Merge branch 'master' into patch-1

This commit is contained in:
Dan Pandre 2021-08-04 13:20:37 -04:00 committed by GitHub
commit a34770f319
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 4 additions and 4 deletions

View File

@ -16,7 +16,7 @@ ms.date: 08/17/2017
ms.reviewer: ms.reviewer:
--- ---
# Windows Defender Credential Guard protection limits # Windows Defender Credential Guard protection limits and mitigations
**Applies to** **Applies to**
- Windows 10 - Windows 10
@ -43,7 +43,7 @@ do not qualify as credentials because they cannot be presented to another comput
## Additional mitigations ## Additional mitigations
Windows Defender Credential Guard can provide mitigations against attacks on derived credentials and prevent the use of stolen credentials elsewhere. However, PCs can still be vulnerable to certain attacks, even if the derived credentials are protected by Windows Defender Credential Guard. These attacks can include abusing privileges and use of derived credentials directly from a compromised device, reusing previously stolen credentials prior to Windows Defender Device Guard, and abuse of management tools and weak application configurations. Because of this, additional mitigations also must be deployed to make the domain environment more robust. Windows Defender Credential Guard can provide mitigations against attacks on derived credentials and prevent the use of stolen credentials elsewhere. However, PCs can still be vulnerable to certain attacks, even if the derived credentials are protected by Windows Defender Credential Guard. These attacks can include abusing privileges and use of derived credentials directly from a compromised device, reusing previously stolen credentials, and abuse of management tools and weak application configurations. Because of this, additional mitigations also must be deployed to make the domain environment more robust.
### Restricting domain users to specific domain-joined devices ### Restricting domain users to specific domain-joined devices

View File

@ -265,7 +265,7 @@
href: windows-sandbox/windows-sandbox-architecture.md href: windows-sandbox/windows-sandbox-architecture.md
- name: Windows Sandbox configuration - name: Windows Sandbox configuration
href: windows-sandbox/windows-sandbox-configure-using-wsb-file.md href: windows-sandbox/windows-sandbox-configure-using-wsb-file.md
- name: "Windows Defender Device Guard: virtualization-based security and WDAC" - name: "Windows Defender Application Control and virtualization-based protection of code integrity"
href: device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control.md href: device-guard/introduction-to-device-guard-virtualization-based-security-and-windows-defender-application-control.md
- name: Windows Certifications - name: Windows Certifications
items: items: