey as 2FA](https://support.yubico.com/hc/en-us/articles/360013708460-Yubico-Login-for-Windows-Configuration-Guide) for you local accont. You can also refer to [passwordless Windows](https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/passwordless-strategy#the-process) which is not recommended (as safe mode needs passwords).  
Secondly, I donot know what policy you are setting.  
Finally, I donot know what items you are talking about.

---

## Post 7 by @anon34108895 — 2023-12-26T06:42:01Z

If you really wanna know how to configure Windows to be secure and private, I suggest you take some time and read [this](https://learn.microsoft.com/en-us/windows/security/) and [this](https://learn.microsoft.com/en-us/windows/privacy/). Then the most of your questions can be answered by yourself.

---

## Post 8 by @Sprout3425 — 2023-12-26T13:32:41Z

Thanks for citing these comprehensive resources. However, it appears they are tediously long, for me personally, someone who does not have the time to understand how all these features work or what they do, but wants to take advantage of them.

---

## Post 9 by @Bhaelros — 2023-12-28T16:24:33Z

You can install security baselines from MS. They are covering most of the recommendations.

> **[Download Microsoft Security Compliance Toolkit 1.0 from Official Microsoft...](https://www.microsoft.com/en-us/download/details.aspx?id=55319)**
>
> This set of tools allows enterprise security administrators to download, analyze, test, edit and store Microsoft-recommended security configuration baselines for Windows and other Microsoft products, while comparing them against other security...

---

## Post 10 by @user1 — 2023-12-28T17:54:49Z

Nice find, I think it could be useful for the upcoming Windows guide.

---

## Post 12 by @anon29374801 — 2023-12-28T23:56:50Z

> [@anon34108895](#):
>
> Firstly, the recommend approach is to use [Yubikey as 2FA](https://support.yubico.com/hc/en-us/articles/360013708460-Yubico-Login-for-Windows-Configuration-Guide)

This is just an FYI for those interested in setting up Yubico for Windows.

I had a ton of trouble getting yubico for windows initially setup and working. If you are like me and for some reason it installs and does not work and you have to go into safe mode and uninstall it. Please note there is still a regkey entry that gets left over that will cause your next install to error out. [This Microsoft Answers](https://answers.microsoft.com/en-us/windows/forum/all/the-feature-you-are-trying-to-use-is-on-a-network/85584916-d12c-4d40-9794-8c4d7274a9b0) was the solution to getting it fixed.

---

## Post 13 by @anon34108895 — 2023-12-29T01:43:02Z

imo if you’re short of time, at least you should read [complete privacy settings for Windows](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services) , [security baseline for Microsoft products](https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/windows-security-configuration-framework/windows-security-baselines#where-can-i-get-the-security-baselinesm-components-to-microsoft-services) , [privacy settings for Edge](https://learn.microsoft.com/en-us/microsoft-edge/privacy-whitepaper/) , [privacy settings for Office](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls)

---

## Post 14 by @anon34108895 — 2023-12-29T01:44:16Z

thank u but I’m currently fine with yubikey login

---

## Post 16 by @Sprout3425 — 2023-12-30T12:43:33Z

I really do not know whether I would get a hardware authentication device. I have no knowledge in this field whatsoever, aside from reading EFF’s SSD guide.

---

## Post 17 by @Sprout3425 — 2023-12-30T12:45:25Z

Thanks so much, I will give them a read.

---

## Post 18 by @Sprout3425 — 2023-12-30T12:46:03Z

I have asked about automating privacy hardening in another post, this is life saving! This should be the default for lay people like me!

---

## Post 19 by @pinkandwhite — 2023-12-30T12:46:35Z

Go to [yubico’s site](https://www.yubico.com/), pick out whichever key suits your needs (probably a 5C or a 5, realistically) and order a pair. getting two is important because some services don’t let you use a hardware authenticator without a backup and you probably shouldn’t use them without have a backup regardless.

---

## Post 20 by @Sprout3425 — 2023-12-30T12:48:27Z

Thank you for your advice, I will consider this, however, I am a University student, with as I said previously ZERO knowledge in this field. I will need to educate myself to properly weigh the pros and cons of using hardware authentication.

---

## Post 21 by @Sprout3425 — 2023-12-30T12:50:50Z

One question, since I have already followed most of the recommendations in the guide made by PG, should I install these baselines still?

---

## Post 22 by @Sprout3425 — 2023-12-30T14:33:37Z

I read the first two large paragraphs, along with the ‘important’ and ‘warning’ boxes, from the [Manage connections from Windows 10 and Windows 11 operating system components to Microsoft services](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services) page.

I am using Windows 11 Pro, so after reading the readme.txt file in the WindowsRTLFB folder, which read: “‘Version 23H2\_Win11’ can be applied to version 23H2 of Windows 11 Enterprise, Windows Server Datacenter and Windows Server Standard.” I had a question, which was: should I run this script anyway? All of this was a lot for a university Biology student, especially considering I barely know how to use a computer. Nevertheless, I appreciate the help.

Next, I moved on to skimming through the [Use policy settings to manage privacy controls for Microsoft 365 Apps for enterprise](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls) page, to skip myself a headache, do I need to apply the settings recommended in this page manually, and read this page in its entirety, or these are these recommendations covered in the Security baselines guide? I will read the Security baselines and Microsoft Edge Privacy Whitepaper pages tomorrow, wish me luck.

---

## Post 23 by @anon34108895 — 2023-12-30T16:00:05Z

> [@Sprout3425](#):
>
> I read the first two large paragraphs, along with the ‘important’ and ‘warning’ boxes, from the [Manage connections from Windows 10 and Windows 11 operating system components to Microsoft services](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services) page.

I think for most people the section [2](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#bkmk-cortana) 12 17 18 21 24 28 29 33 are of top priority(especially [18.16](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#1816-feedback--diagnostics) choose Security for **Send your device data to Microsoft** policy. This will save you a lot of time.

For office there are just 2 settings([1](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls#policy-setting-for-diagnostic-data) [2](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls#policy-settings-for-connected-experiences)). you can download group policies [here](https://discuss.privacyguides.net/t/windows-guide/250/162).  
No the privacy related settings are not included in the security baseline at least for Edge and Office.

---

## Post 24 by @anon34108895 — 2023-12-30T16:29:50Z

As for the security baseline, just Download it and open MS Security Baseline Windows 11 v23H2.xlsx. the suggestions are on the _Windows 11_ column. Some of the important settings are [VBS](https://learn.microsoft.com/en-us/windows/security/hardware-security/system-guard-secure-launch-and-smm-protection#group-policy), [ASR](https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#attack-surface-reduction-rules-by-type), and Windows defender related settings. Basicly it is a more complete and official security guide than berisgood one.  
also refer to some additional recommendations [here](https://discuss.privacyguides.net/t/windows-guide/250/157)  
pls note all of my recommendations are from official Microsoft websites. I think they knows their OS best.

---

## Post 25 by @anon29374801 — 2023-12-30T18:14:08Z

I do question the usefulness of having a local account need a hardware key to login. You need to shut off any other way to access the computer for it to actually provide real security and not security theater. For example, it doesn’t prevent a computer from remoting in.

> **Note** : Local accounts will not be accessible by Windows Remote Desktop (RDP), but may still be accessible through other remote access software such as VNC or SSH. This other software can bypass the second factor because it does not integrate with the Windows authentication system.

I found it a fun thing to do but, I think unless your threat model requires you to lock down windows like this, its going to make using windows much more annoying for a small security gain.

It is much simpler to just lock down whats inside the local account then the account itself.

---

## Post 26 by @Bhaelros — 2023-12-30T19:39:47Z

You can also quickly install baselines via attached PS scripts.

---

## Post 28 by @user1 — 2023-12-30T20:31:14Z

There is a lot of settings that are changed all at once, does it breaks something?  
I guess the remove script could help in that case but I would prefer something more granular or with a GUI for a peace of mind.  
Are the new settings are applied per user or globally?

---

## Post 29 by @sha123 — 2023-12-30T21:37:38Z

> [@Sprout3425](#):
>
> I had a question, which was: should I run this script anyway?

No, at least not without your own overrides. Some settings worsen security (e.g. disable updates) and need changes. Others only work on Enterprise editions. So you might need additional settings to mitigate these on Pro edition.

---

## Post 30 by @sha123 — 2023-12-30T22:08:31Z

> [@Sprout3425](#):
>
> I will read the Security baselines and Microsoft Edge Privacy Whitepaper pages tomorrow, wish me luck.

The problem with Microsoft’s baselines is that they usually expect enterprise editions, security and privacy settings often play it off against each other and some things only apply or make sense for domain joined devices. They usually need some adjustments, then they can be very useful, but applying them blindly can lead to worse security, privacy or usability. To give you an example: I have more than 20 overrides to RTLFB alone.

Since all of this will take a lot of time I would recommend to skip Edge’s privacy whitepaper and simply use Brave instead.

---

## Post 31 by @anon34108895 — 2023-12-31T02:27:17Z

> [@anon29374801](#):
>
> It is much simpler to just lock down whats inside the local account then the account itself.

Yes. I use it bacause password login is less secure than Windows Hello which uses TPM.

> [@user1](#):
>
> There is a lot of settings that are changed all at once, does it breaks something?

Some would. [VBS](https://learn.microsoft.com/en-us/windows/security/hardware-security/system-guard-secure-launch-and-smm-protection#group-policy) needs proper BIOS settings and hardware or it leads to blue screen.

> [@user1](#):
>
> I guess the remove script could help in that case but I would prefer something more granular or with a GUI for a peace of mind.

Maybe you can use [Policy Analyzer](https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/windows-security-configuration-framework/security-compliance-toolkit-10#what-is-the-policy-analyzer-tool).

> [@user1](#):
>
> Are the new settings are applied per user or globally?

just take a look into the xlsx file yourself.

> [@sha123](#):
>
> They usually need some adjustments, then they can be very useful, but applying them blindly can lead to worse security, privacy or usability.

That’s what PG windows guide can do for us imo.

> [@sha123](#):
>
> Since all of this will take a lot of time I would recommend to skip Edge’s privacy whitepaper and simply use Brave instead.

if you donot use Edge, uninstall it.

