windows-v4.0 #256
Replies: 1 comment
|
Very nice work @SkipToTheEndpoint. I sincerely appreciate #247, #250 and #253 being included. Regarding Process Isolation and Code Integrity
I have not personally experienced any issues with Process Isolation. The challenges I have encountered relate primarily to some network printer drivers when the following Edge security settings are enabled:
In the first case (Dynamic Code Settings), some network printer drivers rely on dynamic code generation and may fail when this capability is blocked. However, Win - OIB - SC - Microsoft Edge - D - Security - v4.0 retains Dynamic Code Settings at the more permissive In the second case (Browser Code Integrity Guard), the situation is more complex. Microsoft no longer signs new v3 and v4 printer drivers, which means newer driver versions introduce an additional compatibility challenges. First, deploy the vendor's signing certificate to Trusted Publishers just to allow the driver to load. Even after the driver loads successfully, printing may still fail in Edge while working in Chrome, as components used by the driver can be blocked by Browser Code Integrity Guard when they are not Microsoft-signed. Personally, if I had to choose between the two controls, I would favour retaining Browser Code Integrity Guard (which is Edge-specific). That said, I would be interested in hearing others' perspectives on the security value and compatibility trade-offs of these two settings. Possible TypoI also wanted to kindly point out what appears to be a typo in the release notes in section Win - OIB - SC - Microsoft Edge - U - User Experience.
I believe the second entry was intended to be:
|
Uh oh!
There was an error while loading. Please reload this page.
Windows v4.0 - 2026-09-30 - 26H2 Edition
Windows 11 26H2 is upon us, and with it comes the first major version number bump since the OIB's first "proper" release! Since then it's somehow grown far, far bigger than I ever imagined, and having the opportunity to travel into Europe and the US because people want to listen to me talk about the little passion project that could has been genuinely heart-warming.
This release brings user experience and device security settings you're not going to find anywhere else, bug fixes thanks to the kind folks providing feedback and raising issues, and adjustments to keep your Intune admin experience manageable at scale.
Because I'm determined to beat Microsoft for the 3rd time running on getting the OIB out before they get their own into Intune, the only setting from their 26H2 baseline not included relates to Windows Ready Print, mostly because it's not in Settings Catalog at time of writing this, but also because most people are still battling with printers as it is, let alone Ready Print. I'll review and update as required.
I've also updated my OIB vs CIS Deviation report against their 5.0.0 Intune Benchmark, so you can see exactly what (and why) I've decided to not align here, and try and make those fights with security teams easier.
For your continued trust, support and positive comments, thank you. <3
Added 🆕
🆕 Compliance
One of the biggest changes with this release is the separation of Compliance settings into their own policies, rather than grouped by higher-level categories. This allows for more granular control over compliance grace periods and makes it easier to manage potential exclusions per-environment. I've also brought them in-line with the broader OIB naming convention, which they weren't previously.
Below is a table of the new compliance policies, the setting being required, and the non-compliance schedule:
security intelligence up-to-date
Keen-eyed among you may notice the absence of what used to form the "Password" compliance policy. My reason for removing these is simple: They're trash.
The longer version to that is that they can be incredibly problematic, but also mostly redundant. Those Password compliance settings exist in the DeviceLock CSP, utilise the Exchange ActiveSync Policy Engine (EAS), and have been around since Windows 8.1. This often catches people off-guard, because people expect Compliance to merely check device settings, but these policies are actually then enforced. Moreover, they only impact local accounts. Things like password policies are either enforced via on-prem in a Hybrid Identity scenario, or by Entra itself if accounts are cloud only.
The only useful setting within that policy was "Maximum minutes of inactivity before password is required", which was enforced via MaxInactivityTimeDeviceLock. Rather than moving this setting elsewhere and still being subject to EAS (or potentially causing conflicts), this has been replaced by "Interactive Logon Machine Inactivity Limit" in the Power and Device Lock policy.
Settings Catalog
🆕 Win - OIB - SC - Microsoft Edge - U - Management - v4.0
The Edge Management Service (https://admin.cloud.microsoft/#/Edge) is an excellent addition to any Enterprise environment, providing centralized control and management of Microsoft Edge settings across all user devices (not just ones that are fully-managed).
From the incredible Version Monitoring Dashboard and more recent Extensions Monitoring functionality, it allows a bunch of features that are difficult or impossible to achieve natively in Intune (e.g. allowing users to request Extensions for approval).
After playing with it in my environments for some time, the biggest pain-point has been the behaviour of policy application. By default, user policies from the cloud-based management service will not override GPO/MDM delivered policies, which can lead to frustrating results or conflicts. To counteract that, this new policy not only explicitly allows the usage of the Edge Management Service on managed devices, but configures the default user/platform policy application to listen to cloud policies first.
