Event banner
AMA: Windows security, chip to cloud
Event details
Let’s talk resiliency, security hardening, and recovery tools! We’re kicking off Tech Community Live: Windows edition, with a one-hour Ask Microsoft Anything (AMA) on all things Windows security. Identity protection, application safeguards, device health, access control—this is open forum designed to get you the answers you need to help ensure that hardware and software work together to protect your sensitive data, from the core of the device all the way to the cloud.
On the panel: Katharine Holdsworth, Jeffrey Sutherland, Abhijat Singh, Kevin Sheehan
29 Comments
- Pearl-Angeles
Community Manager
In addition to the questions posted on this page, we also answer questions posted in reply to the event on LinkedIn and X (Twitter). Here are the questions we answered:
Question -- Windows security discussion board on Tech Community -- I’ve read a few mentions of the Secure Future Initiative. And during Ignite I heard about something called the Windows resiliency initiative. Are these the same thing? Related? - answered at 4:27.
Question from the Tech Community -- Is there a way to enable Smart app control when provisioning a device with OSD? The docs say that it can only be used when enabled at device installation, but I don't see ways to enable it for hybrid joined devices. This would be great to start our app hardening journey. Thanks in advance. - answered at 7:10.
Follow up question - How does smart app control in the scenario where you have an unsigned app? - answered at 10:48.
Question from LinkedIn -- Can you help me understand the distinction between User Account Control and admin protection? (Is there some sort of comparison graphic?) - answered at 14:44.
Question from X (formerly Twitter) - On Config Refresh - is there a min or max time frame? Can I set it different for certain groups of devices? - answered at 20:08.
Follow up question: What happens with Config Refresh if the PC goes offline? - answered at 23:01.
Question from Tech Community -- How does admin protection work if you remote into a user’s laptop? For example, if the user is working from home and you as IT support need to use a domain admin account on the remote computer e.g. need to remove some faulty software. - answered at 24:04.
Question from X -- How does Personal Data Encryption select what files to encrypt? - answered at 27:30.
Question from Tech Community - Going back to admin protection -- What about the hidden, system generated accounts and profiles? Is it only one always and preserved—or is there one generated per process and the whole profile deleted afterwards—or is it per user elevating things and the profiles deleted/kept around or ...? - answered at 29:38.
Question -- Your team has done a lot of work making sure more devices have access to device encryption by default, can you share more about what your team is focused on and what it means for users? - answered at 31:46.
Question from X -- Sorry if this is simple, but how do App Control and App Locker fit together? - answered at 33:22.
Question sent to our Windows Community Manager in a private message -- I am having SUCH a hard time getting our IT team to move past traditional Group Policy and into MDM or, seems far for us, Config Refresh. How do I convince them it's time to move forward and modernize some things? - answered at 38:23.
Question from Tech Community -- Is there a way to test Administrator protection with Windows 11, version 24H2 or do we need to use insider builds? - answered at 43:13.
Question from LinkedIn -- When should we use EFS vs. Personal Data Encryption? Can we use both? - answered at 44:31.
Question -- Do any Windows apps have Personal Data Encryption on by default if it's enabled on the device? Or do we always have to set it? - answered at 47:02. For demos on personal data encryption go to https://aka.ms/Ignite2024/BRK290 & https://aka.ms/ignite2024/OD811
Question -- Will it just prompt for a password instead of Windows Hello authentication which (from my understanding) is tied to the machine? - answered at 48:51. - Heather_Poulsen
Community Manager
Thank you for joining today's AMA at Tech Community Live! We'll leave the Q&A open here through 12pm PST Friday for those catching up on demand. Make sure to visit https://aka.ms/TCL/Windows for more great sessions.
- jeddy_Iron Contributor
This is more of a comment than a question - I just wanted to call out that the Intune Policy CSP documentation still has large gaps when compared to traditional Group Policy documentation, especially for newly updated settings. I recently had an issue where the DeviceLock CSP documentation at https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-devicelock did not have any documented formatting for AccountLockoutPolicy, and I had to go find it in a Microsoft GitHub repo at https://github.com/microsoft/osconfig/blob/main/security/SecurityBaseline_WindowsServer_2025-2409.csv . This has been the case for some other CSP settings also.
- Kevin_Sheehan
Microsoft
Great question! Not all settings in GP were originally brought to MDM. We added around 70 or so including new DeviceLock policies in 24H2, and will be backporting in the first quarter of '25 to all in service Win11 releases. Most of the new batch are local security policies, system services, user rights, etc. We'll update the docs when the backport is done, as we don't want to confuse people until they are available and in Settings Catalog.