---

## Post 32 by @user1 — 2023-12-31T10:01:39Z

> [@anon34108895](#):
>
> Maybe you can use [Policy Analyzer](https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/windows-security-configuration-framework/security-compliance-toolkit-10#what-is-the-policy-analyzer-tool).
> 
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/user1/48/2300_2.png) user1:
> 
> > Are the new settings are applied per user or globally?
> 
> just take a look into the xlsx file yourself.

Thank you for those infos, I checked Policy Analyzer and the xlsx file but it’s a bit too much for me.

I hope that the PG team will break down all that in the upcoming Windows guide.

---

## Post 33 by @Sprout3425 — 2024-01-01T12:05:24Z

Thanks a lot @anon34108895 and others, I truly appreciate it. The following is what I have understood so far. @sha123 you say:

> [@sha123](#):
>
> The problem with Microsoft’s baselines is that they usually expect enterprise editions, security and privacy settings often play it off against each other and some things only apply or make sense for domain joined devices. They usually need some adjustments, then they can be very useful, but applying them blindly can lead to worse security, privacy or usability. To give you an example: I have more than 20 overrides to RTLFB alone.
> 
> Since all of this will take a lot of time I would recommend to skip Edge’s privacy whitepaper and simply use Brave instead.

I am using Firefox so I assume the [Microsoft Edge Privacy Whitepaper page](https://learn.microsoft.com/en-us/microsoft-edge/privacy-whitepaper/) is irrelevant to me.

From everything you have said to me @anon34108895, I assume there is four pages to implement, listed here: [Manage connections from Windows 10 and Windows 11 operating system components to Microsoft services](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services), [Use policy settings to manage privacy controls for Microsoft 365 Apps for enterprise](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls), [Security baselines](https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/windows-security-configuration-framework/windows-security-baselines) and [Microsoft Edge Privacy Whitepaper](https://learn.microsoft.com/en-us/microsoft-edge/privacy-whitepaper/). So far, I think we have ruled out the necessity for one page: the [Microsoft Edge Privacy Whitepaper](https://learn.microsoft.com/en-us/microsoft-edge/privacy-whitepaper/) page, however, this is subject to debate.

Considering these factors:

1. I have no clue what I am doing (although, I have read the first two paragraphs, along with the ‘important’ and ‘warning’ boxes, from the [Manage connections from Windows 10 and Windows 11 operating system components to Microsoft services](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services) page).
2. I am using Windows 11 Pro and,
3. I have implemented most of the suggestions in the Windows Guide,

What do I need to do _exactly_? E.g., what scripts do I need to run or policies do I need to set (e.g., the **Windows Restricted Traffic Limited Functionality Baseline** , the **Administrative Template files (ADMX/ADML) and Office Customization Tool for Microsoft 365 Apps for enterprise, Office 2019, and Office 2016** and/or the **Security Compliance Toolkit and Baselines** ), and what do I need to set these policies to? Answering, such questions would be _highly_ appreciated. Furthermore, what are the [Mobile device management (MDM) security baselines](https://learn.microsoft.com/en-us/windows/client-management/mdm/#mdm-security-baseline)? Who are these relevant to?

So far, thanks to @anon34108895 I know there are only 2 settings to apply for Microsoft 365 apps.

> [@anon34108895](#):
>
> I think for most people the section [2](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#bkmk-cortana) 12 17 18 21 24 28 29 33 are of top priority(especially [18.16](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#1816-feedback--diagnostics) choose Security for **Send your device data to Microsoft** policy. This will save you a lot of time.

Aren’t these applied automatically in the security baselines? Can I get away without reading these sections. Would it be more efficient to find policies that I need to revert back from those recommended in the security policies (e.g., stopping automatic updates)?

---

## Post 34 by @sha123 — 2024-01-01T13:44:25Z

> [@Sprout3425](#):
>
> Aren’t these applied automatically in the security baselines?

No. This is from RTLFB. RTLFB and security baselines are partially conflicting.

> [@Sprout3425](#):
>
> Can I get away without reading these sections.

RTLFB is not something you can apply blindly. Some settings disable security critical things like windows or defender updates. You either need to adjust these objects in the baseline before applying or override them afterwards

---

## Post 35 by @Bhaelros — 2024-01-01T15:37:21Z

I didn’t encounter major issues with Windows and Office baselines. Only with Edge baseline it is hindering browser extensions, native messaging and downloads.

My recommendation will be, if you can, first install it on a virtual machine. Test it for few days, then install them into your main host. If that is not possible, then before installing baselines create a manual system recovery point.

---

## Post 36 by @Sprout3425 — 2024-01-02T10:02:34Z

Thanks, for the advice!

---

## Post 37 by @sha123 — 2024-01-02T12:30:04Z

> [@Bhaelros](#):
>
> I didn’t encounter major issues with Windows and Office baselines.

Windows security baseline has a few privacy invasive settings. Did you change them?

---

## Post 38 by @Sprout3425 — 2024-01-02T14:07:07Z

Okay, thanks so much. However, I still don’t know what to do. @sha123 you say:

> [@sha123](#):
>
> RTLFB is not something you can apply blindly. Some settings disable security critical things like windows or defender updates. You either need to adjust these objects in the baseline before applying or override them afterwards

and,

> [@sha123](#):
>
> Windows security baseline has a few privacy invasive settings. Did you change them?

Implying that both the RTLFB and security baselines can not be applied automatically.

---

## Post 39 by @Sprout3425 — 2024-01-02T14:12:31Z

Also, I have no idea how to read this: [Use policy settings to manage privacy controls for Microsoft 365 Apps for enterprise](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls), or use this: [Administrative Template files (ADMX/ADML) and Office Customization Tool for Microsoft 365 Apps for enterprise, Office 2019, and Office 2016](https://www.microsoft.com/en-sa/download/details.aspx?id=49030). Windows links to this page for help ([Create and manage Central Store - Windows Client | Microsoft Learn](https://learn.microsoft.com/en-us/troubleshoot/windows-client/group-policy/create-and-manage-central-store)), however, it is full of unfamiliar terminology.

---

## Post 40 by @sha123 — 2024-01-02T14:36:58Z

> [@Sprout3425](#):
>
> Implying that both the RTLFB and security baselines can not be applied automatically.

You can apply them automatically. But you shouldn’t, without knowing what and how to change. Also the result depends on which order you apply them.

---

## Post 41 by @Sprout3425 — 2024-01-03T01:05:11Z

I feel like applying these baselines is impossible for a layperson, everything is incredibly hard to decipher.

---

## Post 42 by @Sprout3425 — 2024-01-03T04:17:18Z

For those of you who have _zero_ knowledge in computer science and do not have the time to read through all of Microsoft’s documentation, here is how I was able to finally apply the security baseline, after hours of suffering:

**Warning** : make a recovery point before doing the below steps!

1. **Download** the “Windows 11 v23H2 Security Baseline” and “LGPO” files [from here](https://www.microsoft.com/en-us/download/details.aspx?id=55319).
2. **Unzip** both files.
3. In the unzipped LGPO file, navigate to `LGPO_30 > LGPO.exe`.
4. **Copy** the `LGPO.exe` file to `Windows 11 v23H2 Security Baseline > Scripts > Tools`.
5. **Open** Windows PowerShell as an administrator.
6. **Change** the directory to the Scripts folder in the Windows 11 v23H2 Security Baseline file by typing:

```
cd 'C:\Users\Redacted\Downloads\Windows 11 v23H2 Security Baseline\Windows 11 v23H2 Security Baseline\Scripts'
```

1. **Set** the execution policy to unrestricted for the current process by typing:

```
Set-ExecutionPolicy -Scope Process Unrestricted
```

1. You will be prompted with a message about the execution policy change. **Respond** with `Y` to confirm the change.
2. **Run** the `Baseline-LocalInstall.ps1` script with the `-Win11NonDomainJoined` parameter (since I am using a personal laptop) by typing:

```
.\Baseline-LocalInstall.ps1 -Win11NonDomainJoined
```

1. You will receive a security warning. **Respond** with `R` to run the script once.

Congratulations, you’ve successfully applied the Windows 11 security baseline! :tada: **But do not close Windows Powershell yet!**

**Conveniently, the [link](https://www.microsoft.com/en-us/download/details.aspx?id=55319) also includes the other baselines mentioned by the expert users here.** Simply, follow the above steps and use the folders: “Microsoft Edge v117 Security Baseline”, “Microsoft 365 Apps for Enterprise 2306” and “WindowsRTLFB”. Furthermore, you do not have to apply the parameter given in step 9, nor are there any unique requirements for the other scripts, everything else is literally the same. This will save you time.

**While experts suggest you should not blindly apply these policies, I suggest you do apply them all, and then revert back individual, troublesome policies as they appear** (_you may notice them when you try to complete a task or if a feature that you are used to is missing. The only problem I can foresee is the potential removal of useful features before you have a chance to discover and use them. As of now [01/03/2024], the decision on which policies to remove is still under discussion, as detailed below_). I have had no isssues so far.

**See this for updates:** [quote=“sha123, post:34, topic:15750”]  
RTLFB and security baselines are partially conflicting.  
[/quote]

---

## Post 43 by @Sprout3425 — 2024-01-03T04:25:27Z

After this I was prompted to:

> To test properly, create a new non-administrative user account and reboot.

**Do I really need to new non-administrative user account, after applying the security baseline?**

---

## Post 44 by @Sprout3425 — 2024-01-03T04:33:34Z

**2nd Edit:**

> Sorry for the ping @sha123 and @anon34108895, I have one question, I have applied the **Windows security baseline** , and I do not want to use a standard (non-admin) account in conjunction with an administrator account, I just want to use one administrator account.

**The above is not applicable, the Windows security baseline does not force you to use a non-administrator account in conjunction with an administrator account.**

**What settings should I revert back that the security baseline sets?**

**1st Edit:**  **Do I need to apply the “Windows Server 2022 Security Baseline” or is this irrelevant to me using a private home computer and network?**

**2nd Edit:**  **Answer: I didn’t need to do this according to some friendly users.**

I will apply the Edge (I do not really use edge) and 365 baselines, but not the TLFB baseline, as per your opinions. I will do this before you all let me know what settings I should change back. Thank you so much! I highly appreciate you all.