EnabledEnabledEnabledEnabledNote
This does not force you to have to use the Edge Management Service, purely allows "co-management" across Intune and the EMS to be far more frictionless. It's worth noting that if you can't access the admin portal, you'll need the "Edge Administrator" role in Entra.
I would highly recommend enabling both the Version and Extension monitoring features regardless of plans to do anything else. It's literally free reporting.
Changed/Updated 🔄️
Settings Catalog
🔄️Win - OIB - ES - Windows LAPS - D - LAPS Configuration
🔄️Win - OIB - SC - Device Security - D - Local Security Policies
The above policies have not changed at all in content from their "(24H2+)" versions, but have been renamed to reflect currently supported Windows versions with 23H2 end of support on Nov 26th 2026. Policy naming has been bumped to 4.0, and they have superseded the previous versions in the policy manifest.
🔄️Win - OIB - SC - Defender Antivirus - D - Additional Configuration
Enabled. This stops some unwanted and potentially confusing behavior where users could create exploit protection settings but not remove them again due to any actual changes requiring admin rights. Resolves #247🔄️Win - OIB - SC - Device Security - D - Audit and Event Logging
Success + FailuretoSuccessto match CIS Benchmark.🔄️Win - OIB - SC - Device Security - U - Power and Device Lock
900(15 minutes) to replace the previous Password compliance policy's "Maximum minutes of inactivity before password is required" setting.Note
The "15 Minute" inactivity time is driven by the UK NCSC/Cyber Essentials requirements. By all means amend these to suit your business or compliance requirements.
1800rather than900to avoid a device going to sleep at the same time as being automatically locked.🔄️Win - OIB - SC - Device Security - D - Security Hardening
Disabledto match current CIS and MS baselines.SMB 3.1.1SMB 3.1.1🔄️Win - OIB - SC - Device Security - D - Script File Associations
.ps1mrather than.psm1. Resolves #243🔄️Win - OIB - SC - Internet Explorer (Legacy) - D - Security
DisabledtoEnabledto enhance security against potentially harmful downloads.Only TLS 1.2toUse TLS 1.2 and TLS 1.3to enhance security while maintaining compatibility with modern protocols. This setting had previously been broken when being applied via CSP but now works as expected. This also aligns with the MS 26H2 Security Baseline.🔄️Win - OIB - SC - Microsoft Edge - D - Security
EnabledEnabledEnabledEnabledEnable code integrity guard enforcement in the browser processEnabledImportant
As always, test appropriately in your own environment. There have been some reports that Process Isolation and Code Integrity could cause some unwanted effect or impact to PWA's and printing respectively, however it is worth noting that these security features will become default-enabled in the future.
Balanced modesub-setting.🔄️Win - OIB - SC - Microsoft Edge - D - Updates
🔄️Win - OIB - SC - Microsoft Edge - U - Profiles, Sign-In and Sync
EnabledDisabled🔄️Win - OIB - SC - Microsoft Edge - U - User Experience
*.microsoft.com>[*.]microsoft.com*.cloud.microsoft>[*.]cloud.microsoft.comapps.microsoft.comms-windows-store://*as a defence in depth measure to block access to the Windows app store via protocol. Resolves #253javascript://*to potentially mitigate ClickFix attacks, documented in the Google Chrome DISA STIG. Resolves #250EnabledDo not download modelDisabledEnabledEnabledShow only the Work feed tab🔄️Win - OIB - SC - Microsoft Office - U - Security
EnabledEnabledEnabledEnabledEnabledEnabled-disable (don't allow activating OLE Active Content)🔄️Win - OIB - SC - Windows Apps - D - In-Box App Removal
Microsoft.PowerAutomateDesktop_8wekyb3d8bbweinto the freeform list to pass Graph validation checks.🔄️Win - OIB - SC - Windows User Experience - D - Feature Configuration
Blockto prevent users from sharing clipboard content across devices.Endpoint Security
🔄️Win - OIB - ES - Defender Antivirus - D - AV Configuration
Send safe samples automatically (Default)toSend all samples automaticallyto align with best practice.RemovetoQuarantinefollowing several customer interactions that highlighted the need for recoverable handling of potentially non-harmful files.🔄️Win - OIB - ES - Defender Antivirus - D - Security Experience
EnabledtoDisabledto hide some redundant/unhelpful user notifications following a suggestion from Nathan McNulty: https://x.com/NathanMcNulty/status/2087722656674308316Removed 🚮
Removed the "Win - OIB - Compliance - U - Password - v3.1" compliance policy for reasons documented above.
Removed the following <24H2 policies with Windows 23H2 being end of support:
This discussion was created from the release windows-v4.0.
All reactions