Update security features documentation

This commit is contained in:
Paolo Matarazzo 2024-07-25 12:32:41 -04:00
parent 2114ee54ee
commit 32b06c4da9

View File

@ -11,130 +11,130 @@ ms.date: 06/17/2024
:::image type="content" source="images/security-foundation.png" alt-text="Diagram containing a list of security features." border="false"::: :::image type="content" source="images/security-foundation.png" alt-text="Diagram containing a list of security features." border="false":::
Common Criteria (CC) - Common Criteria (CC)
Federal Information Processing Standard (FIPS) - Federal Information Processing Standard (FIPS)
Microsoft Offensive Research and Security Engineering - Microsoft Offensive Research and Security Engineering
Microsoft Security Development Lifecycle (SDL) - Microsoft Security Development Lifecycle (SDL)
OneFuzz service - OneFuzz service
Software bill of materials (SBOM) - Software bill of materials (SBOM)
Windows App software development kit (SDK) - Windows App software development kit (SDK)
Windows Insider and Bug Bounty program - Windows Insider and Bug Bounty program
## Hardware security ## Hardware security
:::image type="content" source="images/hardware.png" alt-text="Diagram containing a list of security features." lightbox="images/hardware.png" border="false"::: :::image type="content" source="images/hardware.png" alt-text="Diagram containing a list of security features." lightbox="images/hardware.png" border="false":::
Hardware-enforced stack protection - Hardware-enforced stack protection
Kernel Direct Memory Access (DMA) protection - Kernel Direct Memory Access (DMA) protection
Microsoft Pluton security processor - Microsoft Pluton security processor
Secured kernel - Secured kernel
Secured-core PC - Secured-core PC
Trusted Platform Module (TPM) - Trusted Platform Module (TPM)
## Operating system security ## Operating system security
:::image type="content" source="images/operating-system.png" alt-text="Diagram containing a list of security features." lightbox="images/operating-system.png" border="false"::: :::image type="content" source="images/operating-system.png" alt-text="Diagram containing a list of security features." lightbox="images/operating-system.png" border="false":::
5G and eSIM - 5G and eSIM
Assigned Access - Assigned Access
Attack surface reduction - Attack surface reduction
BitLocker - BitLocker
BitLocker To Go - BitLocker To Go
Bluetooth protection - Bluetooth protection
Certificates - Certificates
Code signing and integrity - Code signing and integrity
Config Refresh - Config Refresh
Controlled folder access - Controlled folder access
Cryptography - Cryptography
Device Encryption - Device Encryption
Device health attestation - Device health attestation
DNS security - DNS security
Email encryption - Email encryption
Encrypted hard drive - Encrypted hard drive
Exploit protection - Exploit protection
Microsoft Defender Antivirus - Microsoft Defender Antivirus
Microsoft Defender for Endpoint - Microsoft Defender for Endpoint
Microsoft Defender SmartScreen - Microsoft Defender SmartScreen
Personal data encryption - Personal data encryption
Securing Wi-Fi connections - Securing Wi-Fi connections
Server Message Block file services - Server Message Block file services
Tamper protection - Tamper protection
Transport layer security (TLS) - Transport layer security (TLS)
Trusted Boot (Secure Boot + Measured Boot) - Trusted Boot (Secure Boot + Measured Boot)
Virtual private networks (VPN) - Virtual private networks (VPN)
Windows Firewall - Windows Firewall
Windows security policy settings and auditing - Windows security policy settings and auditing
Windows security settings - Windows security settings
## Application security ## Application security
:::image type="content" source="images/application-security.png" alt-text="Diagram containing a list of security features." lightbox="images/application-security.png" border="false"::: :::image type="content" source="images/application-security.png" alt-text="Diagram containing a list of security features." lightbox="images/application-security.png" border="false":::
App containers - App containers
App Control for Business - App Control for Business
Microsoft vulnerable driver blocklist - Microsoft vulnerable driver blocklist
Smart App Control - Smart App Control
Trusted signing - Trusted signing
User Account Control - User Account Control
Win32 app isolation - Win32 app isolation
Windows Sandbox - Windows Sandbox
Windows Subsystem for Linux (WSL) - Windows Subsystem for Linux (WSL)
## Identity protection ## Identity protection
:::image type="content" source="images/identity-protection.png" alt-text="Diagram containing a list of security features." lightbox="images/identity-protection.png" border="false"::: :::image type="content" source="images/identity-protection.png" alt-text="Diagram containing a list of security features." lightbox="images/identity-protection.png" border="false":::
Access management and control - Access management and control
Account lockout policies - Account lockout policies
Credential Guard - Credential Guard
Enhanced phishing protection with Microsoft Defender SmartScreen - Enhanced phishing protection with Microsoft Defender SmartScreen
Federated sign-in - Federated sign-in
FIDO support - FIDO support
Local Security Authority (LSA) protection - Local Security Authority (LSA) protection
Microsoft Authenticator - Microsoft Authenticator
Passkeys - Passkeys
Remote Credential Guard - Remote Credential Guard
Smart cards for Windows service - Smart cards for Windows service
Token protection - Token protection
VBS Key Protection - VBS Key Protection
Windows Hello - Windows Hello
Windows Hello biometric sign-in - Windows Hello biometric sign-in
Windows Hello Enhanced Sign-in Security - Windows Hello Enhanced Sign-in Security
Windows Hello for Business - Windows Hello for Business
Windows Hello for Business multi-factor unlock - Windows Hello for Business multi-factor unlock
Windows Hello PIN - Windows Hello PIN
Windows passwordless experience - Windows passwordless experience
Windows presence sensing - Windows presence sensing
## Privacy ## Privacy
:::image type="content" source="images/privacy.png" alt-text="Diagram containing a list of security features." lightbox="images/privacy.png" border="false"::: :::image type="content" source="images/privacy.png" alt-text="Diagram containing a list of security features." lightbox="images/privacy.png" border="false":::
Privacy dashboard and report - Privacy dashboard and report
Privacy transparency and controls - Privacy transparency and controls
Privacy resource usage - Privacy resource usage
Windows diagnostic data processor configuration - Windows diagnostic data processor configuration
## Cloud services ## Cloud services
:::image type="content" source="images/cloud-security.png" alt-text="Diagram containing a list of security features." lightbox="images/cloud-security.png" border="false"::: :::image type="content" source="images/cloud-security.png" alt-text="Diagram containing a list of security features." lightbox="images/cloud-security.png" border="false":::
Enterprise State Roaming with Azure - Enterprise State Roaming with Azure
Find my device - Find my device
MDM enrollment certificate attestation - MDM enrollment certificate attestation
MDM security baseline - MDM security baseline
Microsoft Account - Microsoft Account
Microsoft Azure Attestation Service - Microsoft Azure Attestation Service
Microsoft Entra ID - Microsoft Entra ID
Microsoft Intune - Microsoft Intune
Microsoft security baselines - Microsoft security baselines
Modern device management through (MDM) - Modern device management through (MDM)
OneDrive for personal - OneDrive for personal
OneDrive for work or school - OneDrive for work or school
OneDrive Personal Vault - OneDrive Personal Vault
Remote Wipe - Remote Wipe
Universal Print - Universal Print
User reauthentication before password disablement - User reauthentication before password disablement
Windows Autopatch - Windows Autopatch
Windows Autopilot and zero-touch deployment - Windows Autopilot and zero-touch deployment
Windows Update for Business deployment service - Windows Update for Business deployment service