Forum Widgets
Latest Discussions
Driver digital signature authentication issues
I am currently developing a desktop application for my company with a kernel driver (which is just a single .sys file). Since drivers must have a Microsoft digital signature to run starting with Windows 10, I have some questions about digital signature authentication. On this webpage (https://learn.microsoft.com/zh-cn/windows-hardware/drivers/dashboard/driver-signing-offerings#hardware-lab-kit-tested-and-dashboard-signed-drivers), I saw a solution for driver signing. The first method requires testing with HLK and submission to Windows Hardware Quality Labs for certification. The second method, according to its description, only requires submitting the driver for signature verification, without HLK testing. What are the differences between these two solutions? Which solution should I choose?SewingAug 23, 2026Copper Contributor64Views0likes2CommentsHow can I tell if I'm enrolled in ESU with my Windows 10? I want to extend my enrollment period.
SolvededcarballoAug 17, 2026Copper Contributor102Views0likes2CommentsMy Windows Security stucked on Black Screen
I cant use Windows Security because everytime i open its just a black screen and after i do something, new window just pop up I searched all over internet for fix, i found some "fixes" that dont work, i used commands, reseting, repairing and also used "SecurityHealthSetup.exe" that was on other blog with this exact problem used as fix, but it did nothing to meSlayeroosAug 15, 2026Copper Contributor5.2KViews1like3CommentsCan I ask a Bitlocker question?
As I understand it, an SSD is built with wear leveling and the actual space is double of the advertised available space to the OS. If an SSD has been in use for an unknown period of time and is later Bitlocked, does all of the drive become protected, even the dormant bits that can't be seen and are "resting"?SolvedTodd GodchauxAug 13, 2026Brass Contributor2.9KViews1like7CommentsUsage of GetRuntimeAttestationReport
Hello Community! I would like to get more information about the function GetRuntimeAttestationReport. It seems like it is signed via a key from the Secure Kernel, but the key's getter function is unknown to me. How does one query this key? Also, how does one verify the key's root of trust? Sincerely RobertrobertbiggsAug 06, 2026Copper Contributor20Views0likes1CommentSecure Boot Q&A opportunities continue in July
If you're still working through Secure Boot certificate update rollouts, Microsoft is continuing the conversation throughout July with three opportunities to get your questions answered by the people closest to the technology. Whether you're focused on Windows Server deployments, virtualization platforms, or OEM updates, these upcoming events are designed to help you navigate planning, validation, troubleshooting, and implementation questions in a live, interactive format. Microsoft engineers and subject matter experts will be available to respond directly to questions from the community. Coming up in July: July 1 - Windows Server Secure Boot AMA Ask Microsoft engineers about Secure Boot certificate updates in Windows Server environments, including deployment planning, monitoring, troubleshooting, and more. July 8 - Secure Boot Office Hours for virtualized environments Bring your questions about Hyper-V, Azure offerings, Windows 365, VMware, and other virtualization scenarios. July 15 - OEM Secure Boot Office Hours Connect with experts to discuss OEM-specific questions, such as firmware considerations, as you prepare for or validate Secure Boot certificate updates. Questions don't have to wait until the events start. With community events, you can post your questions and comments ahead of time, then join the discussion live or catch up when it's convenient for you. Hope you find these events helpful. You can also catch up on demand with the series of Secure Boot AMAs that have taken place over the past several months. Here are the three most recent editions: Ask Microsoft Anything: Secure Boot - June 2026 Ask Microsoft Anything: Secure Boot - May 2026 Ask Microsoft Anything: Secure Boot - April 2026Heather_PoulsenJun 23, 2026Community Manager100Views1like0CommentsSmartScreen false positives
