20
WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies #ILTALSS #LSS26

WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

  • Upload
    vonhi

  • View
    238

  • Download
    1

Embed Size (px)

Citation preview

Page 1: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

WINDOWS 10 ENTERPRISENew Security Features

J. Abernethy – mindSHIFT TechnologiesJosh Quinn – mindSHIFT Technologies

#ILTALSS #LSS26

Page 2: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

TODAY’S AGENDA

• Windows 10 Security Fundamentals• Managing Windows 10 Security• New Windows 10 Security Features

Page 3: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

WIN10 SECURITY FUNDAMENTALS

• Features Forward– Windows 7: NTFS, UAC, Windows Firewall,

BitLocker, AppLocker, Least Privilege, SmartScreen

– Windows 8: TPM Key Attestation, Kerberos Armoring, Modern App Isolation

• EMET now in Windows 10 core• Other areas: LAPS, MBAM

Page 4: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

Threat protection over timeAttackers take advantage of periods between releases

P R O D U C T R E L E A S E T H R E A T S O P H I S T I C A T I O N

T I M E

CA

PA

BIL

ITYGame change with

Windows and Software as a ServicesDisrupt and out innovate our adversaries by design

Protection Gap

WINDOWS 10:SERVICING MODEL

Page 5: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

WINDOWS 10:SERVICING MODEL

Page 6: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

MANAGING WINDOWS 10 SECURITY

• Group Policy• PowerShell• Mobile Device Management• System Center Configuration Manager

Page 7: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

WINDOWS 10:HARDENING GUIDELINES• OS Hardening guidelines still apply

– Center for Internet Security: Win10 Enterprise Benchmark– DISA guidelines

• Update to the latest ADMX templates relevant to your branch

• Specific Windows 10 areas to focus:– Privacy settings– Modern Application Management– New Security Features– Windows 10 “enhancements” – e.g. WLAN HotSpots, Lock screen

notifications

Page 8: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

PROTECT, DETECT & RESPONDPRE-BREACH POST-BREACH

Windows Defender ATP

Breach detection investigation &

response

Device protection

Device Health attestation

Device Guard

Device Control

Security policies

Information protection

Device protection / Drive encryption

Enterprise Data Protection

Conditional access

Threat resistance

SmartScreen

AppLocker

Device Guard

Windows Defender

Network/Firewall

Built-in 2FA

Account lockdown

Credential Guard Microsoft Passport

Windows Hello :)

Identity protection

Breach detection investigation &

response

Device protection

Information protection

Threat resistance

Conditional Access

Windows Defender ATP

Device integrity

Device control

BitLocker and BitLocker to Go

Windows Information Protection

SmartScreen

Windows Firewall

Microsoft Edge

Device Guard

Windows Defender

Windows Hello :)

Credential Guard

Identity protection

WIN10 – NEW SECURITY FEATURES

Page 9: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

DEVICE PROTECTION:DEVICE INTEGRITY & CONTROL• Trusted Platform Module

– What this allows, and why it is important– Foundation for many other technologies

• Secure Boot, Trusted Boot, ELAM– An advanced integrity check of your OS– Requires TPM 1.2, UEFI, Windows 8.1 or higher– Consider disabling pre-boot authentication!

Page 10: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

Kernel

Windows Platform Services

Apps

Kernel

System Container

Trus

tlet#

1

Trus

tlet#

2

Trus

tlet#

3

Hypervisor

Device Hardware

Windows Operating System

Hyper-VHyper-V

WINDOWS 10:VIRTUALIZATION BASED SECURITY

• Separate virtual environment with small surface area

• May store Code Integrity Policies, Credential Information, future initiatives

• Requires UEFI / Secure Boot, virtualization Extensions, Trusted Platform Module

• Compatible with Hyper-V

Page 11: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

• Previous Microsoft Whitelisting Options– Software Restriction

Policies– AppLocker

• Challenges– Vulnerable to Kernel

mode attacks– Management

THREAT RESISTANCE: DEVICE GUARD

Page 12: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

• Provides a security model similar to mobile device operating systems

• Only allows execution of signed applications and drivers but may be configured for “audit” mode

• Firms can establish their own integrity policies for the “master image” and unsigned applications, but will need to manage catalogs and code signing

• Leverages Virtualization Based Security Model

• Challenges……………..

THREAT RESISTANCE: DEVICE GUARD

Page 13: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

THREAT RESISTANCE: MICROSOFT EDGE

• Current Security Features– SmartScreen– Universal App Model– Protected Extensions– Small Surface Layer

• Application Guard– Leverages Virtualization Based Security– Provides Browser Containerization and

isolation– Available in Win10 Enterprise 16188

(Fast Ring)

Page 14: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

IDENTITY PROTECTION:CREDENTIAL GUARD

• Defends Against Pass-The-Hash style attacks• Requirements

– Win10 Enterprise/Education (x64)– UEFI / TPM 2.0+

• Challenges– Domain Credentials only!

Page 15: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

IDENTITY PROTECTION:WINDOWS HELLO FOR BUSINESS

• A world without passwords• “Multifactor” – Something you have (an

enrolled device), and something you know (a PIN)

• Biometrics provide convenience• Challenges

Page 16: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

INFORMATION PROTECTION: WIP OVERVIEW

• Platform integrated, no mode switching

• Classifies data coming from managed network locations and repositories

• “Enlightened” Apps are able to distinguish between corporate and personal data

• Controls copy/paste behavior

• Supports selective wipe

• Leverages SCCM, MDM for policy management

Page 17: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

INFORMATION PROTECTION: WIP CHALLENGES

• Number of Enlightened apps are limited• Limited 3rd party repository support• Auditing / monitoring is rudimentary• Single user per device• Redirected folders / Offline Cache are not

supported• May cause issues with application deployment

Page 18: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

BREACH DETECTION: WINDOWS DEFENDER ATP

• Behavior-based, cloud-powered breach detection system

• Agent is built in to Windows 10

• Leverages Microsoft’s threat intelligence knowledge base

• Powerful tool for investigation and analysis across endpoints

Page 19: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

WINDOWS 10 SECURITY RECOMMENDATIONS

Required

• BitLocker, MBAM, LAPS• SecureBoot, UEFI, TPM• OS Hardening, A/V, Firewall

Optional

• Credential Guard• Windows Defender ATP• Microsoft Edge Application Guard

Future

• Device Guard• Windows Information Protection• Windows Hello for Business

Page 20: WINDOWS 10 ENTERPRISE New Security Features Windows 1… · WINDOWS 10 ENTERPRISE New Security Features J. Abernethy – mindSHIFT Technologies Josh Quinn – mindSHIFT Technologies

Q & A Thank you for attending.

Matt Putney, Regional VP of SalesmindSHIFT Technologies

[email protected]

- or –www.mindshiftonline.com or www.123Together.com

Thank YouJosh QuinnManaging [email protected]

J AbernethyManager – Legal [email protected]

[email protected]