Skip to main content
Guidance

Device security guidance

Guidance for organisations on how to choose, configure and use devices securely.

Page 7 of 37

Windows

Whilst this guide does not apply to any specific version of Windows, it was last tested on Windows 11 25H2 Enterprise Edition, which has more features available than some other versions of Windows

The NCSC recommends using the latest version of Windows alongside the latest available version of our guidance, even if the guidance has not been updated since the latest Windows release. Using the latest version of Windows ensures you receive feature updates, including improvements to security features that offer defence in depth.


General recommendations

For an enterprise deployment of Windows devices, you should do the following:

  • Select suitable Windows devices

    • Choose devices that support modern Windows security features. Devices that meet hardware requirements for Virtualization-Based Security (VBS) and full disk encryption are preferred.
  • Keep devices on supported Windows versions

    • Windows devices receive software updates regularly, and major updates once or twice a year. Organisations should keep devices as up to date as operational requirements allow. 
    • Use Microsoft's Windows lifecycle fact sheet to plan upgrades and ensure devices remain on supported versions of Windows.
  • Use an appropriate enterprise network architecture

    • Provide remote access to enterprise services where needed using one of the recommended network architectures for enterprise deployment.
    • For organisations transitioning from on-premises infrastructure to cloud services, an initial hybrid deployment may be appropriate. This can be implemented using Entra Connect.
  • Use mobile device management

  • Provision devices securely

    • Use Windows Autopilot to enrol and provision devices using zero touch enrolment and a trusted Windows base image. 
    • Provision non-administrative accounts during setup, removing the need for local admin accounts.
  • Deploy endpoint protection

    • Install and configure an antivirus or endpoint detection and response (EDR) solution. 
    • Microsoft Defender Antivirus is an antivirus tool that is included with Windows and provides integrated protection. If using third-party antivirus software, select a reputable vendor and ensure the product provides equivalent functionality, including integration with the Anti-Malware Scan Interface (AMSI).
  • Configure device hardware features appropriately

    • Windows devices commonly include cameras that support Windows Hello authentication and video conferencing. 
    • If cameras are not appropriate for your deployment environment, disable them.
  • Restrict Microsoft Office macros

    • Disable Microsoft Office macros where possible. 
    • If macros are required for specific workflows, restrict their use to defined applications or users. Refer to macro security for Microsoft Office for further configuration guidance.
  • Ensure use of enterprise infrastructure

    • Ensure devices consistently use organisational infrastructure services. 
    • For example, configure endpoints so they use your enterprise DNS solution regardless of local device settings. 

Device configuration

Once you have selected your MDM service, architecture and application management approach, create a device configuration profile to enforce your organisation’s technical security controls.

Your configuration profile should include policies covering the following areas:

  • Configure authentication and identity controls

  • Enable full disk encryption

    • Configure BitLocker to protect data at rest and reduce the risk of data extraction through physical attacks. 
    • We recommend:
      •  enabling Full Disk Encryption
      • using a Trusted Platform Module (TPM) with a PIN
  • Protect external interfaces

    • Restrict or monitor the use of external interfaces and peripherals, including wired and wireless devices.
    • Enable Direct Memory Access (DMA) protections, such as preventing new DMA-capable devices from being enumerated when the device is locked.
  • Enable automatic updates

    • Configure automatic updates for:
      • the Windows operating system
      • installed applications
      • firmware and drivers, where applicable
    • We recommend using Windows Update for Business to centrally manage update policies across your estate. 
  • Configure platform security features

    Enable hardware-based platform protections where supported by the device. This includes:

  • Configure VPN access securely

  • Implement application control

    • Deploy Application Control policies to help defend against malware and ransomware. 
    • Third-party applications used for work should be distributed through an enterprise application catalogue, delivered via MDM or a private application store.
  • Use device health signals to protect cloud access

    • Use device health signals to influence access to built-in cloud services.  
      • For example, Intune compliance policies can enforce conditional access, allowing access to sensitive services only from devices that meet your organisation’s security requirements. 
  • Configure host firewall rules

    • Configure Windows Defender Firewall to reduce unwanted connections.
    • As a baseline:
      • block traffic on Public and Private networks 
      • create explicit allow rules for required services and protocols

Note: Kernel Mode Code Integrity (KMCI) protects Windows system integrity by ensuring only trusted drivers and boot-time components can load. It is separate from user‑mode Application Control, which governs business applications.  App Control for Business (ACfB) uses the Windows Code Integrity engine to configure both KMCI and, when User Mode Code Integrity (UMCI) is enabled, user‑mode application restrictions. 




Published

Reviewed

Version

2.1