October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
BitLocker

Windows 11 Security Settings and Hardening Options: What to Enable

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The HTMD Blog article “Security Settings for Windows 11 Hardening options”, published October 26, 2022, is a useful guide to Windows Security policy areas—but many of its settings hide pages or controls rather than protect the PC. For real hardening, configure protections such as Secure Boot, BitLocker, Microsoft Defender, firewall rules, credential isolation, application controls, and timely updates, then verify they applied.

For managed fleets, Microsoft’s Intune release notes identified the Windows 11 25H2 security baseline as the latest available on August 18, 2026. A baseline is a starting point, not a universal prescription; review its settings, test compatibility, and deploy it in stages.

What the HTMD article covers

The 2022 HTMD article focuses on Windows Security interface areas and related management policies. Its coverage includes:

  • Account Protection
  • App and browser protection
  • Device performance and health
  • Device security
  • Enterprise customization
  • Family options
  • Firewall and Network Protection
  • Notifications and Systray
  • Virus and threat protection

It also points administrators to Group Policy and Intune Settings Catalog categories such as Microsoft Defender, Device Guard, Firewall, and Local Policies Security Options. That makes it a useful map of where to look, but it should not be read as a complete modern hardening standard. Read the original HTMD article.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
YOGOTEU Fingerprint Reader,USB Fingerprint Key Reader Advanced Security Access Window Hello Fingerprint Reader for Windows10/11 Laptops Computer
  • USB Fingerprint Key Reader suitable for Windows10/11 Hello features.
  • 360 Degrees Detection:Fingerprints can be read from any angle in 360Degrees, set up to 10 Fingerprint IDs.
  • 0.05 seconds:Fingerprints authenticated within 0.05seconds. Logins faster and more secure.
  • With intelligent learning algorithm, detection and authentication is faster and more secure.
  • Advanced Protections:Safely protect your logins and data with Fingerprint Security Device.

Hiding Windows Security pages is not the same as hardening

Windows Security policies can control what users see or change. Those controls may help keep users from altering managed settings, but hiding a page does not enable the protection represented by that page. HTMD describes policies to hide areas including Firewall and Network Protection, Device Security, the TPM troubleshooter, notifications, the Systray control, and ransomware-recovery information.

Policy type Example What it does
Visibility-only Hide Account Protection or Firewall and Network Protection Hides a Windows Security area; does not configure sign-in security or firewall rules.
User-control restriction Prevent users from changing selected Windows Security settings Helps preserve administrator-managed configuration, but may make troubleshooting harder.
Direct protection BitLocker, Defender PUA blocking, attack surface reduction (ASR), Credential Guard, or firewall rules Changes security behavior and should be tested for compatibility and operational impact.

Keep useful security warnings visible unless an equivalent monitoring and escalation process is in place. If ransomware-recovery details are hidden, make sure recovery itself is configured and tested; interface suppression is not a backup strategy.

Prioritize protections by what they defend

Hardening means reducing the chance of compromise and limiting the damage if one occurs. Microsoft describes Windows 11’s hardware-security foundations and application and driver controls in its Secure by Design discussion. That does not mean every installation is fully hardened: hardware, edition, configuration, management, and organizational policy all matter.

Threat or objective Controls to consider Important qualification
Device theft and offline data access Secure Boot, TPM, BitLocker, and recovery-key escrow BitLocker protects data at rest; it does not stop malware or an authorized user from accessing data on an unlocked device.
Malware and unwanted software Defender Antivirus, cloud-delivered protection, PUA protection, SmartScreen, and application control Privacy policy, Windows version, management, and application compatibility affect configuration choices.
Credential theft and phishing Windows Hello for Business or another phishing-resistant sign-in method, Credential Guard, LSA protection, and phishing protection Check edition, hardware, identity, and legacy authentication dependencies before enforcement.
Ransomware and malicious execution ASR rules, exploit protection, Controlled Folder Access where appropriate, application controls, and tested backups Begin with audit and pilot deployments for rules that could block business workflows.
Lateral movement Defender Firewall, least privilege, restricted remote management, and appropriately configured RDP and SMB controls Restricting one remote-access path is not enough if another remains exposed.
Persistence through vulnerable software or drivers Prompt updates, vulnerable-driver blocking, HVCI where compatible, and application and driver control Legacy drivers and specialized software can be affected; validate before broad rollout.

