Windows Guide

There are some additional suggestions. Currently I donot have a github account so I cannot submit a pr.

  1. use a secured-core devices with timely firmware support. my personal reccomendation is surface for business series.
  2. turn on Smart App Control. if you have privacy concerns, skip this and use WDAC instead.
  3. configure Bitlocker to use TPM+PIN, long PIN length and 256 bit encryption
  4. Disable Microsoft account
  5. only update drivers through Windows Update or official websites. avoid softwares like Geforce Now
  6. do not show username on lock screen
  7. use yubikey as local account 2FA method
  8. turn off these telemetry.1 2 3
  9. enable complete mitigations for side channel attacks. also this
  10. these settings to improve security. 1 2 3 4 5
4 Likes