Microsoft published its final release of security configuration baseline settings for Windows 10 version 1903 and Windows Server version 1903.
Microsoft enables various controls to Windows users by providing multiple configuration capabilities since the organization needs to implement control over their security configurations.
Generally, Window security baseline applies to Windows 10, Windows Server 2016 and office 2016, But this final release of security configuration baseline settings referred only with Windows 10 and windows server.
A security baseline is a group of Microsoft-recommended configuration settings that explains their security impact. These settings are based on feedback from Microsoft security engineering teams, product groups, partners, and customers.
Microsoft defined over 3,000 Group Policy settings for Windows 10, which does not include over 1,800 Internet Explorer 11 settings. Of these 4,800 settings, only some are security-related.
Microsoft brings some of the major updates with this new security baseline settings for Windows 10 and Windows server. Here some of the notable Baseline settings in this final release that updated by Microsoft.
We can say that the implementation of shutting down the password expiration policy for Windows considering as one of the significant changes in this final security Configuration Baseline Settings for Windows 10. Read here why its shut down.
Microsoft also dropping the enforced disabling of the built-in Administrator and Guest accounts.
According to Microsoft, To keep baselines useful and manageable, we tend to enforce secure defaults for policy settings only when,
1) non-administrative users could otherwise override those defaults, or 2) misinformed administrators are otherwise likely to make poor choices about the setting. Neither of those conditions are true regarding enforcing the default disabling of the Administrator and Guest accounts.
The built-in Guest account -The Guest account (RID -501) is disabled by default on Windows 10 and Windows Server. Only an administrator can enable the Guest account, and an admin would presumably do so only for a valid reason such as for a kiosk system.
The built-in Administrator account – The local Administrator account (RID -500) is disabled by default on Windows 10 but not on Windows Server.
You can Download the content from the Microsoft Security Compliance Toolkit.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.
Also Read:
GitLab has urgently released security updates to address multiple high-severity vulnerabilities in its platform that…
A high-severity security vulnerability (CVE-2025-0514) in LibreOffice, the widely used open-source office suite, has been…
Cisco Systems has disclosed a high-severity vulnerability (CVE-2025-20111) in its Nexus 3000 and 9000 Series…
A sophisticated cyber campaign orchestrated by the Chinese Advanced Persistent Threat (APT) group, Silver Fox,…
A new wave of cyberattacks attributed to the Ghostwriter Advanced Persistent Threat (APT) group has…
The LCRYX ransomware, a malicious VBScript-based threat, has re-emerged in February 2025 after its initial…