MITRE ATT&CK’s operating-system configuration mitigation also highlights controls such as Secure Boot, BitLocker, centrally applied policy, RDP with Network Level Authentication, and configuration audits. MITRE ATT&CK: M1028, Operating System Configuration.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Windows 11 hardening checklist

1. Keep Windows and applications current

Use a managed update process, deploy critical security fixes promptly, and monitor devices that fall behind. Updates to firmware, drivers, browsers, and business applications matter alongside Windows servicing.

2. Establish a trusted boot and encryption foundation

Enable Secure Boot and use TPM-backed protections where supported. Encrypt operating-system and fixed-data volumes with BitLocker, escrow recovery keys to an approved, access-controlled location, and test that authorized administrators can retrieve and use them. Encryption does not replace endpoint protection or backups.

Rank #2
Sale
FIDO U2F Security Key, Thetis [Aluminum Folding Design] Universal Two Factor Authentication USB (Type A) for Extra Protection in Windows/Linux/Mac OS, Gmail, Facebook, Dropbox, SalesForce, GitHub
  • Protect Online Account - Offer a strong factor authentication to your online account. Never lose your accounts through password theft, phishing, hacking or keylogging scams.
  • Universal Compatibility - The Thetis U2F key can be used on any websites which support U2F protocol with the latest Chrome installed on your Windows, Mac OS or Linux. (Important Note: Not compatible with any email clients including Apple Mail, Mozilla Thunderbird or Microsoft Outlook)
  • FIDO-U2f-Certified - Safety is our priority. Certified by world's largest Ecosystem for Standards-based, interoperable Authentication. Only support U2F protocol (No UAF or OTP). Provide low-cost and simple solution with high security.
  • Extremly Durable - Designed with a 360° rotating metal cover that shields the USB connector when not in use. Also, crafted from a durable aluminum alloy to protect the Key from drops, bumps and scratches.
  • Portable Design - Compact, ultra-portable design allows you to take your FIDO key anywhere you need it.

3. Configure endpoint protection and the firewall

Use Microsoft Defender Antivirus real-time protection, cloud-delivered protection, and sample-submission settings consistent with organizational privacy requirements. Keep Defender Firewall enabled for domain, private, and public profiles, and use inbound rules that reflect the device’s role rather than allowing broad access.

Do not assume that adding another antivirus product leaves Defender Antivirus unchanged. The original HTMD article notes that another antivirus can affect Defender Antivirus’s behavior. Distinguish the primary antivirus role from other Microsoft security capabilities, such as Defender for Endpoint’s sensor and security-management functions, and verify the actual state on managed devices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Protect against unwanted and malicious execution

Enable SmartScreen and phishing protections where supported, and assess PUA protection, ASR rules, exploit protection, and application control. Smart App Control’s availability and lifecycle depend on the Windows version, installation state, hardware, and administration. For managed enterprise fleets, consider App Control for Business rather than treating consumer-oriented controls as a universal deployment path.

5. Reduce credential exposure and privilege

Use standard accounts for routine work and controlled, logged elevation for administrative tasks. Assess Windows Hello for Business or another phishing-resistant sign-in method, Credential Guard, and LSA protection. Review custom security support providers, authentication packages, and older authentication dependencies before restricting them.

6. Protect recovery and visibility

Collect security events centrally, alert on meaningful Defender and policy signals, maintain tested backups, and verify recovery procedures. A policy assignment showing success is not by itself proof that a protection is functioning as intended.

