mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-13 22:07:22 +00:00
Update windows-security-baselines.md
Refreshed content based on current baselines
This commit is contained in:
parent
6245ad908c
commit
ae7c181e36
@ -1,6 +1,6 @@
|
||||
---
|
||||
title: Windows security baselines guide
|
||||
description: Learn how to use Windows security baselines in your organization. Specific to Windows 10, Windows Server 2016, and Office 2016.
|
||||
title: Security baselines guide
|
||||
description: Learn how to use security baselines in your organization.
|
||||
keywords: virtualization, security, malware
|
||||
ms.prod: m365-security
|
||||
ms.mktglfcycl: deploy
|
||||
@ -16,12 +16,12 @@ ms.reviewer:
|
||||
ms.technology: windows-sec
|
||||
---
|
||||
|
||||
# Windows security baselines
|
||||
# Security baselines
|
||||
|
||||
|
||||
## Using security baselines in your organization
|
||||
|
||||
Microsoft is dedicated to providing its customers with secure operating systems, such as Windows and Windows Server, and secure apps, such as Microsoft Edge. In addition to the security assurance of its products, Microsoft also enables you to have fine control over your environments by providing various configuration capabilities.
|
||||
Microsoft is dedicated to providing its customers with secure operating systems, such as Windows and Windows Server, and secure apps, such as Microsoft 365 apps for enterprise and Microsoft Edge. In addition to the security assurance of its products, Microsoft also enables you to have fine control over your environments by providing various configuration capabilities.
|
||||
|
||||
Even though Windows and Windows Server are designed to be secure out-of-the-box, many organizations still want more granular control over their security configurations. To navigate the large number of controls, organizations need guidance on configuring various security features. Microsoft provides this guidance in the form of security baselines.
|
||||
|
||||
@ -41,7 +41,15 @@ Security baselines are an essential benefit to customers because they bring toge
|
||||
|
||||
For example, there are over 3,000 Group Policy settings for Windows 10, which does not include over 1,800 Internet Explorer 11 settings. Of these 4,800 settings, only some are security-related. Although Microsoft provides extensive guidance on different security features, exploring each one can take a long time. You would have to determine the security impact of each setting on your own. Then, you would still need to determine the appropriate value for each setting.
|
||||
|
||||
In modern organizations, the security threat landscape is constantly evolving, and IT pros and policy-makers must keep up with security threats and make required changes to Windows security settings to help mitigate these threats. To enable faster deployments and make managing Windows easier, Microsoft provides customers with security baselines that are available in consumable formats, such as Group Policy Objects Backups.
|
||||
In modern organizations, the security threat landscape is constantly evolving, and IT pros and policy-makers must keep up with security threats and make required changes to security settings to help mitigate these threats. To enable faster deployments and make managing Microsoft products easier, Microsoft provides customers with security baselines that are available in consumable formats, such as Group Policy Objects Backups.
|
||||
|
||||
## Baseline principles
|
||||
Our recommendations follow a streamlined and efficient approach to baseline definitions. The foundation of that approach is essentially:
|
||||
- The baselines are designed for well-managed, security-conscious organizations in which standard end users do not have administrative rights.
|
||||
- A baseline enforces a setting only if it mitigates a contemporary security threat and does not cause operational issues that are worse than the risks they mitigate.
|
||||
- A baseline enforces a default only if it is otherwise likely to be set to an insecure state by an authorized user:
|
||||
- If a non-administrator can set an insecure state, enforce the default.
|
||||
- If setting an insecure state requires administrative rights, enforce the default only if it is likely that a misinformed administrator will otherwise choose poorly.
|
||||
|
||||
## How can you use security baselines?
|
||||
|
||||
@ -74,4 +82,4 @@ You may also be interested in this msdn channel 9 video:
|
||||
- [Azure Monitor](/azure/azure-monitor/)
|
||||
- [Microsoft Security Guidance Blog](/archive/blogs/secguide/)
|
||||
- [Microsoft Security Compliance Toolkit Download](https://www.microsoft.com/download/details.aspx?id=55319)
|
||||
- [Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=55319)
|
||||
- [Microsoft Download Center](https://www.microsoft.com/download/details.aspx?id=55319)
|
||||
|
Loading…
x
Reference in New Issue
Block a user