System Protection turned on, but won't save restore points on OS drive
I'm running Windows 10 Pro on a Dell T7910 Workstation housing 8 drives. I have System protection enabled on all of the drives with max usage set to 20% on each drive. I am able to create shadow copies on all of the drives EXCEPT the OS drive. Obviously,…
Secure RDP/IPSec using connection security rules in Windows Defender
I am trying to configure RDP to use IPSec. I have configured two connection security rules for TCP and UPD, requiring authentication for inbound and requesting outbound connections. Authentication method is computer kerberos5. From there I am using a GPO…
How can we Block the StickyNotes through GPO ? So that user won't be able to access this.
Need to Block the StickyNotes App on windows 10 Pro Client Machine from GPO from Window Server 2019. I Tried the below mentioned steps, but didn't work. Can any one help me out?
Understanding Virtualization-Based Security in Windows 10/11 Home Editions
Im confused regarding how VBS operates in Windows 10 and 11 Home editions, since resources indicate that VBS requires the Windows hypervisor to create an isolated environment, while other resources imply that Hyper-V, so the Hypervisor (or is there the…
installation of windows defender on thin client of HP
Hi Team, Need to deploy windows defender on HP Thin client with operating system Windows 10 IOT and need to deploy on 300 systems and need to monitor also everday whether its getting updated or not . How can we monitor those systems for windows defender…
How do I disable Windows Security pop up everytime I used a saved password on Chrome?
I am tired of having to scan my fingerprint/enter my windows hello pin every single time I need to use a saved password on Chrome. How do I turn this off? I tried disabling windows hello on chrome settings but it still doesn't help!
Safety Scanner found 12 infected files but scan results said no problems detected
I ran a Microsoft Security Scan and during the scan I could see that it had found 12 infected files. When the scan completed, it said that there were no viruses, spyware, or other potentially unwanted software detected. I have attached screen shots. …
what solution has replaced microsoft Network Access Protection (NAP)
NAP is a client health policy creation, enforcement, and remediation technology. With NAP, system administrators can establish and automatically enforce health policies, which can include software requirements, security update requirements, and other…
Event ID 4673 for Teams.exe and msedge.exe
We have turned on auditing for Sensitive Privilege Use (both Success and Failure), per STIG V-220770. However, this has led to hundreds of Audit Failures per minute on nearly every endpoint. When checking the Event Viewer I see it's mainly for Teams…
Microsoft XDR (Defender) - DeviceEvents - ShellLinkCreateFileEvent
Hi everyone, I've been trying to create a hunting query in the Defender portal to identify when a malicious .lnk file is created. I noticed that an interesting event to detect and analyze this is "DeviceEvents --> ShellLinkCreateFileEvent",…
Windows NT Heap Alignment on 64-bit Systems
I am trying to develop my own heap for an IoT platform, which is supposed to be an equivalent NT heap of Windows for my masters degree. From what I've seen, it appears like the NT Heap header on 64-bit systems seems to be 8 bytes long. Whenever I…
Can't decrypt my files and folder, certutil shows "Missing stored keyset" for my user's certificate
So a couple of months back, I encrypted some of my files and folder through a simple encryption GUI method. Click on file > Properties > Advanced.. >Compress and Encrypt attributes > Check mark on **Encrypt contents to secure data. ** …
Implementing Australian Essential Eight Application Control via Windows Defender Application Control
Australian Government recommends implementation of Application Control specifically: The execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets is prevented on workstations from…
Bitlocker and memory remanence attack - basic question
Hi, basic bitlocker question If you aren't setting a TPM + Startup PIN, it doesn't matter if you configure the close lid behaviour to sleep or hibernate does it? Meaning if the laptop is stolen and either in sleep or hibernate state, as soon as the…
How do I add my custom windows App to the Kiosk App list when I create a Kiosk user account
I have a WPF custom application that needs to start in kiosk mode on my pc that has windows enterprise LTS version 1809. When I try to create a kiosk user using the instructions on MS support/ community sites, the only app that is available is the…
Code-Signed .exe File Publisher Name Issues in Windows 11
Hello! I developed a program and purchased a code signing certificate from SSL.com to distribute it. However, when signing the .exe file, the publisher name includes my state and hometown instead of just my name. SSL support tested the program on various…
Can't access computer drive remotly via C$
Hi , I think I have a setting or a service in my environment causing the issue , so when I try to browse to \computername\C$ I get the following errors. Network Error Windows cannot access \computername\C$ check spelling ... Although I'm sure…
Intel txt, VT -d , tpm
Hello, I'm having some issues with my laptop and I checked the status with hwinfo. Tpm: In hwinfo it says tpm on board is not supported in **tpm.msc** it says tpm is ready to use, but in Windows defender it says it's not ready for confirmation. …
Security Defaults settings email
I received this email from Microsoft Security The security defaults setting for your sustainablearizona.org tenant will be turned on by January 2, 2025 I have no idea what this means. It talks about my "tenants." I didn't know I had tenants.…
Microsoft Authenticator | Unknown Devices Linked to My Account
I am reaching out to seek assistance regarding an issue I encountered while signing into Outlook via the browser and using my authenticator app. During the sign-in process, I have the option to view which devices the sign-in request is being sent…