Deploy Defender PUA protection in stages

Potentially unwanted application (PUA) protection can block or audit software Microsoft classifies as potentially unwanted. Microsoft documents the following PowerShell controls and numeric values; run management commands in an elevated PowerShell session where required and verify the resulting state.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
  1. Start in Audit mode. This records detections without applying the blocking behavior, so administrators can identify legitimate software and workflows that need attention.
  2. Review events and reports. Investigate detections, identify approved business applications, and document any exception and its owner.
  3. Enable blocking for an appropriate pilot group. Expand only after the audit and pilot results are acceptable.
  4. Monitor and retain a rollback path. If a business-critical workflow is affected, use the documented setting to return to audit or disable it while troubleshooting.
# Enable blocking
Set-MpPreference -PUAProtection Enabled

# Use audit mode
Set-MpPreference -PUAProtection AuditMode

# Disable for controlled rollback or troubleshooting
Set-MpPreference -PUAProtection Disabled

# Query the current value
Get-MpPreference | Format-Table PUAProtection

Microsoft maps the returned values as 0 for disabled, 1 for enabled/block, and 2 for audit mode. The documented Group Policy path is Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus > Configure detection for potentially unwanted applications; set it to Enabled, then choose Block or Audit Mode. Defaults can vary with Windows version, Defender for Endpoint onboarding, Smart App Control state, and security intelligence version, so verify rather than assume. Microsoft PUA protection documentation.

Use Intune baselines and Settings Catalog carefully

As of August 18, 2026, Microsoft’s Intune release notes identified the Windows 11 25H2 security baseline as the latest available. Microsoft notes that a new baseline can add settings, change defaults, retire settings, or update guidance; existing profiles do not automatically move to the new baseline. Review the release notes and your customizations before changing profiles. Microsoft Intune release notes.

A baseline is a reviewed starting configuration, not an instruction to override every business-specific setting. Microsoft’s documented 25H2 update includes a setting concerning disabling Internet Explorer 11 launch through COM automation, and Microsoft notes that existing profiles may need to be edited and saved for updated settings to take effect. Confirm current behavior in the release notes and the profile before rollout.

Create a targeted Settings Catalog policy

  1. In the Microsoft Intune admin center, go to Devices → Configuration → Create → New policy.
  2. Choose Windows 10 and later, then select Settings catalog.
  3. Search by the security capability you need, such as Microsoft Defender, Attack Surface Reduction, Device Guard, Firewall, Local Policies Security Options, BitLocker, SmartScreen, or Windows Security.
  4. Configure only settings tied to a defined security objective. Check for overlapping settings in security baselines, Endpoint security policies, Group Policy, Configuration Manager, and other management tools.
  5. Assign the policy to a pilot device group, review policy status and conflicts, and validate behavior on representative devices.
  6. Expand assignment in deployment rings, monitoring device status and application impact at each stage.

The HTMD article specifically recommends searching the Settings Catalog for Microsoft Defender, Device Guard, Firewall, and Local Policies Security Options. Use those as navigation cues, not as a reason to deploy every matching setting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Update a baseline without losing track of customizations

  1. Compare the new baseline’s settings with the deployed profile and record local changes, exclusions, and business owners.
  2. Review additions, changed defaults, and retired settings against your applications and threat model.
  3. Test the revised configuration on representative hardware and software, including devices that are remote or intermittently connected.
  4. Expand in rings only after reviewing conflicts, device reporting, event logs, and user impact.

Group Policy areas that deserve review

For traditional Active Directory or hybrid estates, review policy precedence and assignment scope before adding equivalent Intune settings. Avoid having multiple management planes set the same control without understanding which value wins.

  • Credential and authentication protection: LSA protection, Credential Guard, custom security support providers and authentication packages, LAN Manager hash storage, account lockout, password policy, and phishing-resistant sign-in.
  • Network security: Defender Firewall profiles and inbound defaults, RDP exposure and Network Level Authentication, SMB signing where appropriate, anonymous enumeration, and legacy protocol dependencies.
  • Application and exploit protection: ASR, exploit protection, SmartScreen, application control, and vulnerable-driver blocking.
  • Data protection: BitLocker, recovery-key handling, removable-media controls, and backup validation.

