Solved

Thin secure Windows 10

Posted on 2016-10-19
5
46 Views
Last Modified: 2016-10-24
I am starting to think about deploying Windows 10.  Are there any good docs out there that show the minimum install (Required services, apps and such) for a thin windows 10 workstation?  I welcome your opinion as well on what can be shut off and what the effect may be.
0
Comment
Question by:loftyworm
  • 3
5 Comments
 
LVL 53

Accepted Solution

by:
McKnife earned 250 total points
Comment Utility
About services: http://www.blackviper.com/service-configurations/black-vipers-windows-10-service-configurations/ has always been a good source. He explains, what the column titles mean to him. Be aware, that as soon as you leave the default config, you are not 100% sure anything will works as expected. You can gain a little performance but I wouldn't say it's worth the (small) risk. Better make sure to deploy SSD drives for speed.

About apps: the built-in apps can be uninstalled completely without any side effects. They can be re-enabled if you feel a need later. There are scripts like this:
Get-AppxProvisionedPackage | Remove-AppxProvisionedPackage

Open in new window

that can do the job for you. Dism.exe can be used to even service the install medium already so that those apps will not even be installed in the first place.
Again, the performance gain is not great and disk space saved is marginable.

If you think about a lean windows, ask yourself if the built-in protective measures (bitlocker and win defender) offer reasonable protection and features for you. If so, you might be able to skip installing 3rd party AV and encryption - that would be good for your performance as the MS ones integrate better.
0
 
LVL 11

Author Comment

by:loftyworm
Comment Utility
TY, I will look it over.  I am less concerned about performance then I am security.
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
The default config is not insecure. The ports are closed, the default ACLs are good. What gets people into trouble is usually their own fault and own misconfig.
0
 
LVL 41

Assisted Solution

by:Jackie Man
Jackie Man earned 250 total points
Comment Utility
Windows 10 hardening and enterprise security
http://www.computerworld.com/article/2968394/microsoft-windows/windows-10-hardening-and-enterprise-security.html

The article in the link above might give you some insights. Focus on the features on Multifactor authentication, Data loss prevention (DLP) and Application control might be on your agenda of the security concerns.
0
 
LVL 53

Expert Comment

by:McKnife
Comment Utility
These measures are something to consider, yes, but not at the stage where he is at (pre-deployment, image creation).
0

Featured Post

Scale it in WD Gold

With up to ten times the workload capacity of desktop drives, WD Gold hard drives employ advanced technology to deliver among the best in reliability, capacity, power efficiency and performance.

Join & Write a Comment

Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now