---

## Post 45 by @pinkandwhite — 2024-01-03T05:08:29Z

That’s to be expected, the documentation is for people who are managing a business deployment and not just laypeople

---

## Post 46 by @anon34108895 — 2024-01-03T07:06:16Z

> [@Sprout3425](#):
>
> one more question, do I need to apply the “Windows Server 2022 Security Baseline” or is this irrelevant to me using a private home computer and network?

no. only find what’s matching your WIndows edition.

> [@Sprout3425](#):
>
> Do I really need to new non-administrative user account, after applying the security baseline?

no afaik. tbh I donot know what this prompt means. I suggest you to ignore it.

> [@Sprout3425](#):
>
> TLFB baseline according to your opinions

instead of applying RTLFB, you can also read the web page and adjust settings manually by your needs. This is my way of adjusting privacy settings and I think it’s more versatile and easy to revert changes. I think for most people the section [2](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#bkmk-cortana) 12 17 18 21 24 28 29 33 are of top priority(especially [18.16](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#1816-feedback--diagnostics) choose Security for **Send your device data to Microsoft** policy.

---

## Post 47 by @anon34108895 — 2024-01-03T07:08:33Z

> [@Sprout3425](#):
>
> I have heard the UAC setting could be annoying.

[Enable or Disable Ctrl+Alt+Delete Secure Desktop for UAC prompt in Local Group Policy Editor](https://www.tenforums.com/tutorials/112476-enable-ctrl-alt-delete-secure-desktop-uac-prompt-windows.html#:~:text=OPTION%20ONE-,Enable%20or%20Disable%20Ctrl%2BAlt%2BDelete%20Secure%20Desktop%20for%20UAC%20prompt%20in%20Local%20Group%20Policy%20Editor,-The%20Local%20Group)

---

## Post 48 by @Sprout3425 — 2024-01-03T11:20:12Z

Thanks a lot!

---

## Post 49 by @Sprout3425 — 2024-01-03T11:25:02Z

What are these settings, _exactly_? I found some information from Microsoft themselves, [here](https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-11-version-23h2-security-baseline/ba-p/3967618).

So far, I have noticed that the “Windows 11 v23H2 Security Baseline” has turned off **Controlled Folder Access** , placing it on _Audit Mode_. I manually changed this setting to _Block_ (Click Start \> type and then click Edit group policy. Click Computer Configuration \> Administrative Templates \> System \> Device Guard \> Turn On Virtualization Based Security \> Secure Launch Configuration), because Microsoft says:

> To fully enable controlled folder access, you must set the Group Policy option to _Enabled_ and select _Block_ in the options drop-down menu.

**More security settings that the baseline weakened/disabled include** (that I was able to identify): **Apply UAC restrictions to local accounts on network logons** , **System Guard Secure Launch and SMM protection** , **Firewall & network protection notifications** , **Firmware protection**. Furthermore, I noticed that under Windows Security \> App browser & control \> Exploit protection settings \> **Programme settings** , a lot of seemingly important settings seem to be untouched.

Now, to be honest, I can’t be bothered to look through the 63 (I think) changed Local Group Policy settings, for settings that the “Windows 11 v23H2 Security Baseline” may have counter intuitively turned off. Moreover, the baseline may have not configured/missed some settings in the first place. **Can anyone alert me as to settings that I should manually override/change?**

In general, I noticed that some (_groan_) group policy security settings had defaults that were different to their _recommended_ state (as prescribed by Microsoft), meaning they were weakening the security of my device on purpose. This begs the question, **why on Earth, does this “security” baseline weaken a small number of seemingly arbitrarily chosen security settings?**

**Note: I noticed that Microsoft are updating their baselines, you can find [updates here](https://techcommunity.microsoft.com/t5/microsoft-security-baselines/bg-p/Microsoft-Security-Baselines).**

Lastly, I could not be bothered to read the “Microsoft Edge Privacy Whitepaper”, does it provide anything of importance?

**Update 2: This is how I set my settings for System Guard Secure Launch and SMM protection, would you all recommend any changes?**

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/5/51b684f60bac93c0c5d485b3563c1fe67edeba79.jpeg)

---

## Post 50 by @sha123 — 2024-01-03T13:46:26Z

> [@Sprout3425](#):
>
> What are these settings, _exactly_?

Computer Configuration  
Windows Components\Microsoft Defender Antivirus\MAPS  
Join Microsoft MAPS

I changed it from 2 → 0

and

Computer Configuration  
Windows Components\Microsoft Defender Antivirus\MAPS  
Send file samples when further analysis is required

3 → 2

are the most important ones.

You might also want to change:  
Computer Configuration  
Windows Components\Microsoft Defender Antivirus  
Control whether or not exclusions are visible to Local Admins.

1 → 0

Pls read what they do before changing them.

---

## Post 51 by @Sprout3425 — 2024-01-03T13:58:30Z

> [@sha123](#):
>
> Computer Configuration  
> Windows Components\Microsoft Defender Antivirus\MAPS  
> Join Microsoft MAPS
> 
> I changed it from 2 → 0

Interestingly, mine was defaulted to this.

> [@sha123](#):
>
> Computer Configuration  
> Windows Components\Microsoft Defender Antivirus\MAPS  
> Send file samples when further analysis is required
> 
> 3 → 2
> 
> are the most important ones.

Mine was set to: _(0x0) Always prompt_, by default.

> [@sha123](#):
>
> You might also want to change:  
> Computer Configuration  
> Windows Components\Microsoft Defender Antivirus  
> Control whether or not exclusions are visible to Local Admins.
> 
> 1 → 0

Not sure whether this means enabled or disabled, since these options are not displayed like that, for me. Mine is enabled.

> [@sha123](#):
>
> Pls read what they do before changing them.

I read the Group Policy descriptions. Thanks a lot!

---

## Post 52 by @sha123 — 2024-01-03T13:58:59Z

> [@Sprout3425](#):
>
> Lastly, I could not be bothered to read the “Microsoft Edge Privacy Whitepaper”, does it provide anything of importance?

If you use Edge it is important, otherwise not.

---

## Post 53 by @Sprout3425 — 2024-01-03T14:01:36Z

I applied the Microsoft Edge v117 Security Baseline and disabled all telemetry in the privacy and security settings, so I assume it is unimportant anyway.

---

## Post 54 by @sha123 — 2024-01-03T14:03:06Z

Are you sure that the baseline was applied correctly? Did you restart the device afterwards? Did you do GPO changes to these settings before applying the policy?

Would recommend to compare your current state to the baseline them with the policy analyzer tool.

---

## Post 55 by @sha123 — 2024-01-03T14:04:13Z

> [@Sprout3425](#):
>
> I applied the Microsoft Edge v117 Security Baseline and disabled all telemetry in the privacy and security settings, so I assume it is unimportant anyway.

The main problem with Edge is not only diagnostic data. There is quite some invasive nonsense to deactivate.

---

## Post 56 by @sha123 — 2024-01-03T14:18:44Z

> [@anon34108895](#):
>
> Enable or Disable Ctrl+Alt+Delete Secure Desktop for UAC prompt in Local Group Policy Editor

Not in the security baseline and not recommended to activate according to Microsoft Blog post from 2019.

---

## Post 57 by @Sprout3425 — 2024-01-03T14:19:45Z

I am silly, I mistook UAC for something else, UAC does not pester me at all. Aside from defaulting to no.

---

## Post 58 by @Sprout3425 — 2024-01-03T14:33:40Z

This is the last step and the largest time investment. I do not know at the moment whether I will commit. Could it be smarter to apply the entire thing at once and then overwrite some of their prescribed settings?

The only other thing that worries me is this:

> [@sha123](#):
>
> RTLFB and security baselines are partially conflicting.

---

## Post 59 by @sha123 — 2024-01-03T14:47:55Z

> [@Sprout3425](#):
>
> More security settings that the baseline weakened/disabled include

Except the controlled folder access setting, most other settings usually have good reasons to be that way, and what you think is weakening security might not in practice or can lead to instabilities if you force settings on hardware which does not fulfill the requirements. Problem is that Microsoft’s docs and descriptions are sometimes outdated or confusing, which is where a lot of the confusion comes from.

---

## Post 60 by @sha123 — 2024-01-03T14:55:56Z

> [@Sprout3425](#):
>
> The only other thing that worries me is this:
> 
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/sha123/48/14_2.png) sha123:
> 
> > RTLFB and security baselines are partially conflicting.

The two main conflicting settings, were the defender settings I wrote. But independently of the security baseline you should go through the most important privacy settings. Be it with RTLFB or via some other way.

Oh and learn to use the policy analyzer tool. It’s immensely helpful to compare different policies to each other and to your current state and to get an overview, including descriptions of the settings.

---

## Post 61 by @sha123 — 2024-01-03T15:26:22Z

> [@Sprout3425](#):
>
> ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/5/51b684f60bac93c0c5d485b3563c1fe67edeba79.jpeg)
> 
> image1920×993 131 KB

Some minor points: Just selecting `Secure Boot` would be enough, since Windows will turn on DMA protection automatically, if your device fulfills the requirements. Not checking the `Require UEFI Memory Attributes Table` can lead to instabilities, if your hardware does not fulfill the requirements. Aside from that it is fine. But shouldn’t this already be set from the security baseline?

---

## Post 64 by @Sprout3425 — 2024-01-04T00:48:40Z

> [@sha123](#):
>
> Did you do GPO changes to these settings before applying the policy?

No, I don’t think I did, because I don’t know what a GPO change is tbh. Could you explain what this is @sha123?

---

## Post 65 by @Sprout3425 — 2024-01-04T00:51:46Z

> [@sha123](#):
>
> The two main conflicting settings, were the defender settings I wrote.

Thank you.

Also, I have noted some successes and failures, which I assume are due to me not having an Enterprise Windows edition.  
 ![image](//forum-uploads.privacyguidesusercontent.com/optimized/2X/d/dd3f14cd0eb3bcd76ad8381d7b9ba116cad5b333_2_690x14.png)

![image](//forum-uploads.privacyguidesusercontent.com/optimized/2X/d/df2289e9da5f2e8ad7d377efd638b8d9c022584f_2_690x39.png)

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/e/efaa22a79b2606fca2fccd4c536295557e35fd25.jpeg)

---

## Post 66 by @Sprout3425 — 2024-01-04T00:57:03Z

There was a weird behaviour, where I kept changing the settings and something would default everything to disabled, except for the **Platform Security Level** which was set to _Secure Boot_ by the baseline I think.

