Given the additional security that's coming with Windows 11, it was pointed out to me there are a number of optional Device Security features that may be turned on in Windows 10. I'd appreciate hearing from anyone who's explored and/or implemented any of these features.
Windows will turn these on automatically if they are available. Memory Integrity and Core Isolation require TPM 2.0. Security Processor requires TPM 1.2(I believe). Secure Boot requires UEFI. Here is a link talking about the options. Device protection in Windows Security (microsoft.com)
Not sure I agree with "Windows will turn these on automatically if they are available," because my motherboard doesn't have the TPM chip installed (it's on order!), but I can turn on Core Isolation.I don't see the other options on my computer because of the missing TPM chip I assume. Yes, I had previously looked at that MS website for more info. Googling about the subject yielded next to nothing other than from MS. I generally don't turn on optional Windows features unless/until I have enough information to change my decision.
This topic area includes legacy versions of Windows prior to Windows 2000: Windows 3/3.1, Windows 95 and Windows 98, plus any other Windows-related versions including Windows Mobile.
Here is a link talking about the options. Device protection in Windows Security (microsoft.com)