1
Window 10 Security Primer by offline_ Boot BitLocker Encrypt Fixed Drives BitLocker To Go Encrypt Removable Drives Logon Password Running Learn More 4010 Lake Washington Blvd NE Suite 200 Kirkland, WA 98033 +1 (425) 823-4500 [email protected] adaptiva.com /adaptiva /adaptiva /company/adaptiva A quick reference guide of key Microsoft-related tools, features, and technologies to secure your Windows 10 environment for every endpoint state Maximize Firmware-Based Security Trusted Platform Module TPM Attestation Secure 10 On-Chip Cryptography and Security Authenticate Devices Migrate from BIOS to UEFI Control the Boot Process UEFI Protect Against Rootkits and Bootkits Secure Boot Trusted Boot Early Launch Anti-Malware Prevent Windows Bootloader Tampering Prevent Tampering with Windows Kernel and Components Block Untrusted Drivers Log Boot Process for Remote Attestation Measured Boot Windows Hello for Business Kerberos Armoring Compound Authentication Replace Passwords with Biometric or PIN Protect Tokens During Exchange Authenticate Both User and Device Deny Access to Insecure Systems Windows Device Health Attestation Account Lockout TPM Lockout Lock User Out Per Policy Software Devices Data Cyber Defense Prevent Unauthorized Changes Allow/Deny Running Applications AppLocker Separate Business Data from Personal Data Windows Information Protection Control File Access Based on Use and Device Attributes Dynamic Access Control Block Known-Dangerous Content Windows Defender SmartScreen Protect System and User Accounts against Threats Windows Defender Credential Guard Harden Endpoints Against Malware Windows Defender Device Guard Apply Security Configuration via Group Policy/MDM Device Restriction Policies Isolate Threats via Virtualization Windows Defender Application Guard Allow/Deny Running Applications Based on Cloud Reputation Windows Defender Application Control Protect PCs from Viruses, Malare and Ransomware Windows Defender Restrict Inbound/Outbound Network Traffic Windows Defender Firewall Protect Web Activity with Virtualized Browser Edge Browser Virtualization Simulate a Physical Smart Card Virtual Smart Cards Automate Security Configuration Management Client Health Apply Security Patches and Updates OneSite Learn more about the Adaptiva Windows 10 Accelerator Program at adaptiva.com/products Resolve Lockouts Access PC/Disk When Locked Out BitLocker Recovery User Account Control

Boot...Mar 07, 2018  · Windows 10 environment for every endpoint state Maximize Firmware-Based Security Trusted Platform Module TPM Attestation Secure 10 On-Chip Cryptography and

  • Upload
    others

  • View
    4

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Boot...Mar 07, 2018  · Windows 10 environment for every endpoint state Maximize Firmware-Based Security Trusted Platform Module TPM Attestation Secure 10 On-Chip Cryptography and

Window 10 Security Primer by

offline_

Boot

BitLocker

Encrypt Fixed Drives

BitLocker To Go

Encrypt Removable Drives

Logon

Password

Running

Learn More

4010 Lake Washington Blvd NE

Suite 200

Kirkland, WA 98033

+1 (425) 823-4500

[email protected]

adaptiva.com

/adaptiva

/adaptiva

/company/adaptiva

A quick reference guide of key Microsoft-related tools, features, and technologies to secure your Windows 10 environment for every endpoint state

Maximize Firmware-Based Security

Trusted PlatformModule

TPM Attestation Secure 10

On-Chip Cryptographyand Security

AuthenticateDevices

Migrate from BIOSto UEFI

Control theBoot Process

UEFI

Protect Against Rootkits and Bootkits

Secure Boot Trusted BootEarly LaunchAnti-Malware

Prevent Windows Bootloader Tampering

Prevent Tampering with WindowsKernel and Components

Block UntrustedDrivers

Log Boot Process forRemote Attestation

Measured Boot

Windows Hellofor Business

Kerberos ArmoringCompound

Authentication

Replace Passwordswith Biometric or PIN

Protect TokensDuring Exchange

Authenticate BothUser and Device

Deny Access toInsecure Systems

Windows DeviceHealth Attestation

AccountLockout

TPMLockout

Lock User Out Per Policy

Software Devices Data Cyber Defense

Prevent Unauthorized Changes

Allow/DenyRunning Applications

AppLocker

Separate Business Datafrom Personal Data

Windows InformationProtection

Control File Access Based onUse and Device Attributes

Dynamic AccessControl

Block Known-DangerousContent

Windows DefenderSmartScreen

Protect System andUser Accounts against Threats

Windows DefenderCredential Guard

Harden Endpoints AgainstMalware

Windows DefenderDevice Guard

Apply Security Configuration via Group Policy/MDM

Device RestrictionPolicies

Isolate Threats viaVirtualization

Windows DefenderApplication Guard

Allow/Deny Running ApplicationsBased on Cloud Reputation

Windows DefenderApplication Control

Protect PCs from Viruses, Malare and Ransomware

Windows Defender

Restrict Inbound/OutboundNetwork Tra�c

Windows DefenderFirewall

Protect Web Activity withVirtualized Browser

Edge BrowserVirtualization

Simulate a PhysicalSmart Card

Virtual Smart Cards

Automate Security Configuration Management

Client Health

Apply SecurityPatches and Updates

OneSite

Learn more about the Adaptiva Windows 10 Accelerator Program at adaptiva.com/products

ResolveLockouts

Access PC/DiskWhen Locked Out

BitLocker Recovery

User Account Control