Saturday, November 2, 2024
HomeComputer SecurityMicrosoft Released Final Version of Security Configuration Baseline for Windows 10 and...

Microsoft Released Final Version of Security Configuration Baseline for Windows 10 and Windows Server

Published on

Malware protection

Microsoft published its final release of security configuration baseline settings for Windows 10 version 1903 and Windows Server version 1903.

Microsoft enables various controls to Windows users by providing multiple configuration capabilities since the organization needs to implement control over their security configurations.

Generally, Window security baseline applies to Windows 10, Windows Server 2016 and office 2016, But this final release of security configuration baseline settings referred only with Windows 10 and windows server.

- Advertisement - SIEM as a Service

A security baseline is a group of Microsoft-recommended configuration settings that explains their security impact. These settings are based on feedback from Microsoft security engineering teams, product groups, partners, and customers.

Microsoft defined over 3,000 Group Policy settings for Windows 10, which does not include over 1,800 Internet Explorer 11 settings. Of these 4,800 settings, only some are security-related.

New security configuration baseline settings

Microsoft brings some of the major updates with this new security baseline settings for Windows 10 and Windows server. Here some of the notable Baseline settings in this final release that updated by Microsoft.

  • Enable svchost.exe mitigation options – Enforces Stricter security on Windows services hosted in svchost.exe that controls all binaries loaded by svchost.exe must be signed by Microsoft. So it never allows 3rd party apps if its try to use the svchost.exe hosting process.
  • App Privacy setting – This baseline setting denies users to interact with applications using speech while the system is locked.
  • Disabling multicast name resolution– It eliminates the mitigate server spoofing threats.
  • Domain Controller baseline – Adding Recommended auditing settings for Kerberos authentication service.
  • Dropping the password-expiration policies – It stop the Password expiration policies for Windows, which required users to change their password periodically.
  • Cipher strength settings in BitLocker drive encryption – This baseline require the strongest available BitLocker encryption.

We can say that the implementation of shutting down the password expiration policy for Windows considering as one of the significant changes in this final security Configuration Baseline Settings for Windows 10. Read here why its shut down.

Disabling of the built-in Administrator & Guest accounts.

Microsoft also dropping the enforced disabling of the built-in Administrator and Guest accounts.

According to Microsoft, To keep baselines useful and manageable, we tend to enforce secure defaults for policy settings only when,
1) non-administrative users could otherwise override those defaults, or 2) misinformed administrators are otherwise likely to make poor choices about the setting. Neither of those conditions are true regarding enforcing the default disabling of the Administrator and Guest accounts.

The built-in Guest account -The Guest account (RID -501) is disabled by default on Windows 10 and Windows Server. Only an administrator can enable the Guest account, and an admin would presumably do so only for a valid reason such as for a kiosk system.

The built-in Administrator account – The local Administrator account (RID -500) is disabled by default on Windows 10 but not on Windows Server.

You can Download the content from the Microsoft Security Compliance Toolkit.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.

Also Read:

Attack Surface Analyzer 2.0 – Free Microsoft Tool to Detect Changes in Operating Systems While Installing Apps

 

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

LightSpy iOS Malware Enhanced with 28 New Destructive Plugins

The LightSpy threat actor exploited publicly available vulnerabilities and jailbreak kits to compromise iOS...

ATPC Cyber Forum to Focus on Next Generation Cybersecurity and Artificial Intelligence Issues

White House National Cyber Director, CEOs, Key Financial Services Companies, Congressional and Executive Branch...

New PySilon RAT Abusing Discord Platform to Maintain Persistence

Cybersecurity experts have identified a new Remote Access Trojan (RAT) named PySilon. This Trojan...

Konni APT Hackers Attacking Organizations with New Spear-Phishing Tactics

The notorious Konni Advanced Persistent Threat (APT) group has intensified its cyber assault on...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Google Chrome Security, Critical Vulnerabilities Patched

Google has updated its Chrome browser, addressing critical vulnerabilities that posed potential risks to...

New Windows Downgrade Attack Let Hackers Downgrade Patched Systems To Exploits

The researcher discovered a vulnerability in the Windows Update process that allowed them to...

Hackers Use Fog Ransomware To Attack SonicWall VPNs And Breach Corporate Networks

Recent cyberattacks involving Akira and Fog threat actors have targeted various industries, exploiting a...