From the Field: Security Features

๐Ÿ”Ž ๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ โ€” Real-World Findings from Security Assessments

๐Ÿ’ฅ ๐Ÿฒ๐Ÿญ.๐Ÿต% of infrastructures Iโ€™ve assessed do not use any security featuresย available on Windows Server.

๐—ช๐—ฒ’๐—ฟ๐—ฒ ๐˜๐—ฎ๐—น๐—ธ๐—ถ๐—ป๐—ด ๐—ฎ๐—ฏ๐—ผ๐˜‚๐˜:

๐Ÿ” Secure Boot (needs UEFI)

๐Ÿ” Trusted Boot (auto-enabled with Secure Boot)

๐Ÿ” Credential Guard (requires Secure Boot + virtualization)

On modern Windows 11 workstations, these are often enabled by default.

๐—•๐˜‚๐˜ ๐—ผ๐—ป ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ๐˜€?

I still regularly see BIOS-based configs and protections turned off. Onย supported versionsย of Hyper-V and VMware, UEFI + Secure Boot can be enabled by default.

๐—ง๐—ต๐—ถ๐˜€ ๐—ฒ๐˜…๐—ฝ๐—ผ๐˜€๐—ฒ๐˜€ ๐˜†๐—ผ๐˜‚ ๐˜๐—ผ:

โš ๏ธ Bootkits

โš ๏ธ Rootkits

โš ๏ธ Credential Theft

Enabling these is not optionalโ€”๐—ถ๐˜โ€™๐˜€ ๐—ฒ๐˜€๐˜€๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น.

๐—š๐—ผ๐—ผ๐—ฑ ๐—ป๐—ฒ๐˜„๐˜€?

๐Ÿ“ฆ Windows Server 2025 enables Credential Guard by default (on supported hardware).

๐Ÿ‘‰ Are these protections enabled in your environment? If not, whatโ€™s stopping you?