Windows Updates and Security Hardening
Device profile: Windows update settings
Section titled “Device profile: Windows update settings”Auto Update Enabled Controls whether automatic updates are enabled for the device. Auto Update Options Defines the update behavior, such as download and install scheduling. Scheduled Install Day / Time Specifies when updates should be installed (day and time). Auto Reboot With Logged On Users Determines if the system is allowed to reboot while users are logged in. Always automatically restart at the scheduled time / timeout Forces device restart after a specific timeout when scheduled installs occur. Include Recommended Updates If enabled, recommended updates will be installed in addition to critical ones. Install updates for other Microsoft products Expands updates to include non-Windows Microsoft software. Show a notification when restart is needed Displays a prompt when a restart is required after update. Notification dismissal method Sets how update notifications are dismissed (e.g., manually or auto). Enable Active Hours Activates protection against restarts during user-defined hours. Active Hours Start / End Defines the window during which restarts are restricted. SLA for Number of Days Service Level Agreement expectation for completing updates. Check OS Version for Servicing Support Verifies if the OS version is eligible for updates. Use Update Class Policy Source Determines whether to inherit update class settings from policy source. Set Policy Driven Update Source for: Provides granular control over update sources for:
- Feature Updates
- Quality Updates
- Driver Updates
- Other Updates
Third Party Patching Configure automated patching of non-Microsoft (third-party) applications. This section allows administrators to schedule recurring tasks to apply patches across supported third-party software. Fields include:
- AutoRun – Enables or disables the entire patching task.
- Run Task – Defines execution frequency (e.g., Weekly).
- Day of Week – Select the specific weekday to run the task.
- Start Time – Defines the time of day when patching begins.
- Auto Reboot With Logged On Users – If enabled, the system will automatically reboot even if users are logged in.
- Show a notification when your PC requires a restart – Notifies end users about required reboots after patching.
- Run updates under user context – Executes patching with the logged-in user’s credentials.
- Only when user is local Administrator – Limits patching execution to devices where the user has local admin rights.
Intune Determines how the device is managed within Microsoft Intune. The only available setting here is:
- Device Ownership – Select between Corporate or Personal to define how the device should be enrolled in Intune.
Windows Disk Cleanup Enables automated cleanup of system files and temporary data to reduce storage usage and improve performance. You can control the execution schedule and the specific file types that should be purged during cleanup. Available fields:
- AutoRun – Enables or disables the cleanup task entirely.
- Run Task – Defines the cleanup frequency (e.g., Weekly).
- Day of Week – Selects which day the cleanup should run.
- Start Time – Specifies the exact time for execution.
Checkboxes allow granular control over the types of data to remove:
- Temporary Setup Files – Removes files created during Windows setup.
- Old Chkdsk Files – Deletes log files from past Check Disk scans.
- Setup Log Files – Clears installation logs created by Windows or third-party software.
- Microsoft Defender Antivirus – Cleans up AV scan history and outdated definition logs.
- Diagnostic Data Viewer Database Files – Deletes system diagnostic history.
- Downloaded Program Files – Removes ActiveX controls and Java applets.
- Temporary Internet Files – Clears web browser caches (IE/Edge legacy).
- System Error Memory Dump Files – Deletes memory dumps generated after system crashes.
- System Error Minidump Files – Clears smaller crash dumps.
- Windows Error Reports and Feedback Diagnostics – Deletes reports generated by Windows Error Reporting (WER).
- Branch Cache – Removes cached content for branch office optimization.
- DirectX Shader Cache – Clears files created by the GPU shader compiler.
- Delivery Optimization Files – Deletes files used in peer-to-peer update delivery.
- Language Resources Files – Removes unused language packs.
- Recycle Bin – Empties the system recycle bin.
- Retail Demo Offline Content – Deletes demo materials for retail display devices.
- Temporary Files – Clears generic temporary files from the system.
- Thumbnails – Deletes image thumbnail cache files.
- User File History – Removes historical backups of user files.
- Catalog Files for the Content Indexer – Deletes indexing-related files.
- Downloads (Personal downloads folder) – Clears files from the user’s Downloads folder.
- Offline Files – Deletes cached files used for offline access.
- Windows Upgrade Log Files – Removes logs from previous Windows version upgrades.
- Windows Update Cleanup – Deletes outdated updates and update cache data.
Device Local Admin Allows automated management of a predefined local administrator account on the endpoint. This can be used for consistent access across devices, especially in environments where users are not local admins.
- Device Local Admin – Enables or disables creation of the account.
- Local Admin Username – Defines the username to be created (e.g.,
virtualadmin). - Auto-Rotate Local Admin Password – When enabled, the password is automatically rotated at a set interval.
- Interval to Auto-Rotate (Days) – Sets the rotation frequency (e.g., every 90 days).
Security hardening
Section titled “Security hardening”The Security Hardening section provides a list of configurable system policies focused on enhancing endpoint security. Each rule modifies OS, network, or application behavior to reduce vulnerabilities. The table includes columns for property name, affected system component, change type, and toggles for enabling the rule and allowing user control.