Microsoft’s Windows 11 22H2 baseline discussion emphasized protections including LSASS, custom SSPs and authentication providers, enhanced phishing protection, vulnerable-driver blocking, and administrator account lockout. It is useful background, but do not treat a 2022 baseline discussion as current configuration guidance for every Windows 11 release. Microsoft Windows 11 22H2 security baseline discussion.

Rank #4
AHANIN Windows Hello Fingerprint Reader, USB Dongle for Windows 11 & 10
  • Point 1 【WINDOWS HELLO COMPATIBLE】 Works with Windows 10 and Windows 11 Windows Hello as a Windows Hello fingerprint reader. This fingerprint reader for Windows 11 supports one-touch fingerprint login to replace passwords, for quick unlock of laptops and desktops.
  • Point 2 【PLUG & PLAY, NO DRIVERS REQUIRED】 This plug and play USB fingerprint reader works as a usb fingerprint reader windows 11 dongle. Insert it into any USB port for recognition without extra software or drivers. Its slim compact shape will not block adjacent USB slots on your PC, suitable as a fingerprint reader for pc.
  • Point 3 【360° FAST FINGERPRINT SCANNING】 This fingerprint scanner features a 360° all-angle sensor for steady fingerprint matching. The biometric sensor can store multiple fingerprints at the same time, matching the use of multi-user shared desktop and laptop computers.
  • Point 4 【ENCRYPTED BIOMETRIC SECURITY】 This fingerprint reader has a built-in encryption chip. The chip blocks unauthorized access to PC login accounts, personal files and stored data. It adds password-free security for fingerprint login on Windows devices.
  • Point 5 【PORTABLE FOR WINDOWS DEVICES】 This lightweight biometric finger print device fits home, office and travel scenarios. It works with most Windows laptops, desktops and all-in-one PCs, for convenient unlock when you carry computers outside.

Verify configuration on the device

Use read-only checks to confirm what the device reports, then compare results with the management console and policy assignment. Some commands require administrator rights; output and command availability depend on Windows edition, hardware, configuration, and management state.

# Defender Antivirus status
Get-MpComputerStatus

# Defender Antivirus preferences, including PUA protection
Get-MpPreference
Get-MpPreference | Format-Table PUAProtection

# BitLocker volumes (administrative rights may be required)
Get-BitLockerVolume

# Secure Boot status (supported UEFI devices; may require elevation)
Confirm-SecureBootUEFI

# TPM status
Get-Tpm

A successful command is only one check. Reconcile local results with Intune or Group Policy reporting, Defender alerts, relevant event logs, and practical tests such as recovery-key retrieval and application operation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Test compatibility before enforcing aggressive controls

HVCI, Credential Guard, ASR, application control, and restrictive network policies can interrupt software or workflows. Check specifically for:

  • Legacy or unsigned drivers, VPN clients, network filters, and security software.
  • Virtualization products and hardware without required TPM, Secure Boot, or virtualization support.
  • Screen readers and accessibility tools.
  • Medical, industrial, point-of-sale, or other specialized applications.
  • Custom authentication providers and applications that rely on legacy credentials.
  • Software that depends on macros, scripts, SMB, NTLM, legacy printers, or broad network access.
  • Remote and offline scenarios, including VPN, captive portals, and domain-disconnected use.

Microsoft’s baseline discussion calls for compatibility testing where hardware-enforced protections and drivers may be affected. Use audit mode where available, pilot on representative devices, define an owner for each exception, and document how to reverse a policy that blocks essential work. Microsoft baseline compatibility discussion.

Choose the management path for your environment

Home or unmanaged PC

Prioritize Windows Update, Defender Antivirus, the firewall, Secure Boot, device encryption or BitLocker where available, a standard-user account, Windows Hello, SmartScreen, PUA protection, browser security, backups, and safe recovery-key storage. Avoid manually importing enterprise Group Policy settings or Intune baselines without a clear reason.

