Professional Documents
Culture Documents
Troubleshooting
DEFENDING WINDOWS PCS AGAINST MALWARE
Mike Halsey
MVP
7 8.1 10
Mainstream Support Expired Mainstream Support Jan 9, 2018 Mainstream Support 10 years+
Extended Support Jan 14, 2020 Extended Support Jan 10, 2023 Extended Support 10 years+
Module Content
Data protection
Privacy
Organizational File and Data storage
File and Data transport
Level Security Removable and portable media
Encryption
Biometrics
Password enforcement
BYOD access
Guest device access
Windows 7 Windows 8.1 Windows 10
Security Center
Windows Defender Download
Windows Defender Offline Download Download
Windows Firewall
Advanced Firewall
User Account Control
SmartScreen
Malicious Software Removal Tool Option Option
Secure Boot
Trusted Boot
App Containers Limited
Early Launch Anti-Malware
Mandatory Security Updates Option Option
Using Secure Boot
Secure Boot first verifies that the
motherboard UEFI firmware is digitally
signed
It then queries the digital signature of the
Boot loader, checking it matches a
cryptographic signature stored in the UEFI
firmware
If both signatures match, the Operating
System is permitted to load
Secure Boot is required on all consumer
PCs sold with Windows 8.1 and Windows 10
from all Official Microsoft OEM Partners
Custom PCs, and some business PCs may
not come with Secure Boot support, or
with Secure Boot enabled
Some UEFI systems support disabling
Secure Boot in the firmware
Some Linux distros support Secure Boot,
check the website for the distro you wish to
install
Some UEFI systems allow you to mark a
non-Secure Boot OS as safe
Trusted Boot takes over once the OS has
begun to load
It checks the OS Kernel, and all other OS
components, drivers, start-up files, Early
Launch Anti-Malware to see if they have
been modified
Trusted Boot
If a component has been modified,
Trusted Boot will refuse to load that
component, and Windows automatic
system repair will attempt to repair the
damaged or modified component in the
background
Browsing the Web Securely
Never click anything just
because an app or
website asks you to!
Windows 7 Windows 8.1 Windows 10