Enable ‘Local Security Authority (LSA) protection’ Secures the Local Security Authority process by preventing unsigned drivers and plug-ins from being loaded. Enhances credential protection on Windows systems. Set User Account Control (UAC) to automatically deny elevation requests Prevents unauthorized applications or users from attempting privilege elevation by default denial. Enable ‘Require additional authentication at startup’ Forces multi-factor or secure boot mechanisms to be enforced at system startup. Set default behavior for ‘AutoRun’ to ‘Enabled: Do not execute any autorun commands’ Disables execution of autorun.inf files to prevent malware propagation through removable media. Set LAN Manager authentication level to ‘Send NTLMv2 response only. Refuse LM & NTLM’ Improves authentication protocol security by eliminating older, less secure LM and NTLM methods. Disable Anonymous enumeration of shares Prevents unauthenticated users from discovering shared folders on the system. Disable ‘Installation and configuration of Network Bridge on your DNS domain network’ Blocks creation of network bridges which could be used to bypass network segmentation policies. Enable Local Admin password management Allows centralized and secure rotation or assignment of local administrator passwords. Disable the local storage of passwords and credentials Prevents Windows from saving passwords in local stores, reducing credential theft risks. Enable ‘Microsoft network client: Digitally sign communications (always)’ Requires SMB packets to be signed, ensuring data integrity and helping prevent man-in-the-middle attacks. Enable ‘Apply UAC restrictions to local accounts on network logons’ Limits local accounts’ ability to perform elevated operations over network sessions, improving remote access security. Prohibit use of Internet Connection Sharing on your DNS domain network Disables ICS to prevent endpoints from acting as unauthorized internet gateways. Disable running or installing downloaded software with invalid signature Blocks untrusted software lacking a valid digital signature from execution or installation. Disable ‘Continue running background apps when Google Chrome is closed’ Prevents Google Chrome from maintaining active processes after the browser window is closed, reducing background resource usage and potential vulnerabilities. Disable ‘Password Manager’ in Google Chrome Disables Chrome’s built-in password manager, encouraging use of more secure enterprise credential stores. Disable ‘Always install with elevated privileges’ Prevents software installations from automatically using elevated privileges, reducing the attack surface during application deployment. Disable JavaScript on Adobe DC Disables JavaScript execution within Adobe Acrobat to reduce exposure to document-based exploits. Enable ‘Require domain users to elevate when setting a network’s location’ Requires administrator approval for domain users when attempting to change network location, reducing misclassification of network zones. Enable ‘Block third party cookies’ in Google Chrome Prevents websites from saving third-party cookies, enhancing user privacy and reducing cross-site tracking. Set controlled folder access to enabled or audit mode Activates Microsoft Defender Exploit Guard’s Controlled Folder Access to restrict untrusted apps from making changes to protected directories. Disable Flash on Adobe Reader DC Removes support for Flash content in Adobe Reader DC, addressing known security vulnerabilities. Disable JavaScript on Adobe Reader DC Disables JavaScript execution in Adobe Reader to minimize risk from malicious scripts embedded in PDF files. Set ‘Remote Desktop security level’ to ‘TLS’ Ensures Remote Desktop sessions use TLS for secure encrypted communications. Enable ‘Limit local account use of blank passwords to console logon only’ Restricts blank password usage to local console access, blocking remote login attempts without proper credentials. Disable ‘Device Install Software Request Error Report’ option Turns off error reporting prompts related to device driver installation issues. Prevent Internet Control Message Protocol (ICMP) redirects from overriding Stops devices from accepting ICMP redirect packets, defending against certain network-level attacks. Block outdated ActiveX controls for Internet Explorer Prevents the execution of unsupported or outdated ActiveX components, mitigating legacy vulnerabilities in Internet Explorer. Disable ‘Allow Basic authentication’ for WinRM Client Disables legacy authentication for Windows Remote Management client to enforce stronger methods like Kerberos or certificate-based login. Disable ‘Allow Basic authentication’ for WinRM Service Same as above but applied to the server side (WinRM service), further securing remote management protocols. Disable ‘Autoplay’ for non-volume devices Blocks autoplay functionality for devices such as memory cards or digital cameras to prevent unwanted script execution. Disable ‘Autoplay’ for all drives Globally disables autoplay across all connected drives to mitigate autorun-based threats. Disable ‘Enumerate administrator accounts on elevation’ Prevents Windows from listing available administrator accounts when elevation is required, reducing information leakage. Disable IP source routing Blocks IP packets that specify source routing, a rarely used option that can be abused to bypass network security policies. Disable merging of local Microsoft Defender Firewall rules with group policy firewall rules for the Public profile Ensures that only centrally managed Group Policy firewall rules are applied to the Public profile, overriding any local rules that may weaken security. Disable merging of local Microsoft Defender Firewall connection rules with group policy firewall rules for the Public profile Similar to the previous setting, this blocks local connection rules from merging with Group Policy settings for the Public profile. Disable SMBv1 client driver Disables the legacy SMBv1 protocol driver to reduce vulnerabilities from outdated network file sharing protocols. Disable Solicited Remote Assistance Blocks users from sending invitations for remote assistance, helping prevent unauthorized remote access attempts. Hide Option to Enable or Disable Updates Removes the UI options that allow users to enable or disable Windows Updates manually, helping enforce centralized update policies. Microsoft Office Enable Automatic Updates Enables automatic updates for Microsoft Office, ensuring the suite stays up to date with security patches and improvements. Set IPv6 source routing to highest protection Configures IPv6 to reject source routing headers, which can be used to bypass normal routing and launch network attacks.