From ae7c181e365f15c367e774ac884371f740580884 Mon Sep 17 00:00:00 2001
From: Rick Munck <33725928+jmunck@users.noreply.github.com>
Date: Fri, 21 Jan 2022 09:33:28 -0600
Subject: [PATCH 1/8] Update windows-security-baselines.md
Refreshed content based on current baselines
---
.../windows-security-baselines.md | 20 +++++++++++++------
1 file changed, 14 insertions(+), 6 deletions(-)
diff --git a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
index 7d1c42a7bb..e0debfadee 100644
--- a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
+++ b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
@@ -1,6 +1,6 @@
---
-title: Windows security baselines guide
-description: Learn how to use Windows security baselines in your organization. Specific to Windows 10, Windows Server 2016, and Office 2016.
+title: Security baselines guide
+description: Learn how to use security baselines in your organization.
keywords: virtualization, security, malware
ms.prod: m365-security
ms.mktglfcycl: deploy
@@ -16,12 +16,12 @@ ms.reviewer:
ms.technology: windows-sec
---
-# Windows security baselines
+# Security baselines
## Using security baselines in your organization
-Microsoft is dedicated to providing its customers with secure operating systems, such as Windows and Windows Server, and secure apps, such as Microsoft Edge. In addition to the security assurance of its products, Microsoft also enables you to have fine control over your environments by providing various configuration capabilities.
+Microsoft is dedicated to providing its customers with secure operating systems, such as Windows and Windows Server, and secure apps, such as Microsoft 365 apps for enterprise and Microsoft Edge. In addition to the security assurance of its products, Microsoft also enables you to have fine control over your environments by providing various configuration capabilities.
Even though Windows and Windows Server are designed to be secure out-of-the-box, many organizations still want more granular control over their security configurations. To navigate the large number of controls, organizations need guidance on configuring various security features. Microsoft provides this guidance in the form of security baselines.
@@ -41,7 +41,15 @@ Security baselines are an essential benefit to customers because they bring toge
For example, there are over 3,000 Group Policy settings for Windows 10, which does not include over 1,800 Internet Explorer 11 settings. Of these 4,800 settings, only some are security-related. Although Microsoft provides extensive guidance on different security features, exploring each one can take a long time. You would have to determine the security impact of each setting on your own. Then, you would still need to determine the appropriate value for each setting.
-In modern organizations, the security threat landscape is constantly evolving, and IT pros and policy-makers must keep up with security threats and make required changes to Windows security settings to help mitigate these threats. To enable faster deployments and make managing Windows easier, Microsoft provides customers with security baselines that are available in consumable formats, such as Group Policy Objects Backups.
+In modern organizations, the security threat landscape is constantly evolving, and IT pros and policy-makers must keep up with security threats and make required changes to security settings to help mitigate these threats. To enable faster deployments and make managing Microsoft products easier, Microsoft provides customers with security baselines that are available in consumable formats, such as Group Policy Objects Backups.
+
+## Baseline principles
+Our recommendations follow a streamlined and efficient approach to baseline definitions. The foundation of that approach is essentially:
+- The baselines are designed for well-managed, security-conscious organizations in which standard end users do not have administrative rights.
+- A baseline enforces a setting only if it mitigates a contemporary security threat and does not cause operational issues that are worse than the risks they mitigate.
+- A baseline enforces a default only if it is otherwise likely to be set to an insecure state by an authorized user:
+ - If a non-administrator can set an insecure state, enforce the default.
+ - If setting an insecure state requires administrative rights, enforce the default only if it is likely that a misinformed administrator will otherwise choose poorly.
## How can you use security baselines?
@@ -74,4 +82,4 @@ You may also be interested in this msdn channel 9 video:
- [Azure Monitor](/azure/azure-monitor/)
- [Microsoft Security Guidance Blog](/archive/blogs/secguide/)
- [Microsoft Security Compliance Toolkit Download](https://www.microsoft.com/download/details.aspx?id=55319)
-- [Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=55319)
\ No newline at end of file
+- [Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=55319)
From 221732d890a8d6969e91f9edf950a1de35777826 Mon Sep 17 00:00:00 2001
From: Rick Munck <33725928+jmunck@users.noreply.github.com>
Date: Fri, 21 Jan 2022 09:46:11 -0600
Subject: [PATCH 2/8] Update get-support-for-security-baselines.md
Began cleaning up this page... More to come
---
.../get-support-for-security-baselines.md | 9 +++------
1 file changed, 3 insertions(+), 6 deletions(-)
diff --git a/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md b/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md
index 4881edff29..d566bd5bad 100644
--- a/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md
+++ b/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md
@@ -1,6 +1,6 @@
---
-title: Get support for Windows security baselines
-description: Find answers to frequently asked question on how to get support for Windows baselines, the Security Compliance Toolkit (SCT), and related topics.
