Summary
In this chapter, we introduced securing end user Windows devices and some of the different Windows 10 versions available. We then covered the Microsoft Defender ATP service by providing a feature overview and guidance for onboarding machines. Following this, we discussed Windows 10 updates using the Windows Update for Business technology and how to configure deployment rings using Intune.
Next, we reviewed advanced Windows hardening configurations, which included technologies such as Windows Hello for biometric authentication, Windows encryption using BitLocker, how to configure Windows Defender AV real-time protection, and SmartScreen. Then, we discussed additional hardening tips to prevent name resolution poisoning and MITM over network communications. We also covered additional hardening tips by discussing Microsoft Office security baselines and hardening Google Chrome. Finally, we finished the chapter with Windows 10 privacy and data protection.
In the following chapter...