Edit: it is so buggy it keeps changing from my settings back to disabled, I think it is a visual glitch?

---

## Post 67 by @Sprout3425 — 2024-01-04T01:10:16Z

Thanks so much for the high level of detail @anon34108895. Wouldn’t it be easier to apply it and then to overwrite the settings? Have to do some maths here, which option would entail changing less settings? Plus, you are correct applying all of the settings at once after applying the security baseline could cause me some trouble I suppose.

---

## Post 68 by @anon34108895 — 2024-01-04T06:09:05Z

> [@Sprout3425](#):
>
> Controlled Folder Access

The setting is actually [**Windows components \> Microsoft Defender Antivirus \> Microsoft Defender Exploit Guard \> Controlled folder access**](https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/enable-controlled-folders?view=o365-worldwide#group-policy:~:text=Windows%20components%20%3E%20Microsoft%20Defender%20Antivirus%20%3E%20Microsoft%20Defender%20Exploit%20Guard%20%3E%20Controlled%20folder%20access) .

> [@Sprout3425](#):
>
> Click Computer Configuration \> Administrative Templates \> System \> Device Guard \> Turn On Virtualization Based Security

Before this there are several BIOS settings you should adjust.

1. turn Secure boot on and disable **third party Microsoft UEFI CA** which is for Linux.
2. turn virtulization related settings on.
3. turn Thunderbolt related security settings to the highest level.
4. set Bios password.
5. only boot your hard drive and disable all other items in the boot sequence settings.
6. turn on TPM and set Pluton as default it you have it.

Let’s return to the policy. This policy contains several **IMPORTANT** settings. The settings in this policy cannot be easily to revert to default status.

1. Secure Boot and DMA protection. If your laptop is shipped after 2018 select it to secureboot and DMA protection.
2. VBS aka code integrity. most hardware are compatible with it. select it to on/on with uefi lock. uefi lock means this settings is written to your bios rather than only the system(Windows). also turn on Require UEFI Memory Attributes Table.
3. Credential Guard. select it to on/on with uefi lock.
4. Secure Launch aka system guard secure launch aka firmware protection. smm protection is included in secure launch. this [requires](https://learn.microsoft.com/en-us/windows/security/hardware-security/how-hardware-based-root-of-trust-helps-protect-windows#system-requirements-for-system-guard) a Intel vPro CPU. If your device is compatiable, turn it on.
5. hardware enforced stack protection. [requirments](https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-11-version-22h2-security-baseline/ba-p/3632520#:~:text=There%20is%20a%20hardware%20dependency%20for%20this%20new%20feature%20that%20requires%20Intel%20Tiger%20Lake%20and%20beyond%20or%20AMD%20Zen3%20and%20beyond.). If your device is compatiable, turn it on.

> [@Sprout3425](#):
>
> Apply UAC restrictions to local accounts on network logons

open the xlsx file and you can see that this policy is for domain joined device. these settings are in red in the xlsx file.

> [@Sprout3425](#):
>
> System Guard Secure Launch and SMM protection

see above

> [@Sprout3425](#):
>
> **Firewall & network protection notifications**

I donot know about this.

> [@Sprout3425](#):
>
> Windows Security \> App browser & control \> Exploit protection settings \> **Programme settings**

There is a baseline file for this. it’s in baseline.zip/scripts/configfiles/ep-reset.xml. config the policy **Windows components** \> **Windows Defender Exploit Guard** \> **Exploit Protection** \> **Use a common set of exploit protection settings** to use the xml.

> [@Sprout3425](#):
>
> Can anyone alert me as to settings that I should manually override/change?

this [answer of mine](https://discuss.privacyguides.net/t/windows-guide/250/157) contains all of the related settings that may not be in the security baseline and privacy settings like RTLFB.

> [@Sprout3425](#):
>
> I noticed that some (_groan_) group policy security settings had defaults that were different to their _recommended_ state

any examples?

> [@Sprout3425](#):
>
> This is how I set my settings for System Guard Secure Launch and SMM protection, would you all recommend any changes?

see above. the baseline seggests uefi memory table.

> [@Sprout3425](#):
>
> I applied the Microsoft Edge v117 Security Baseline and disabled all telemetry in the privacy and security settings, so I assume it is unimportant anyway.

Did you throw [admx and adml](https://discuss.privacyguides.net/t/windows-guide/250/162) files into the correct place before applying the baseline? I agree with sha123 here. There is quite a lot privacy related settings in Edge.

> [@Sprout3425](#):
>
> There was a weird behaviour, where I kept changing the settings and something would default everything to disabled, except for the **Platform Security Level** which was set to _Secure Boot_ by the baseline I think.

can you explain this more clearly? have you try rebooting? what’s it like before and after set to default? did you click ok after change the settings?check the status of the VBS related settings in Windows Defender app-device security-core isolation.

---

## Post 69 by @anon34108895 — 2024-01-04T06:11:58Z

> [@Sprout3425](#):
>
> you can find [updates here](https://techcommunity.microsoft.com/t5/microsoft-security-baselines/bg-p/Microsoft-Security-Baselines)

[rss](https://techcommunity.microsoft.com/gxcuf89792/rss/board?board.id=Microsoft-Security-Baselines)

---

## Post 70 by @anon34108895 — 2024-01-04T06:18:44Z

> [@anon34108895](#):
>
> this [answer of mine](https://discuss.privacyguides.net/t/windows-guide/250/157)

one more setting: If you donot have DMA protection, turn on [this](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/configure?tabs=common#disable-new-dma-devices-when-this-computer-is-locked). always use hibernate instead of sleep because it activates Bitlocker. Device in sleep or awake status is not protected by Bitlocker. and the most impratant thing: turn Bitlocker on.  
I’m not a native English speaker so there’s a lot of grammar mistakes in my answer.

---

## Post 71 by @user1 — 2024-01-04T07:16:43Z

There are so many confusing settings, such a rabbit hole!  
It would be great if @anon34108895, @sha123, @Bhaelros could volunteer to contribute finalizing the PG Windows guide :pray: :pray:

---

## Post 72 by @sha123 — 2024-01-04T13:11:10Z

> [@anon34108895](#):
>
> Secure Boot and DMA protection. If your laptop is shipped after 2018 select it to secureboot and DMA protection.

DMA protection should automatically turn on if you select `secure boot` and your device supports it. The security baseline also just selects secure boot. Is there any advantage in selecting `Secure Boot and DMA protection` that I overlooked?

> [@Sprout3425](#):
>
> Edit: it is so buggy it keeps changing from my settings back to disabled, I think it is a visual glitch?

In the security settings UI? That could indicate that it is not active in practice. Can you check with msinfo?  
If it’s really not active you might need to change UEFI settings or you have firmware problems.

---

## Post 73 by @sha123 — 2024-01-04T13:16:32Z

> [@Sprout3425](#):
>
> I applied the Microsoft Edge v117 Security Baseline

Type edge://policy into Edge’s address bar. Some settings won’t be applied because it needs MDM enrollment. See [Edge Policies for non-Domain-joined Devices – Successfully apply HomepageLocation, DefaultSearchProvider, … – Gunnar Haslinger](https://hitco.at/blog/apply-edge-policies-for-non-domain-joined-devices/) for a solution (you just need to apply the first registry file).

---

## Post 74 by @Sprout3425 — 2024-01-04T14:28:38Z

> [@anon34108895](#):
>
> Did you throw [admx and adml](https://discuss.privacyguides.net/t/windows-guide/250/162) files into the correct place before applying the baseline? I agree with sha123 here. There is quite a lot privacy related settings in Edge.

Not sure what the ‘correct place’ is nor what the .admx and .adml files are.

---

## Post 75 by @Sprout3425 — 2024-01-04T14:30:43Z

> [@anon34108895](#):
>
> check the status of the VBS related settings in Windows Defender app-device security-core isolation.

Status for firmware protections is _Off_. Which is odd.

---

## Post 76 by @Sprout3425 — 2024-01-04T14:37:41Z

Not sure that this is relevant [Edge Policies for non-Domain-joined Devices – Successfully apply HomepageLocation, DefaultSearchProvider, … – Gunnar Haslinger](https://hitco.at/blog/apply-edge-policies-for-non-domain-joined-devices/), not to mention it is pretty intimidating! I say this because, all the settings I can see have an ‘Ok’ status.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/3/3c73ce9fc1f7356b76a52d9f13f0c32a6e1cc8b7.png)

---

## Post 77 by @Sprout3425 — 2024-01-04T14:40:56Z

> [@sha123](#):
>
> In the security settings UI? That could indicate that it is not active in practice. Can you check with msinfo?

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/c/c35c00e9ae6a5b1e74eb3a4dee23f03334a5df95.png)

---

## Post 78 by @Sprout3425 — 2024-01-04T14:42:00Z

> [@anon34108895](#):
>
> one more setting: If you donot have DMA protection, turn on [this](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/configure?tabs=common#disable-new-dma-devices-when-this-computer-is-locked). always use hibernate instead of sleep because it activates Bitlocker. Device in sleep or awake status is not protected by Bitlocker. and the most impratant thing: turn Bitlocker on.  
> I’m not a native English speaker so there’s a lot of grammar mistakes in my answer.

Pretty sure I have DMA protection, right?

---

## Post 79 by @Sprout3425 — 2024-01-04T15:14:02Z

> [@anon34108895](#):
>
> - turn Secure boot on and disable **third party Microsoft UEFI CA** which is for Linux.
> - turn virtulization related settings on.
> - turn Thunderbolt related security settings to the highest level.
> - set Bios password.
> - only boot your hard drive and disable all other items in the boot sequence settings.
> - turn on TPM and set Pluton as default it you have it.

I remember before this changing BIOS settings recommended in the Windows Guide preview. Now, it is important to mention that I am using Lenovo BIOS, I could not find anything related to what you said except for setting a password, and turning on secure boot. There were three passwords I could set, user, HDD and administrator, and a ‘power-on-password’ setting or something like that. I have set an administrator password previously, not sure whether I should set the ‘power-on-password’ setting or the user or HDD settings. From my brief research, it seems I shouldn’t.

