Lead Image © Galina Peshkova, 123RF.com

Lead Image © Galina Peshkova, 123RF.com

Endpoint Security for Windows 10

Well-Tempered Computer

Article from ADMIN 67/2022
By
Windows 10, build 21H1, has numerous protection mechanisms out of the box. We look at the option for delaying updates, the components and features of Microsoft Defender, and recommendations for hardening the operating system.

Microsoft introduced a number of new security features in Windows 10, but they are not available in all variants of the operating system. For example, features such as Windows Defender Device Guard – now Microsoft Defender Application Control – or Microsoft Defender Credential Guard are only available in Windows 10 Enterprise E3/E5; Microsoft Defender for Endpoint – formerly Advanced Threat Protection – is only available with Windows 10 Enterprise E3/E5, Microsoft 365 E5 Security, and Microsoft 365 E5. Also not to be ignored is that Microsoft only allows the Enterprise version to use group policies that can configure the Windows Store.

Windows Update for Business

The monthly patch day still causes excitement among many administrators, as does the question as to whether everything will continue to work as it did before the update. Microsoft has changed the update cycle for Windows 10. Apart from the monthly critical updates, the company releases optional updates at different times in the second half of the month. Therefore, you can concentrate on installing the critical updates and install the optional updates at a later point in time, once their compatibility with the IT infrastructure has been successfully checked.

Windows Update for Business [1], the update process for business customers, includes what are known as update rings, which you can use to specify the order in which you want to patch end devices and servers. These rings let you, for example, patch only unimportant computers or special test machines in an initial update wave. Update rings also allow systems to be patched as a function of how they interact. For example, a domain controller can be patched first, followed by an Exchange server that requires the Active Directory (AD) services to work properly.

Windows Update for Business also lets you define

...
Use Express-Checkout link below to read the full article (PDF).

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy ADMIN Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

comments powered by Disqus