Small business

Start with centrally managed updates, endpoint protection, encryption and recovery-key handling, least privilege, and tested backups. Add a management service when you need reliable deployment, inventory, compliance reporting, and response—not simply because a long checklist exists.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
TNP USB-C Fingerprint Reader, Windows Hello PC Scanner for Windows 11/10
  • Support Windows 10 / 11 Hello Biometric Authentication: Plug and play with updated Windows OS, provides instant access for Windows computers. Tasks such as login, sign in or unlock can be accomplished with a touch of a finger, no need to remember usernames and passwords
  • Up to 5 Fingerprint Registration: Allow family members, close friends, or colleagues to gain access to a single computer. 360° all direction fingerprint registering for better accuracy and faster response.
  • Paralleled Software Support: With Smart ID Encryption, encrypting your files has never been so easy. You can specify a folder as an encrypted zone, once a file is copied into the folder, it automatically be encrypted.
  • Gets Smarter Over Time: With each fingerprint registry, the scanned data is added to the profile of the enrolled finger. So, the more you use it, the more accurate it gets. Allowing faster access.
  • All You Need in a Nano Formfactor: Small and lightweight, takes up no space. Drop it in your pocket and you wouldn't even notice a thing.

Microsoft Entra-joined or Intune-managed organization

Use an Intune security baseline as a starting point, then layer targeted Endpoint security policies and Settings Catalog settings. Consider Defender for Endpoint, Conditional Access, Windows Hello for Business, BitLocker escrow, ASR, application control, compliance policies, and device-risk integration according to licensing and operational capacity. Separate administrative roles and protect privileged accounts.

Hybrid Active Directory organization

Account for Group Policy precedence, OU design, security filtering, and any loopback processing in use. Map existing policies before migrating them to Intune, and investigate NTLM, SMB, RDP, printer, and other legacy dependencies. Harden identity systems and administrative tiers as well as client devices.

Regulated or government environments

Use the benchmark or framework required by the organization, but assess applicability and operational impact. Microsoft baselines are a natural starting point for Microsoft-managed Windows estates; CIS benchmarks help with benchmark-based governance; DISA STIGs are designed for applicable U.S. government and defense contexts and may be too restrictive as a general commercial or home-PC default. None removes the need for testing, approved exceptions, and ongoing review. Microsoft Security Compliance Toolkit and Windows security baselines · CIS Benchmarks.

Match tools to the job

Management, detection, and assessment tools solve different problems. Buying a product does not automatically harden Windows; the organization still needs someone to own deployment, alerts, exceptions, and remediation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Tool or approach Primary job What it does not replace
Intune Cloud device management, configuration, security policies, compliance, and baseline deployment Endpoint detection and response by itself
Defender for Endpoint Endpoint detection and response, security investigation, and related endpoint protections Carefully designed configuration and policy deployment
Defender for Business Endpoint security capabilities for smaller organizations Operational ownership, backup, or configuration planning
Configuration Manager Management in established on-premises or co-managed estates A security baseline decision or threat-response process
CIS-CAT Pro Assessment and reporting against CIS Benchmarks Intune policy deployment or EDR
Tenable Nessus Vulnerability and configuration assessment across infrastructure Windows endpoint policy management or EDR

Product availability, licensing, and feature entitlement vary by plan and organization; check the vendor’s current terms before making a purchasing decision. Microsoft Intune · Microsoft Defender for Endpoint · Microsoft Defender for Business · Microsoft endpoint management · CIS-CAT Pro · Tenable Nessus.

A practical rollout sequence

  1. Inventory devices, editions, hardware support, management planes, business applications, and remote-access paths.
  2. Choose a baseline that fits the organization, compare it with current policy, and document justified deviations.
  3. Deploy core protections first: updates, Secure Boot and TPM where supported, encryption with recoverable keys, Defender, firewall, and least privilege.
  4. Use audit mode and pilot rings for PUA, ASR, HVCI, Credential Guard, application control, and compatibility-sensitive network restrictions.
  5. Verify policy status on devices, inspect events and alerts, test core applications, and confirm recovery procedures.
  6. Expand gradually, assign owners to exceptions, and review policy drift and baseline changes on a recurring schedule.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.