Since the launch of Windows 11 in 2021, Microsoft has touted the new operating system’s improved security, much of it attributable to new default settings that enable features that were optional in Windows 10. A new round of security features scheduled to appear in Windows 11 over the next year will address more fundamental security concerns.

The biggest security issue is that the overwhelming majority of Windows users run using an account with administrator privileges. If they’re tricked into running a piece of malicious code, that malware has the same administrative rights, meaning it can install additional software and generally wreak havoc on the system. The fix is a feature called Administrator Protection, which gives the user standard permissions by default. If they need to perform an action that requires administrator rights, such as installing an app or changing a system setting, they’ll need to authenticate using Windows Hello biometrics or a device-specific PIN. That authorization creates a temporary token that is valid only for the current action and is destroyed as soon as the task is completed. Microsoft argues that this change will be “disruptive to attackers as they no longer have automatic, direct access to the kernel or other critical system security without specific Windows Hello authorization.” The addition of Windows Hello is the game-changer here. Being able to authenticate using biometrics instead of having to enter a password should reduce the hassle factor dramatically.The feature is in preview now and should be released to the public in 2025.

A second feature, Smart App Control, is designed to block malware by preventing unknown apps from running on a Windows 11 PC. Apps that are well known will run without issue, but unsigned and unfamiliar apps will be prevented from running; the feature will also block all scripts from the internet, including those that try to leverage PowerShell as a vector for installing malware. Smart App Control will be on by default for consumer PCs. In corporate environments, IT administrators will need to enable App Control for Business policies and select a “signed and reputable policy” template; they can then add internal apps using management tools.

Finally, Windows Protected Print mode eliminates the need for third-party print drivers, which have become an aggressive and effective entry point for attackers.

Logical Operations has been helping organizations across New York State migrate to Windows 11 for several years. We have courses for both technical staff and end users, and are Learning Consultants can help put together a training plan for all areas of your organization if you are looking to make the switch-over to Windows 11. You can take a look at our full class listing here:

For help putting together a Windows 11 transition plan (that could include some of the courses above or maybe different ones) please fill out this form to contact one of our Learning Consultants – we’d love to chat with you! https://logicaloperationstraining.com/contact-us/.