+title: Get support for security baselines
+description: Find answers to frequently asked question on how to get support for baselines, the Security Compliance Toolkit (SCT), and related topics.
keywords: virtualization, security, malware
ms.prod: m365-security
ms.mktglfcycl: deploy
@@ -96,9 +96,6 @@ Windows Server 2008 R2 |[SP1](/previous-versions/tn-archive/gg236605(v=technet.1
-> [!NOTE]
-> Browser baselines are built-in to new OS versions starting with Windows 10
-
## See also
-[Windows security baselines](windows-security-baselines.md)
\ No newline at end of file
+[Windows security baselines](windows-security-baselines.md)
From 004918d137384f87cd0b4404b4da561c682c08a3 Mon Sep 17 00:00:00 2001
From: Rick Munck <33725928+jmunck@users.noreply.github.com>
Date: Fri, 21 Jan 2022 09:56:05 -0600
Subject: [PATCH 3/8] Update security-compliance-toolkit-10.md
Update outdated version (part of overall SCT clean-up effort)
---
.../security-compliance-toolkit-10.md | 19 +++++++++----------
1 file changed, 9 insertions(+), 10 deletions(-)
diff --git a/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md b/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md
index 2d66169700..fc362eccef 100644
--- a/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md
+++ b/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md
@@ -30,27 +30,26 @@ The Security Compliance Toolkit consists of:
- Windows 11 security baseline
- Windows 10 security baselines
- - Windows 10 Version 1909 (November 2019 Update)
- - Windows 10 Version 1903 (April 2019 Update)
- - Windows 10 Version 1809 (October 2018 Update)
- - Windows 10 Version 1803 (April 2018 Update)
- - Windows 10 Version 1709 (Fall Creators Update)
- - Windows 10 Version 1703 (Creators Update)
- - Windows 10 Version 1607 (Anniversary Update)
- - Windows 10 Version 1511 (November Update)
+ - Windows 10 Version 21H2
+ - Windows 10 Version 21H1
+ - Windows 10 Version 20H2
+ - Windows 10 Version 1909
+ - Windows 10 Version 1809
+ - Windows 10 Version 1607
- Windows 10 Version 1507
- Windows Server security baselines
+ - Windows Server 2022
- Windows Server 2019
- Windows Server 2016
- Windows Server 2012 R2
- Microsoft Office security baseline
- - Office 365 Pro Plus
+ - Microsoft 365 Apps for Enterprise Version 2112
- Office 2016
- Microsoft Edge security baseline
- - Edge Browser Version 93
+ - Edge Browser Version 97
- Tools
- Policy Analyzer tool
From 5b96f589ac0bff6a2098457d997610e1494e02a2 Mon Sep 17 00:00:00 2001
From: Denise Vangel-MSFT
Date: Mon, 24 Jan 2022 09:45:15 -0800
Subject: [PATCH 4/8] Update get-support-for-security-baselines.md
---
.../get-support-for-security-baselines.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md b/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md
index d566bd5bad..5bdccb2a0d 100644
--- a/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md
+++ b/windows/security/threat-protection/windows-security-configuration-framework/get-support-for-security-baselines.md
@@ -11,7 +11,7 @@ manager: dansimp
audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
-ms.date: 06/25/2018
+ms.date: 01/24/2022
ms.reviewer:
ms.technology: windows-sec
---
From dad9fb4622b53cf24eed2065c394e833771a24ab Mon Sep 17 00:00:00 2001
From: Denise Vangel-MSFT
Date: Mon, 24 Jan 2022 09:48:10 -0800
Subject: [PATCH 5/8] Update windows-security-baselines.md
---
.../windows-security-baselines.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
index e0debfadee..4e279c96a6 100644
--- a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
+++ b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
@@ -11,7 +11,7 @@ manager: dansimp
audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
-ms.date:
+ms.date: 02/24/2022
ms.reviewer:
ms.technology: windows-sec
---
From a6b492fcf62feafe3e9f6d415c07572f0c77f81e Mon Sep 17 00:00:00 2001
From: Denise Vangel-MSFT
Date: Mon, 24 Jan 2022 09:48:26 -0800
Subject: [PATCH 6/8] Update windows-security-baselines.md
---
.../windows-security-baselines.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
index 4e279c96a6..e2178d5931 100644
--- a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
+++ b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
@@ -12,7 +12,7 @@ audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
ms.date: 02/24/2022
-ms.reviewer:
+ms.reviewer: jmunck
ms.technology: windows-sec
---
From 1bd2edccad1103b4d52efb0e73861fb5083d84c5 Mon Sep 17 00:00:00 2001
From: Denise Vangel-MSFT
Date: Mon, 24 Jan 2022 09:49:43 -0800
Subject: [PATCH 7/8] Update security-compliance-toolkit-10.md
---
.../security-compliance-toolkit-10.md | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md b/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md
index fc362eccef..eac63f1ad2 100644
--- a/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md
+++ b/windows/security/threat-protection/windows-security-configuration-framework/security-compliance-toolkit-10.md
@@ -11,8 +11,8 @@ manager: dansimp
audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
-ms.date: 11/26/2018
-ms.reviewer:
+ms.date: 01/24/2022
+ms.reviewer: rmunck
ms.technology: windows-sec
---
From 221c82a3a8ef07ac325fdcedee46fc25025d6d62 Mon Sep 17 00:00:00 2001
From: Denise Vangel-MSFT
Date: Mon, 24 Jan 2022 09:51:21 -0800
Subject: [PATCH 8/8] Update windows-security-baselines.md
---
.../windows-security-baselines.md | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
index e2178d5931..17e520e281 100644
--- a/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
+++ b/windows/security/threat-protection/windows-security-configuration-framework/windows-security-baselines.md
@@ -11,7 +11,7 @@ manager: dansimp
audience: ITPro
ms.collection: M365-security-compliance
ms.topic: conceptual
-ms.date: 02/24/2022
+ms.date: 01/24/2022
ms.reviewer: jmunck
ms.technology: windows-sec
---