Event banner
AMA: Windows Security
Event details
Have questions about how to keep your devices protected and productive end to end? Have suggestions on where we should invest our engineering muscle to take Windows platform security even further? Curious about the capabilities that light up when you move from Windows Pro to Enterprise E3, and from E3 to E5? Come to this Ask Microsoft Anything (AMA) all about Windows security.
This AMA will not have a video feed, but our speakers will be responding to your comments in discussion below.
20 Comments
- Trevor_Rusher
Community Manager
Thanks for joining us today for an AMA on Windows security. We appreciate your questions and feedback—and look forward to continuing the discussion on the Windows community!
- Christian ZenzanoCopper ContributorWill Windows 10 be able to use the Microsoft authenticator app as a method to authenticate and change passwords.
- Christian ZenzanoCopper ContributorIn the session today, I heard that Windows 11 will be the 1st true passwordless authentication OS. Can you describe how Windows 11 uses TPM to accomplish this? Is there an ability to automate the change of a hidden password so that it may comply with PCI or CJIS compliance rules that require a periotic password change.
- Katharine_Holdsworth
Microsoft
You can learn more here http://aka.ms/whfb.
I don't quite understand the question about changing a hidden password as in a passwordless device there is no password to change.
- Christian ZenzanoCopper ContributorWill Windows 11 have better integration with Azure Right management and Microsoft Cloud App Security? The ability of end users to utilize many cloud services without a corporate identity enabled the new work from home workforce to store corporate data on many unapproved SaaS platforms .
- Dennis_EwaldCopper ContributorI think the new Controlled Folder Access feature is great and I'm already using it. One thing that bothers me so far is that if I want to create an exception for a process I have to specify the path to the corresponding exe. This could in principle bypass the entire policy once I know for which exe an exception was created (rename file). Is it planned to be able to create an exception based on the hash value, similar to existing legacy solutions ?
- Dennis_EwaldCopper ContributorWhat options will we have in the future via Intune to prevent the launch of individual apps ?
- Jeffrey_Sutherland
Microsoft
You can use Windows Defender Application Control (WDAC) to control what apps are allowed to run on Windows. WDAC policies can be deployed via Intune and Intune offers some basic, built-in policies that you can start from. That said, most customers will find they need to use custom policies which can be deployed through Intune using custom OMA-URI with the ApplicationControl CSP. https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/deploy-windows-defender-application-control-policies-using-intune- Jeffrey_Sutherland
Microsoft
We’d love to hear what additional features you’d like to see with Intune management of application control.
- Dennis_EwaldCopper ContributorI have been looking at Microsoft Defender Security Center lately and have a question about device groups. I have a freshly created tenant with no groups set up by default. Now when I create my first group "Device Group1", I get the group "Ungrouped Devices (Default)" in addition to the group I created. By itself, I understand that it makes sense to have a default group that contains all devices that do not belong to my device group. The question I have now is the following: In the default group the Remediation Level is set to Full, but what if I don't create a custom group and I can't see any groups on my dashboard (see first image). Are all clients already in the default group by default before the first manual creation of a group and the Remediation level is also set to Full there or do the devices all have no assignment before?
- Trevor_Rusher
Community Manager
Welcome to the Windows security Ask Microsoft Anything (AMA)! This live hour gives you the opportunity to ask questions and provide feedback to the engineering and product teams building Windows. Introduce yourself by replying to this thread. Post each question in the Comment on this event… box above.- KurtStevenson
Microsoft
Hi everyone! I'm Kurt Stevenson a Product Marketing Manager on the Windows Pro team! - Jeffrey_Sutherland
Microsoft
Hi! I’m Jeffrey Sutherland, a Lead Program Manager on the core OS security team. My team owns platform integrity features, including things like secure boot, code integrity, Windows Defender Application Control, and AppLocker. - Augusto Valdez
Microsoft
Hi, I am Augusto Valdez, Director of Product Marketing for Windows Commercial.
- would be very interesting to know when all the MSIX Goodness (except the simple already included MSIX deployment) come to Configuration Manager TPs and Releases. I hope very soon for MSIX App Attach, Config Packages, Updates, Bundles etc.
- Heather_Poulsen
Community Manager
We don't have any MSIX experts in this AMA right now, but we are hosting an MSIX AMA at 12:00PM PT as part of Tech Community Live. Can you post your question over there? What's new and what's next with MSIX - Microsoft Tech Community
- MVP_BabooCopper ContributorThe vast majority of pirated windows use KMS activation through illegal servers or simulating a KMS server on the user's own computer. Will Windows 11 have any changes from Windows 10 to avoid this?
- Katharine_Holdsworth
Microsoft
Activation in Windows 11 is the same as in Windows 10. If you have a piracy concern, please report through this link https://www.microsoft.com/en-us/concern/privacy