Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Thin secure Windows 10

Posted on 2016-10-19
5
Medium Priority
?
312 Views
Last Modified: 2016-10-24
I am starting to think about deploying Windows 10.  Are there any good docs out there that show the minimum install (Required services, apps and such) for a thin windows 10 workstation?  I welcome your opinion as well on what can be shut off and what the effect may be.
0
Comment
Question by:loftyworm
  • 3
5 Comments
 
LVL 57

Accepted Solution

by:
McKnife earned 1000 total points
ID: 41850299
About services: http://www.blackviper.com/service-configurations/black-vipers-windows-10-service-configurations/ has always been a good source. He explains, what the column titles mean to him. Be aware, that as soon as you leave the default config, you are not 100% sure anything will works as expected. You can gain a little performance but I wouldn't say it's worth the (small) risk. Better make sure to deploy SSD drives for speed.

About apps: the built-in apps can be uninstalled completely without any side effects. They can be re-enabled if you feel a need later. There are scripts like this:
Get-AppxProvisionedPackage | Remove-AppxProvisionedPackage

Open in new window

that can do the job for you. Dism.exe can be used to even service the install medium already so that those apps will not even be installed in the first place.
Again, the performance gain is not great and disk space saved is marginable.

If you think about a lean windows, ask yourself if the built-in protective measures (bitlocker and win defender) offer reasonable protection and features for you. If so, you might be able to skip installing 3rd party AV and encryption - that would be good for your performance as the MS ones integrate better.
0
 
LVL 11

Author Comment

by:loftyworm
ID: 41850326
TY, I will look it over.  I am less concerned about performance then I am security.
0
 
LVL 57

Expert Comment

by:McKnife
ID: 41850436
The default config is not insecure. The ports are closed, the default ACLs are good. What gets people into trouble is usually their own fault and own misconfig.
0
 
LVL 51

Assisted Solution

by:Jackie Man
Jackie Man earned 1000 total points
ID: 41851757
Windows 10 hardening and enterprise security
http://www.computerworld.com/article/2968394/microsoft-windows/windows-10-hardening-and-enterprise-security.html

The article in the link above might give you some insights. Focus on the features on Multifactor authentication, Data loss prevention (DLP) and Application control might be on your agenda of the security concerns.
0
 
LVL 57

Expert Comment

by:McKnife
ID: 41851805
These measures are something to consider, yes, but not at the stage where he is at (pre-deployment, image creation).
0

Featured Post

Identify and Prevent Potential Cyber-threats

Become the white hat who helps safeguard our interconnected world. Transform your career future by earning your MS in Cybersecurity. WGU’s MSCSIA degree program was designed in collaboration with national intelligence organizations and IT industry leaders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It is a real story and is one of my scariest tech experiences. Most users think that IT experts like us know how to fix all computer problems. However, if there is a time constraint and you MUST not fail the task or you will lose your job, a simple …
How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
This video will show you how to get GIT to work in Eclipse.   It will walk you through how to install the EGit plugin in eclipse and how to checkout an existing repository.
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…

926 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question