---

## Post 80 by @sha123 — 2024-01-04T15:15:28Z

> [@Sprout3425](#):
>
> all the settings I can see have an ‘Ok’ status.
> 
> ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/3/3c73ce9fc1f7356b76a52d9f13f0c32a6e1cc8b7.png)

Hm, that’s quite surprising since a few settings clearly say that MDM is a requirement and on my device Edge marked these settings with an error. Not sure how you did that, but it seems like you don’t need the MDM fake enrollment

---

## Post 81 by @Sprout3425 — 2024-01-04T15:15:34Z

> [@anon34108895](#):
>
> - Secure Launch aka system guard secure launch aka firmware protection. smm protection is included in secure launch. this [requires](https://learn.microsoft.com/en-us/windows/security/hardware-security/how-hardware-based-root-of-trust-helps-protect-windows#system-requirements-for-system-guard) a Intel vPro CPU. If your device is compatiable, turn it on.
> - hardware enforced stack protection. [requirments](https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-11-version-22h2-security-baseline/ba-p/3632520#:~:text=There%20is%20a%20hardware%20dependency%20for%20this%20new%20feature%20that%20requires%20Intel%20Tiger%20Lake%20and%20beyond%20or%20AMD%20Zen3%20and%20beyond.). If your device is compatiable, turn it on.

Not sure whether my device (Legion 5P 15IMH05H) is compatible for these settings. However, I have turned them on regardless. :rofl:

---

## Post 82 by @Sprout3425 — 2024-01-04T15:18:57Z

I have signed in with my University account of Microsoft 365 services before, and Edge I think. How is the term Mobile-Device-Management-Solutions relevant to me, someone who is using a laptop?

---

## Post 83 by @Sprout3425 — 2024-01-04T15:46:47Z

> [@anon34108895](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/sprout3425/48/8_2.png) Sprout3425:
> 
> > Windows Security \> App browser & control \> Exploit protection settings \> **Programme settings**
> 
> There is a baseline file for this. it’s in baseline.zip/scripts/configfiles/ep-reset.xml. config the policy **Windows components** \> **Windows Defender Exploit Guard** \> **Exploit Protection** \> **Use a common set of exploit protection settings** to use the xml.

I tried doing this, I enabled the setting and then used the URL by opening the file in Edge. I read that there a prerequisites, no idea what they are as I genuinely can’t understand what the description is trying to say. Hopefully, I have done this successfully.

Why wasn’t this done in the script? Have I even applied this baseline successfully in the first place (could someone check the solution post, which entails how I applied this baseline, perhaps unsuccessfully)?

Also, I just noticed the .xml file disappeared from my configs folder, will the URL still work?

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/b/b2f52d0ce9ca6d7bfcbcef8f3c99f06b19b0722b.jpeg)

---

## Post 84 by @anon34108895 — 2024-01-05T05:43:03Z

> [@Sprout3425](#):
>
> Pretty sure I have DMA protection, right?

Yes according to your msinfo.

> [@Sprout3425](#):
>
> Status for firmware protections is _Off_.

Your device are not compatible with it.

> [@Sprout3425](#):
>
> I could not find anything related to what you said except for setting a password, and turning on secure boot.

what about boot order/ boot sequence?

> [@Sprout3425](#):
>
> Also, I just noticed the .xml file disappeared from my configs folder, will the URL still work?

the correct form of the path is like this:  
C:\EP-reset\EP-reset.xml

---

## Post 85 by @Sprout3425 — 2024-01-06T12:40:30Z

Thanks so much @fiwayan173, you have provided some immensely helpful links. Keep in mind that I have applied the Windows 11 v23H2 Security Baseline, the Microsoft 365 Apps for Enterprise 2306 baseline and the Microsoft Edge v117 Security Baseline. I say this because some policies you mention may be covered in these baselines.

These are my **final** questions (all of them are regarding policies, all of which I assume aren’t covered in the baselines):

- You mention the [Attack surface reduction rules reference](https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#attack-surface-reduction-rules-by-type), to reiterate, you will have to be more specific with me, as I have _no_ knowledge in computer science. In general, I am requesting a brief run down on _how_ to apply your recommendations (specifically the ones I mention that I need help with in this post), which you have already confirmed are suitable for all basic users who want to improve their privacy. Unfortunately, Microsoft’s documentation is not meant to be read by lay people, like me. So, along with your recommendations a quick explanation on _how_ to apply them, _what_ they do and _why_ we should use them, would be excellent.

- These recommendations in particular:

> [@Windows Guide](https://discuss.privacyguides.net/t/windows-guide/250/157):
>
> enable [complete mitigations](https://support.microsoft.com/en-us/topic/kb4073119-windows-client-guidance-for-it-pros-to-protect-against-silicon-based-microarchitectural-and-speculative-execution-side-channel-vulnerabilities-35820a8a-ae13-1299-88cc-357f104f5b11#:~:text=that%20are%20running.-,Registry%20settings,-We%20provide%C2%A0the) for side channel attacks. also [this](https://learn.microsoft.com/en-us/virtualization/hyper-v-on-windows/cve-2017-5715-and-hyper-v-vms#ensure-hyper-v-is-configured-to-expose-new-processor-capabilities-to-guest-virtual-machines)

Are particularly hard to know what on Earth is going on. The pages are speaking in different tongues. :rofl:And I can’t even find the specific settings to change, how to change them, or understand why I need to change them within the linked pages.

- Regarding the [Windows Restricted Traffic Limited Functionality Baseline](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#bkmk-general), you recommend applying the [24. Microsoft Defender Antivirus](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#bkmk-defender), [29. Windows Update](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#bkmk-wu) and [28. Delivery Optimization](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#bkmk-updates) settings, whereas Microsoft states: “For security reasons, it is important to take care in deciding which settings to configure as some of them may result in a less secure device. Examples of settings that can lead to a less secure device configuration include: Windows Update, Automatic Root Certificates Update, and Microsoft Defender Antivirus. Accordingly, we do not recommend disabling any of these features.” Why is this?

- You mentions these pages: [1](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls#policy-setting-for-diagnostic-data) and [2](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls#policy-settings-for-connected-experiences), in this context:

> [@fiwayan173](#):
>
> For office there are just 2 settings([1](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls#policy-setting-for-diagnostic-data) [2](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls#policy-settings-for-connected-experiences)). you can download group policies [here](https://discuss.privacyguides.net/t/windows-guide/250/162).  
> No the privacy related settings are not included in the security baseline at least for Edge and Office.

This is confusingly worded. Firstly, aren’t the Office and Edge settings covered in the [Microsoft 365 Apps for Enterprise 2306 baseline](https://www.microsoft.com/en-us/download/details.aspx?id=55319)?

Secondly, in your quote you make a link to your other quote:

> [@Windows Guide](https://discuss.privacyguides.net/t/windows-guide/250/162):
>
> Btw you need to download [Edge](https://www.microsoft.com/en-us/edge/business/download?ch=1&form=MA13FJ) policy and [office](https://www.microsoft.com/en-sa/download/details.aspx?id=49030) policy firstly before applying security baseline. Also remember to update them often. You can follow this [rss](https://techcommunity.microsoft.com/gxcuf89792/rss/board?board.id=Microsoft-Security-Baselines) feed.

It was a bit hard to piece together your quotes into a cohesive whole. After reading Microsoft’s documentation on these policies, where they say: “If you’re using Group Policy, you need to download the most current version of the Administrative Template files (ADMX/ADML) from the Microsoft Download Center.” I assume in order to apply these policies ([1](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls#policy-setting-for-diagnostic-data) and [2](https://learn.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls#policy-settings-for-connected-experiences)) one needs to apply the [Administrative Template files (ADMX/ADML) and Office Customization Tool for Microsoft 365 Apps for enterprise, Office 2019, and Office 2016](https://www.microsoft.com/en-sa/download/details.aspx?id=49030) first. Is this what you meant to say?

Once again to someone who is illiterate in this field, a simple explanation on how on Earth to use and apply the [Administrative Template files](https://www.microsoft.com/en-sa/download/details.aspx?id=49030), would be highly appreciated.

- You suggest these [policies](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-microsoft-accounts#restrict-the-use-of-microsoft-accounts) to “disable one’s Microsoft account”, do you know if any integral functionality may be lost by doing this?

- I need help with enabling Smart App Control which you all suggested WDAC, how do I do this exactly (easiest way)?

- Lastly, you say:

> [@Windows Guide](https://discuss.privacyguides.net/t/windows-guide/250/157):
>
> these settings to improve security. [1](https://www.microsoft.com/en-us/security/blog/2018/10/26/windows-defender-antivirus-can-now-run-in-a-sandbox/#:~:text=How%20to%20enable%20sandboxing%20for%20Windows%20Defender%20Antivirus%20today) [2](https://learn.microsoft.com/en-us/windows/security/identity-protection/access-control/local-accounts#enforce-local-account-restrictions-for-remote-access) [3](https://learn.microsoft.com/en-us/windows/security/identity-protection/remote-credential-guard?tabs=gpo#enable-delegation-of-nonexportable-credentials-on-the-remote-hosts) [4](https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2014/2915720?redirectedfrom=MSDN#suggested-actions) [5](https://support.microsoft.com/en-us/topic/kb5032314-how-to-manage-the-ole-object-conversion-vulnerability-associated-with-cve-2023-36563-98d95ae9-2f9e-4f65-9231-46363c31cf07#:~:text=If%20you%20have%20applications%20in%20your%20environment%20that%20are%20at%20risk%20of%20this%20vulnerability%2C%20follow%20these%20steps%20to%20mitigate%20the%20vulnerability)

The second ‘setting’ is a link to a page consisting of multiple topics, which cover multiple settings each, so are you referring specifically to the _Enforce local account restrictions for remote access_ topic or all of the settings covered by this page? It would be helpful to specify. Furthermore, the _Enforce local account restrictions for remote access_ topic seemed to be already applied by the Windows security baseline.

The same goes with the other links, you helpfully link to what appears to be one topic within the page, but I do not know if I should read and apply the other topics. For the third link, you link to _Enable delegation of nonexportable credentials on the remote hosts_, underneath is another heading: _Configure delegation of credentials on the clients_, followed by more headings. Should I stick only to the topic you provided? More importantly, we should first ask ourselves: are these individual topics already covered by the baseline? Potentially saving us time. Further update: the _Enable delegation of nonexportable credentials on the remote hosts_ topic within the third link was also already covered by the baseline. Also, the [fifth link](https://support.microsoft.com/en-us/topic/kb5032314-how-to-manage-the-ole-object-conversion-vulnerability-associated-with-cve-2023-36563-98d95ae9-2f9e-4f65-9231-46363c31cf07#:~:text=If%20you%20have%20applications%20in%20your%20environment%20that%20are%20at%20risk%20of%20this%20vulnerability%2C%20follow%20these%20steps%20to%20mitigate%20the%20vulnerability) apparently doesn’t apply to the latest version of Windows 11.