- lalanc01Iron Contributor
Is there a way to test Administrator protection with 24h2 or we need to use insider builds?
If it's only on insider builds, do you know if it will be available later in 24h2 or only on 25h2?
thks- Per-Larsen
Microsoft
It is currently only for insider builds Administrator protection on Windows 11 | Microsoft Community Hub
- genaromayelesCopper Contributor
When I have an MAA policy set in my tenant, I noticed that while building an application for deployment, the dependency and supersedence options are not editable after the detection rules step. Instead, it skips directly to scope tags and then to review and submit for approval. Could you explain why this happens and how to address it?
- Jason_Sandys
Microsoft
This does not sound like expected behavior to me and could be an anomaly somewhere. I suggest opening a support case to investigate further, determine root cause, and pass on to the product team if action is required to address this.
- lalanc01Iron Contributor
Is there a way to have a consolidated view of which Defender settings/exclusions are set for a specific devices in the Intune portal so to avoid having to connect directly on the device to get the info from the registry and via powershell?
Thks- Per-Larsen
Microsoft
No, only by looking into each policy assigned to a device.
But thanks for the feedback.
- genaromayelesCopper Contributor
Is there a way to streamline the Multi-Admin Approval (MAA) process by automatically notifying other admins when a script or app requires approval?
- Joe_Lurie
Microsoft
genaromayeles Today Intune doesn't notify admins about these requests, but it's great feedback! You could probably configure this in your tenant using PowerAutomate or Graph. I'll bring this to the PM working on this feature 😊
- lalanc01Iron Contributor
Is there a way to set applocker rules like we can with GPO UI, but with Intune?
Asking because it seems that the only way is to generate an xml file and upload it which can easily create issues/errors
Thks- Per-Larsen
Microsoft
No, you need to use a custom policy in Intune to configure AppLocker.
Support Tip: Using AppLocker to create custom Intune policies for Windows 10 apps | Microsoft Community Hub
We have it on our roadmap to make it easier to create policies for Application Control for Business in Intune.- Joe_Lurie
Microsoft
Here's the roadmap item so you can keep track!
https://www.microsoft.com/en-us/microsoft-365/roadmap?featureid=397885
- Anikpal123Copper Contributor
How can see Ransomware in windows security?
- Per-Larsen
Microsoft
Anikpal123 Can you elaborate on your question??
- Anikpal123Copper Contributor
To detect any type of malware in pc. So in windows defender security system ransomware feature is not found . How can I find this?
- lalanc01Iron Contributor
Hi, are there other options than network unlock to prevent users from having to enter their bitlocker pin?
thks
- Joe_Lurie
Microsoft
Hey Stefane lalanc01 good to see you here! Network Unlock is handy when devices are being updated and rebooted overnight, so the device is ready for the end user when they come in in the morning, instead of stuck at the PIN screen. You really have two choices here:
- Use Network Unlock
- Remove the PIN requirement
Fortunately, we added hotpatching to Windows 11 Enterprise, version 24H2. Make sure you join that AMA as well, as it will allow the updates to install and be active even without a reboot AMA: Hotpatching Windows - client and server - December 11, 2024 - Microsoft Event
- lalanc01Iron Contributor
Thks Joe, yes hotpatch is good, but since bitlocker is suspended during patching with Autopatch it's less of a concern.
It's more of when we need to reboot devices for whatever reason or when there's power outages and the user is working remotely from home and IT just power on the machine.
- Jason_Sandys
Microsoft
Hi Lalanc01. No. The options are extremely limited -- mostly by design and the limitations of the platform at the time it was designed. For this reason, this is one of the reasons many recommend not using a PIN at all. This is not a universal recommendation, but is something to consider when choosing whether or not to enforce a PIN. If your organization feels that they need a PIN, I'd first suggest revisiting this as there's a lot of unfounded and outdated FUD floating around out there on this. If you still come to the conclusion that you need to enforce a PIN, then you should look at Personal Device Encryption (PDE) instead or on top of BitLocker (without a PIN) as PDE implements a layer of file system encryption that is gated by Windows Hello for Business thus actually being more secure and easier to use for end-users.
- lalanc01Iron Contributor
Yes PDE will surely help once we move to 24h2 since it supports a broader scope of documents/places.
Could you elaborate a bit more on 'lot of unfounded and outdated FUD floating around'? This could help in our discussions with our security team for a new for the PIN.
Thks