Hello, I'm a developer of https://www.abareplace.com/ Unfortunately, Microsoft SmartScreen blocks https://www.abareplace.com/download/ of my application and multiple attempts to contact Microsoft about this case were in vain. The app is clean on VirusTоtаl, has a valid digital signature, and is published to MS Store. However, users see the SmartScreen warning when trying to run the installer downloaded from my website: Windows protected your PC Windows Defender SmartScreen prevented an unrecognized app from starting. Running this app might put your PC at risk. Other developers report exactly the same problem and it https://www.reddit.com/r/Windows11/comments/1pz8qww/windows_code_signing_is_broken_for_indie/ It has no sense from the security point of view to block something that is already published on Microsoft Store. I submitted a ticket to https://www.microsoft.com/en-us/wdsi/filesubmission?persona=SoftwareDeveloper one month ago. The ticket was "In progress" for many weeks, then was silently closed. I opened a new ticket one week ago and it's still "in progress". I also submitted the file via Report this file as safe > I am the owner or representative of this website and I want to report an incorrect warning about it button in Microsoft Edge several times, but received no confirmation email that you should receive after submitting the form. I know that the times when Steve Ballmer shouted: "Developers! Developers! Developers!" are long gone, but can Microsoft make live at least a bit easier to independent software vendors? Thank you.abareplaceApr 09, 2026Copper Contributor809Views1like4CommentsDésinscription Windows ESU (Windows 10)
Bonjour, A la suite de problème sur mon matériel à la suite d'une mise à jour de sécurité (KB5071546) du programme de mise à jour de sécurité étendu (Windows ESU), j'ai fait une demande sur le support pour qu'on me désinscrive de l'ESU. Le billet est le numéro 7098812524 Après échange on m'a indiqué que je pouvais le faire depuis mon compte Microsoft. Mais sur mon compte Microsoft, je ne trouve pas d'onglet dans la partie "Abonnement" qui se réfère à l'ESU et donc je n'arrive pas à me désinscrire par mes propres moyens. Pouvez-vous m'aider, s'il vous plaît ? Je suis à disposition si vous avez besoin d'informations complémentaires.SolvedCléonApr 09, 2026Copper Contributor156Views0likes2CommentsCompanion guide: Transitioning to post-quantum cryptography
Whether you joined us live or are catching up afterward, this companion guide brings together all the resources, links, and deeper dives referenced during the Microsoft Technical Takeoff session on Transitioning to post-quantum cryptography. Think of it as your follow‑along toolkit: everything you need to explore key topics, revisit demos, and continue learning at your own pace. Use it to jump straight to the details that matter most to you or to share highlights with your team. Industry standards: NIST standardized the first set of PQC algorithms FIPS 203 Key Encapsulation Mechanism (ML-KEM) FIPS 204 Digital Signature Standard (ML-DSA) FIPS 205 Hash Based Digital Signature Standard (SLH-DSA) NIST SP 800-208 Stateful Hash-Based Signature Schemes (LMS, XMSS) Last year, Microsoft added post-quantum cryptography algorithms to SymCrypt, Microsoft’s core cryptographic library. Read the announcement: Microsoft's quantum-resistant cryptography is here Direct callers can leverage Cryptography API: Next Generation (CNG) libraries and Certificate and Cryptographic messaging functions in Windows Server 2025 (and later) and Windows 11. Request ML-DSA server certificates with Microsoft Active Directory Certificate Services (ADCS). Windows TLS Stack (Schannel): TLS hybrid key exchange per the latest IETF internet draft is now available for preview in the Windows Insider Program and coming soon to Windows Server. Additional algorithms coming to SymCrypt as global standards and compliance regulations mature. When available, ML-KEM hybrid groups can be enabled and prioritized on devices using the same mechanisms as existing TLS ECC curves. To learn more, see Manage Transport Layer Security (TLS) in Windows Server. Additional resources: Post-Quantum Cryptography APIs Now Generally Available on Microsoft Platforms Windows 11 Security BookHeather_PoulsenApr 03, 2026Community Manager2.1KViews1like1Comment
Tags
- security15 Topics
- windows 1011 Topics
- BitLocker9 Topics
- Windows Defender6 Topics
- defender6 Topics
- wdac6 Topics
- Windows Security6 Topics
- edge5 Topics
- intune4 Topics
- windows 114 Topics