I have no idea what is going on with the [fourth link](https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2014/2915720?redirectedfrom=MSDN#suggested-actions).

---

## Post 87 by @sha123 — 2024-01-06T20:12:37Z

> [@Sprout3425](#):
>
> requesting a brief run down on _how_ to apply your recommendations

Most of the ASR rules are already implemented by the security baselines.

> [@Sprout3425](#):
>
> Unfortunately, Microsoft’s documentation is not meant to be read by lay people, like me

Microsoft docs are terrible, but you don’t need prior computer science education to implement these things. It just takes a lot of effort and is really cumbersome.

---

## Post 88 by @jerm — 2024-01-06T23:18:59Z

> **[GitHub - starchturrets/windows-shenanigans: Just my notes on how to](https://github.com/starchturrets/windows-shenanigans)**
>
> Just my notes on how to

---

## Post 89 by @anon34108895 — 2024-01-07T13:08:44Z

> [@sha123](#):
>
> Is there any advantage in selecting `Secure Boot and DMA protection` that I overlooked?

no

> [@Sprout3425](#):
>
> You mention the [Attack surface reduction rules reference](https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#attack-surface-reduction-rules-by-type)

In group Policy editor, open **Windows components** \> **Microsoft Defender Antivirus** \> **Microsoft Defender Exploit Guard** \> **Attack surface reduction** \> **Configure Attack Surface Reduction rules**. You would see 13 lines there. add these 3 lines  
56a863a9-875e-4185-98a7-b882c64b5ce5  
d1e49aac-8f56-4280-b9ba-993a6d77406c  
01443614-cd74-433a-b99e-2ecdc07bfc25  
then change the value of all 16 lines from 1 to 6.  
Basiclly these rules warn you when you are doing sth that may get your pc infected. Only if you click allow can you continue to execute the dangerous operation.

> [@Sprout3425](#):
>
> Are particularly hard to know what on Earth is going on. The pages are speaking in different tongues.

If your CPU is Intel, execute the following command in an adminstrator command prompt or powershell:

```
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverrideMask /t REG_DWORD /d 3 /f
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverride /t REG_DWORD /d 72 /f
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Virtualization" /v MinVmVersionForCpuBasedMitigations /t REG_SZ /d "1.0" /f
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Virtualization" /v RetsPredictedFromRsbOnly /t REG_DWORD /d 1 /f
```

These settings slow down your PC a bit but make your PC more secure against some CPU exploit.

> [@Sprout3425](#):
>
> This is confusingly worded. Firstly, aren’t the Office and Edge settings covered in the [Microsoft 365 Apps for Enterprise 2306 baseline](https://www.microsoft.com/en-us/download/details.aspx?id=55319)?

The **security** baseline do not include **privacy** related settings, no matter if it’s Windows, Office or Edge.

> [@Sprout3425](#):
>
> Is this what you meant to say?

Yes. I’m not sure if security baseline can do this for you automaticlly. Open group policy editor, if you can see items like

```
Administrative template
    >start menu and task bar
    ...
    >Microsoft Edge
    ...
    >Microsoft office 2016
    ...
    >Windows Components
    ...
```

then you donot have to do it manually.  
To do it manually, take edge for example. In this [page](https://www.microsoft.com/en-us/edge/business/download?form=MA13FJ), click Download Windows 64-bit Policy. extract cab file. find MicrosoftEdgePolicyTemplates.zip\>windows\>admx\>msedge.admx. put this file in your C:\Windows\PolicyDefinitions folder. then find icrosoftEdgePolicyTemplates.zip\>windows\>admx\>(your locale code)\>msedge.adml and put this in C:\Windows\PolicyDefinitions(your locale code) folder.

> [@Sprout3425](#):
>
> You suggest these [policies](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/understand-microsoft-accounts#restrict-the-use-of-microsoft-accounts) to “disable one’s Microsoft account”, do you know if any integral functionality may be lost by doing this?

If you have sign in MS account in your Windows (i.e. you are not using a loocal account) and your using Windowsm Hello, then WIndows Hello(PIN, finderprint and face) won’t work after you setting these polices. You can also not log in Microsoft store and any other native apps using MS account.

> [@Sprout3425](#):
>
> The second ‘setting’ is a link to a page consisting of multiple topics, which cover multiple settings each, so are you referring specifically to the _Enforce local account restrictions for remote access_ topic or all of the settings covered by this page? It would be helpful to specify. Furthermore, the _Enforce local account restrictions for remote access_ topic seemed to be already applied by the Windows security baseline.
> 
> The same goes with the other links, you helpfully link to what appears to be one topic within the page, but I do not know if I should read and apply the other topics. For the third link, you link to _Enable delegation of nonexportable credentials on the remote hosts_, underneath is another heading: _Configure delegation of credentials on the clients_, followed by more headings. Should I stick only to the topic you provided? More importantly, we should first ask ourselves: are these individual topics already covered by the baseline? Potentially saving us time. Further update: the _Enable delegation of nonexportable credentials on the remote hosts_ topic within the third link was also already covered by the baseline. Also, the [fifth link](https://support.microsoft.com/en-us/topic/kb5032314-how-to-manage-the-ole-object-conversion-vulnerability-associated-with-cve-2023-36563-98d95ae9-2f9e-4f65-9231-46363c31cf07#:~:text=If%20you%20have%20applications%20in%20your%20environment%20that%20are%20at%20risk%20of%20this%20vulnerability%2C%20follow%20these%20steps%20to%20mitigate%20the%20vulnerability) apparently doesn’t apply to the latest version of Windows 11.
> 
> I have no idea what is going on with the [fourth link](https://learn.microsoft.com/en-us/security-updates/SecurityAdvisories/2014/2915720?redirectedfrom=MSDN#suggested-actions).

6 settings for 5 links (command prompt in adminstrator)

```
setx /M MP_FORCE_USE_SANDBOX 1
reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 0 /f
reg add "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa" /v DisableRestrictedAdmin /t REG_DWORD /d 0 /f
reg add "HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config" /v EnableCertPaddingCheck /t REG_DWORD /d 1 /f
reg add "HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config" /v EnableCertPaddingCheck /t REG_DWORD /d 1 /f
reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\OLELinkConversionFromOLESTREAMToIStorage" /v Disabled /t REG_DWORD /d 1 /f
```

> [@Sprout3425](#):
>
> I need help with enabling Smart App Control which you all suggested WDAC, how do I do this exactly (easiest way)?

SAC requires a clean install. If you cannot do this, use WDAC.

1. [Install](https://webapp-wdac-wizard.azurewebsites.net/) WDAC Wizard then open it
2. policy creater-base policy-signed and reputable mode- policy Rules:disable audit mode-File rules:merge with 2 rules checked-done.
3. find your creatd cip file. in your adminstrator command prompt

```
$PolicyBinary = ""C:\Users\aaaaaaaaaaa\Documents\{86983A4B-5CF4-4E82-9E54-4A6DF14E3FA3}.cip""
CiTool --update-policy $PolicyBinary [-json]
```

done.  
4. to disable the WDAC policy  
`CiTool.exe -rp "{86983A4B-5CF4-4E82-9E54-4A6DF14E3FA3}" -json`  
5. WDAC is not suitable for everyone.

---

## Post 90 by @Sprout3425 — 2024-01-07T13:12:51Z

Before properly reading this I can say: thanks you are a saint, this seems to be the level of detail I was looking for.

---

## Post 91 by @anon34108895 — 2024-01-07T13:41:46Z

There are a few final settings to note. they are not in the baseline and not mentioned before.  
1 Recently Microsoft Edge decides some policies are not applicable if you are logging in Edge using a personal account. so do not log in Edge. Enable [this](https://docs.microsoft.com/DeployEdge/microsoft-edge-policies#browsersignin) and set it to disallow.  
2 disallow Microsoft account in office: Administrative Templates (Users)\>Microsoft Office 2016\>Miscellaneous\> Block signing into Office  
3 do not add your personal pc to a domain. I also do not suggest logging your work or school MS account in your personal PC. use browser in incognito mode to access school or work resource. your work or school MS account is not controled by you. your school can see everything in it. often these kind of account are not secure(lack of 2fa, security key etc). usually you can also not delete your school account. you have to ask for school admin for deleting. avoid using school or work ms account unless it’s a must for you.

---

## Post 92 by @Sprout3425 — 2024-01-09T02:46:38Z

Hmm, I need to log in to Excel, Word and PowerPoint to get licenses for them I think. May be wrong

---

## Post 93 by @Sprout3425 — 2024-01-09T02:51:14Z

Not sure which ones to disable, pretty sure connected experiences are essential for me as a uni student, but not 100% sure what they do. I did read their descriptions  
Allow the use of connected experiences in Office that analyze content  
Allow the use of connected experiences in Office that download online content  
Allow the use of additional optional connected experiences in Office  
Allow the use of connected experiences in Office

---

## Post 94 by @Sprout3425 — 2024-01-09T02:52:01Z

Thanks so much though, all of this went pretty smoothly!

---

## Post 95 by @Sprout3425 — 2024-01-09T05:51:21Z

## Final solution

**Disclaimer** : I have no knowledge in this field, therefore, I have certainly missed steps, or done steps incorrectly, so please feel free to correct me. Furthermore, make sure you understand the purposes of the recommended settings before applying them (you can always revert individual settings). Please feel free to suggest edits to this post so I can add more information on the purpose of each setting and the impacts of each settings on your system, as well as formatting advice.

Shout out to @anon34108895 and @sha123.

* * *

**1.**  **Before applying the security baseline** you need to do the following:

- Navigate to the [Microsoft Edge for Business download page](https://www.microsoft.com/en-us/edge/business/download?form=MA13FJ).

- Click on ‘ **Download Windows 64-bit Policy** ’. Please note that this is different from the main download button located above it.

