From 11023a058fc39e4d8319c1dd9e86682285295994 Mon Sep 17 00:00:00 2001 From: cchavez-msft <136099320+cchavez-msft@users.noreply.github.com> Date: Mon, 24 Jun 2024 14:04:59 -0400 Subject: [PATCH] hardwareSecurityAshwinBaliga --- .../security/book/hardware-security-hardware-root-of-trust.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/windows/security/book/hardware-security-hardware-root-of-trust.md b/windows/security/book/hardware-security-hardware-root-of-trust.md index 871680e2f4..43a29bc8d2 100644 --- a/windows/security/book/hardware-security-hardware-root-of-trust.md +++ b/windows/security/book/hardware-security-hardware-root-of-trust.md @@ -27,6 +27,8 @@ Pluton supports the TPM 2.0 industry standard, allowing customers to immediately As with other TPMs, credentials, encryption keys, and other sensitive information cannot be easily extracted from Pluton even if an attacker has installed malware or has complete physical possession of the PC. Storing sensitive data like encryption keys securely within the Pluton processor, which is isolated from the rest of the system, helps ensure that attackers cannot access sensitive data - even if attackers use emerging techniques like speculative execution. +In an ongoing commitment to enhancing security, there are plans to introduce additional Pluton Security Processor capabilities, such as a Key Storage Provider (KSP). This new functionality, known internally as CredGuard v2, will leverage this KSP to provide advanced protection to Azure AD and Intune credentials. This is a testament to continuous efforts to stay ahead of potential threats and provide users with the most secure experience possible. + Pluton also solves the major security challenge of keeping its own security processor firmware up to date across the entire PC ecosystem. Today customers receive updates to their security firmware from a variety of different sources, which may make it difficult for customers to get alerts about security updates, keeping systems in a vulnerable state. Pluton provides a flexible, updateable platform for its firmware that implements end-to-end security functionality authored, maintained, and updated by Microsoft. Pluton is integrated with the Windows Update service, benefiting from over a decade of operational experience in reliably delivering updates across over a billion endpoint systems. Microsoft Pluton is available with select new Windows PCs. :::image type="icon" source="images/learn-more.svg" border="false"::: **Learn more:**