- After downloading, extract the ‘ **MicrosoftEdgePolicyTemplates.cab** ’ file. This will create a file named ‘ **MicrosoftEdgePolicyTemplates.zip** ’.

- Open the ‘ **MicrosoftEdgePolicyTemplates.zip** ’ file.

- Navigate to the following path within the zip file: `MicrosoftEdgePolicyTemplates.zip > windows > admx > msedge.admx`.

- Move the ‘ **msedge.admx** ’ file to your `C:\Windows\PolicyDefinitions` folder.

- Next, find the file at this path: `MicrosoftEdgePolicyTemplates.zip > windows > admx > (your locale code) > msedge.adml`.

- Move the ‘ **msedge.adml** ’ file to your `C:\Windows\PolicyDefinitions(your locale code)` folder.

- **Download** the [Administrative Template files (ADMX/ADML) and Office Customization Tool for Microsoft 365 Apps for enterprise, Office 2019, and Office 2016](https://www.microsoft.com/en-us/download/details.aspx?id=49030).

- Click the **big blue download button**.

- Find the ‘ **admintemplates\_x64\_5423.1000\_en-us.exe** ’ file, open it, accept the conditions, then choose a folder for it to extract files there. For example, you can choose the ‘Downloads’ folder.

- It will create two side-by-side folders named ‘ **admin** ’ and ‘ **admx** ’.

- Open the ‘ **admx** ’ folder and copy all the files with the format ‘ **something16.admx** ’ over to the `C:\Windows\PolicyDefinitions` folder.

- Similarly, for the language-specific files, navigate to the ‘**admx \> (your locale code)**’ folder within the ‘ **admin** ’ folder.

- Copy all the ‘ **something16.adml** ’ files to your `C:\Windows\PolicyDefinitions(your locale code)` folder.

I am using **Fluent Reader** to subscribe to the [https://techcommunity.microsoft.com/gxcuf89792/rss/board?board.id=Microsoft-Security-Baselines](https://techcommunity.microsoft.com/gxcuf89792/rss/board?board.id=Microsoft-Security-Baselines) (use the URL and click ‘add source’ on Fluent Reader), where update for the security baseline are updated by Microsoft. However, I do not know whether I have the time to update these baselines and apply them again.

* * *

**2.**  **Apply the Windows security baselines.**

- **Warning** : Baselines affect hundreds of settings, but you can create a recovery point before proceeding with the following steps!

1. Download the **‘Windows 11 v23H2 Security Baseline.zip’** , **‘Microsoft Edge v117 Security Baseline.zip’** and **‘Microsoft 365 Apps for Enterprise 2306.zip’** and **‘LGPO.zip’** files [from here](https://www.microsoft.com/en-us/download/details.aspx?id=55319).

- I will show you how to apply the ‘Windows 11 v23H2 Security Baseline’ below, the steps are the same for the ‘Microsoft Edge v117 Security Baseline.zip’ and ‘Microsoft 365 Apps for Enterprise 2306.zip’ files.

- Begin by **unzipping** both the ‘LGPO.zip’ and ‘Windows 11 v23H2 Security Baseline.zip’ files.

- In the unzipped LGPO file, navigate to `LGPO_30 > LGPO.exe`.

- **Copy** the `LGPO.exe` file to `Windows 11 v23H2 Security Baseline > Scripts > Tools`.

- **Open** Windows PowerShell as an administrator.

- **Change** the directory to the Scripts folder in the Windows 11 v23H2 Security Baseline file by typing:

```
cd 'C:\Users\Redacted\Downloads\Windows 11 v23H2 Security Baseline\Windows 11 v23H2 Security Baseline\Scripts'
```

- **Set** the execution policy to unrestricted for the current process by typing:

```
Set-ExecutionPolicy -Scope Process Unrestricted
```

- You will be prompted with a message about the execution policy change. **Respond** with `Y` to confirm the change.

- **Run** the `Baseline-LocalInstall.ps1` script with the `-Win11NonDomainJoined` parameter (if your device is not connected to a **domain** [which I don’t know what this is to be honest]) by typing:

```
.\Baseline-LocalInstall.ps1 -Win11NonDomainJoined
```

- You will receive a security warning. **Respond** with `R` to run the script once.

- Leave PowerShell open and repeat the steps above for the other two baselines: **‘Microsoft Edge v117 Security Baseline.zip’** and **‘Microsoft 365 Apps for Enterprise 2306.zip’**.

- Once you have finished applying the three baselines, open PowerShell as an administrator and type in the following to set the execution policy for the LocalMachine scope to `AllSigned`:

```
Set-ExecutionPolicy -ExecutionPolicy AllSigned
```

- Now, click enter. You will be prompted with a message about the execution policy change. **Respond** with `Y` to confirm the change.

* * *

**3.** The baseline configuration will disable Controlled Folder Access, setting it to Audit Mode. If you want to change this setting to Block, you can do so manually.

- Open the Group Policy Management Editor.

- Navigate to `Computer Configuration` and select `Administrative Templates`.

- Expand the tree to the following path:

```
Windows components > Microsoft Defender Antivirus > Microsoft Defender Exploit Guard > Controlled folder access
```

- Double-click on the `Configure Controlled folder access` setting.

- In the options, set it to `Enabled`.

- This will enable the Controlled Folder Access setting in Microsoft Defender. Please note that this might restrict access to protected folders by applications, which can affect their functionality.

- After applying the baseline, there is an additional step you should take. There is a specific file for this in the baseline package.

- Locate the file `ep-reset.xml` in the following path within the baseline package:

```
Windows 11 v23H2 Security Baseline.zip/scripts/configfiles/ep-reset.xml
```

- You need to configure a policy to use this XML file. In the Group Policy Management Editor, navigate to the following path:

```
Windows components > Windows Defender Exploit Guard > Exploit Protection > Use a common set of exploit protection settings
```

- Configure this policy to use the `ep-reset.xml` file.

- This will apply a common set of exploit protection settings across your system, enhancing its security. Please note that changes to security settings can have significant impacts on your system. Always ensure you understand the changes you’re making, and consider backing up your system before making any modifications. If you’re unsure, seek assistance from a professional.

* * *

**4. Important settings:**

- Before adjusting the **Virtualization Based Security** policy, there are several BIOS settings you should modify:

- **Secure Boot** : Turn this on and (if applicable) disable the third-party Microsoft UEFI CA which is for Linux.

- **Virtualization Settings** : Turn these on (this was @anon34108895’s advice, I have no idea what these are specifically).

- **Thunderbolt Security Settings** : Set these to the highest level (again, if applicable I couldn’t find these).

- **BIOS Password** : Set a BIOS password.

- **Boot Sequence Settings** : Only boot your hard drive and disable all other items (if applicable, I couldn’t find these).

- **TPM** : Turn on TPM and set Pluton as default if you have it (if applicable, I couldn’t find these).

- After adjusting the BIOS settings, navigate to the policy by clicking `Computer Configuration > Administrative Templates > System > Device Guard > Turn On Virtualization Based Security`. This policy contains several important settings that cannot be easily reverted to default status:

- **Secure Boot and DMA Protection** : If your laptop was shipped after 2018, select it to secure boot and DMA protection.

- **VBS (Code Integrity)**: Most hardware is compatible with this. Select it to on/on with UEFI lock. UEFI lock means this setting is written to your BIOS rather than only the system (Windows). Also, turn on `Require UEFI Memory Attributes Table`.

- **Credential Guard** : Select it to on/on with UEFI lock.

- **Secure Launch (System Guard Secure Launch/Firmware Protection)**: SMM protection is included in secure launch. This requires an Intel vPro CPU. If your device is compatible, turn it on.

- **Hardware Enforced Stack Protection** : If your device is compatible, turn it on.

* * *

**5. Turning on Smart App Control without using Windows Defender settings:**

- First, install the [WDAC Wizard on your system](https://webapp-wdac-wizard.azurewebsites.net/packages/WDACWizard_2.4.1.0_x64_8wekyb3d8bbwe.MSIX).

- Open the WDAC Wizard and follow these steps:

- Once done, click ‘Finish’.

- Find the `.cip` file you created (it should be in your Documents folder). Open an administrator command prompt and execute the following command:

```
$PolicyBinary = "C:\Users\YourUsername\Documents\{BF7C2699-87B0-4A61-B0D5-EED077419032}.cip"
CiTool --update-policy $PolicyBinary [-json]
```

- Replace `YourUsername` with your actual username.

- If you need to disable the WDAC policy, use the following command:

```
CiTool.exe -rp "{BF7C2699-87B0-4A61-B0D5-EED077419032}" -json
```

- **Note:** WDAC might not be suitable for everyone due to its strict control over applications. Please consider your needs and system requirements before enabling it.

* * *

**6. Apply additional measures as recommended by @anon34108895:**

- **Configuring Attack Surface Reduction Rules:**

- In the Group Policy Editor, navigate to the following path:

```
Windows components > Microsoft Defender Antivirus > Microsoft Defender Exploit Guard > Attack surface reduction > Configure Attack Surface Reduction rules
```

- This policy should already be enabled by the security baseline. Then, click the ‘Show’ option next to ‘See the state for each ASR rule’. You will see 13 lines there. Add these 3 lines:

```
56a863a9-875e-4185-98a7-b882c64b5ce5
d1e49aac-8f56-4280-b9ba-993a6d77406c
01443614-cd74-433a-b99e-2ecdc07bfc25
```

- Then, change the value of all 16 lines from 1 to 6. These rules warn you when you are about to perform an action that may infect your PC. You can only continue to execute the potentially dangerous operation if you click ‘allow’.

- **Securing your Intel CPU:**

- If your CPU is Intel, execute the following commands in an administrator command prompt or PowerShell:

```
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverrideMask /t REG_DWORD /d 3 /f
reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management" /v FeatureSettingsOverride /t REG_DWORD /d 72 /f
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Virtualization" /v MinVmVersionForCpuBasedMitigations /t REG_SZ /d "1.0" /f
reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Virtualization" /v RetsPredictedFromRsbOnly /t REG_DWORD /d 1 /f
```

- These settings may slow down your PC a bit but will make your PC more secure against some CPU exploits.

- **Some more recommended settings:**

- Open the command prompt as an administrator.

- Execute the following commands:

```
setx /M MP_FORCE_USE_SANDBOX 1
reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 0 /f
reg add "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa" /v DisableRestrictedAdmin /t REG_DWORD /d 0 /f
reg add "HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config" /v EnableCertPaddingCheck /t REG_DWORD /d 1 /f
reg add "HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config" /v EnableCertPaddingCheck /t REG_DWORD /d 1 /f
reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\OLELinkConversionFromOLESTREAMToIStorage" /v Disabled /t REG_DWORD /d 1 /f
```

Below are what the commands do:

```
setx /M MP_FORCE_USE_SANDBOX 1
```

- This command sets the environment variable `MP_FORCE_USE_SANDBOX` to `1`.

```
reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 0 /f
```

- This command disables the `LocalAccountTokenFilterPolicy`.

```
reg add "HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa" /v DisableRestrictedAdmin /t REG_DWORD /d 0 /f
```

- This command disables the `DisableRestrictedAdmin` policy.

```
reg add "HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Wintrust\Config" /v EnableCertPaddingCheck /t REG_DWORD /d 1 /f
```

- This command enables the `EnableCertPaddingCheck` policy.

```
reg add "HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config" /v EnableCertPaddingCheck /t REG_DWORD /d 1 /f
```

- This command enables the `EnableCertPaddingCheck` policy for 32-bit applications on 64-bit platforms.

```
reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\AppCompat\OLELinkConversionFromOLESTREAMToIStorage" /v Disabled /t REG_DWORD /d 1 /f
```

- This command disables the `OLELinkConversionFromOLESTREAMToIStorage` policy.

## Windows privacy

- Just like the Windows security baselines you can apply the [Windows Restricted Traffic Limited Functionality Baseline](https://download.microsoft.com/download/D/9/0/D905766D-FEDA-43E5-86ED-8987CEBD8D89/WindowsRTLFB.zip), however, not all settings within this baseline are recommended. Which settings to apply and not to apply is a work in progress for me. We will need more discussion on this matter.

## Well done! Congradulations :slight_smile:

---

## Post 96 by @Sprout3425 — 2024-01-09T05:53:02Z

> [@sha123](#):
>
> The two main conflicting settings, were the defender settings I wrote

What are these specifically, I can’t find what you are referring to?

---

## Post 97 by @Sprout3425 — 2024-01-09T06:01:21Z

One of my last questions goes unaddressed: Regarding the [Windows Restricted Traffic Limited Functionality Baseline](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#bkmk-general), @anon34108895 you recommend applying the [24. Microsoft Defender Antivirus](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#bkmk-defender), [29. Windows Update](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#bkmk-wu) and [28. Delivery Optimization](https://learn.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#bkmk-updates) settings, whereas Microsoft states: “For security reasons, it is important to take care in deciding which settings to configure as some of them may result in a less secure device. Examples of settings that can lead to a less secure device configuration include: Windows Update, Automatic Root Certificates Update, and Microsoft Defender Antivirus. Accordingly, we do not recommend disabling any of these features. Why is this?

---

## Post 98 by @sha123 — 2024-01-09T11:27:31Z

Yay, you did it!

Nice write-up. Haven’t looked into it in detail, but looks good on first sight.

Two important points to edit into your comment:

1. Some settings in the security baselines are privacy invasive, which is why you need to take care about privacy afterwards. Especially take a look at Smartscreen and MS Defender settings.

2. A warning that RTLFB should never be applied blindly because it breaks Windows, Defender and certificate updates and a few other things.

---

## Post 99 by @sha123 — 2024-01-09T11:31:35Z

> [@Sprout3425](#):
>
> What are these specifically, I can’t find what you are referring to?

['Hardening' Windows - #51 by Sprout3425](https://discuss.privacyguides.net/t/hardening-windows/15750/51) . These are the most important, but not the only ones.

MS Office and Edge also need privacy settings, the former only a few, the latter quite many.

---

## Post 100 by @Sprout3425 — 2024-01-09T12:58:25Z

Haha bittersweet was a pain in the… Yay to you for helping. also Couldn’t have done it without @anon34108895

---

## Post 101 by @dngray — 2024-02-05T14:35:43Z

> [@Inclusion of a basic guide/ recommendation column for hardening Windows](https://discuss.privacyguides.net/t/inclusion-of-a-basic-guide-recommendation-column-for-hardening-windows/11170/9):
>
> This is something that unfortunately has languished because I know that to write it I would have to do a lot of research to know it is correct. We were thinking of a guide something along the lines of setting some LGPOs, however I do want to avoid something which breaks normal functionality of Windows. As Privacy Guides does accept community contributions, this certainly is an area someone experienced could teach us about.

See my reply, I think we should also consider some of the feedback in [update!: Windows guide by IkelAtomig · Pull Request #1659 · privacyguides/privacyguides.org · GitHub](https://github.com/privacyguides/privacyguides.org/pull/1659)

Ideally a PR which could perhaps include some of that/superseed would be good, we can always give credit to all authors (as co-authors).

---

## Post 102 by @Average_Joe — 2024-02-05T20:38:10Z

Some great information in this thread.

I haven’t seen much comparisons done between the security differences between Windows 10 and Windows 11.

**I’ve learned the hard way that “newer doesn’t translates to better”.**

Perhaps a thread dedicated to ‘Hardening Windows 11’ would be helpful as it seems like a big install compared to Windows 10.

---

## Post 103 by @dngray — 2024-02-06T12:08:41Z

Any guide should really mainly focus on Windows 11 as windows 10 is quite similar and will be unsupported end of next year anyway

---

## Post 105 by @anon34108895 — 2024-03-29T06:43:25Z

hey guys I created a new [Windows Guide](https://github.com/privacyguides/privacyguides.org/pull/2452) pr. everyone is welcomed!

---

## Post 106 by @Sprout3425 — 2024-03-29T11:29:37Z

Legend

---

## Post 107 by @anon72670793 — 2024-03-29T15:18:56Z

@anon34108895 Are we still allowed to post Windows Hardening stuff here?

I just had a quick addition. I’ve been using these two tools to set up my Windows 11.

> **[Windows 11 Perfect Install](https://christitus.com/windows-11-perfect-install/)**
>
> Having Fun with Technology

> **[privacy.sexy - Maximize Your Privacy and Security](https://privacy.sexy/)**
>
> Discover privacy.sexy, the privacy tool to maximize your privacy and security on Windows, macOS, and Linux. Easily use best practices to prevent tracking and make your life secure and private — because privacy is sexy.

Both are open source and much easier than doing a bunch of settings manually. Maybe there should be a basic hardening and an expert hardening section?

---

## Post 108 by @dngray — 2024-03-29T15:32:13Z

We’re reluctant to add tools which can break the system. I know privacy.sexy can do that quite easily.

---

## Post 109 by @anon72670793 — 2024-03-29T15:39:23Z

Understood, when it comes to issues with privacy.sexy, is this on Windows Standard mode? I’ve been using privacy.sexy on Standard mode for a while and haven’t had any issues, but I’ll start keeping a closer eye out.

I still think Chris Titus has a good Windows 11 setup to remove the basic stuff. Not sure if any issue reported to his stuff causing issues though.

> **[Windows 11 Perfect Install](https://christitus.com/windows-11-perfect-install/)**
>
> Having Fun with Technology

> **[The Perfect Windows 11 Install](https://www.youtube.com/watch?si=zFouIERSZX2n3dU_&v=6UQZ5oQg8XA&feature=youtu.be)**
>
> Setting a clean Windows 11 is difficult with all the built-in bloat. This guide fixes all that to give you a clean system that is easy to manage.Website Guid...

---

## Post 110 by @exaCORE — 2024-03-29T20:46:05Z

> [@anon72670793](#):
>
> [Windows 11 Perfect Install](https://christitus.com/windows-11-perfect-install/)

The perfect windows 11 install is Linux :sunglasses:

---

## Post 111 by @Sprout3425 — 2024-03-30T02:07:30Z

Wish I could be bothered to use Linux, however, I have heard about compatibility issue with things like games, making it such an effort. Especially, if I needed to run apps that only work on Windows, I can’t be bothered to switch between operating systems. Hopefully, Ubuntu becomes a universal OS that can do everything, and makes it easy for “normal” people like me to do everything they need to do, without jumping through hurdles.

---

## Post 112 by @Sprout3425 — 2024-03-30T04:52:01Z

> [@anon72670793](#):
>
> Both are open source and much easier than doing a bunch of settings manually. Maybe there should be a basic hardening and an expert hardening section?

> [@dngray](#):
>
> We’re reluctant to add tools which can break the system. I know privacy.sexy can do that quite easily.

I am honestly begging you all (the legendary PG team) to review and test such tools, especially the safer ones, since they are such _huge_ time savers, and because they have the powerful potential to make privacy measures implemented across a much wider scale, which will benefit all of us by pressuring such design by default (the final step). Maybe in the future we could have a page dedicated to them, in the OS guides or the suggested tools categories.

Especially for “normal” people, one click solutions to improving ubiquitous products like Windows, are absolutely _essential_ for what I think are obvious reasons, which seems to align with the major goals of this website.

If you want I can make this a new topic, although I think I have done so in the past.

As for your concerns, I implemented the entire Windows Security Baseline by Microsoft, and only had I kid you not like one error (and my use case for Windows is pretty diverse), not to mention such tools already exist that provide excellent resources like brief explanations on the tradeoffs for specific settings and allow you to customise their configurations.

---

## Post 113 by @sha123 — 2024-04-01T20:59:21Z

privacy.sexy didn’t successfully apply a lot of settings on my test device, despite their program saying otherwise. Also has been buggy and was flagged by MS Defender. Some things are nice to take inspiration from (e.g. disabling some third-party telemetry of well-known software).

Can’t recommend Chris Titus either. I can’t trust someone who says a lot of questionable things in his video to know what he is doing. His tool also assembles other tools.

---

## Post 114 by @sha123 — 2024-04-01T21:10:37Z

Thx for putting in the work.

Would recommend to split Edge, Office, Windows Privacy and Windows Security each into separate pages. Otherwise it’s overwhelmingly long.

---

## Post 115 by @dngray — 2024-04-04T03:41:32Z

As this is one of the shorter threads I’m going to lock it and encourage future suggestions be made in: [Windows Guide](https://discuss.privacyguides.net/t/windows-guide/250/).

but it will take some work. Please continue discussion in the above thread.

---

## Post 116 by @dngray — 2024-04-04T03:41:38Z


