@dwizzzleMSFT
David Weston (DWIZZZLE)
4 months
Windows 11 in 2024 is major progress - just took a @Lenovo ThinkPad Z16 Gen 2 out of the box and installed latest build: ✅Standard USER DEFAULT!!! (Adminless) ✅Signed-only apps (Smart App Control SAC) ✅Win32 App Isolation (AppSilo) ✅Pluton default, DRTM firmware…
Tweet media one
16
34
184

Replies

@AathifMahir
Aathif Mahir
4 months
@dwizzzleMSFT @Lenovo That's awesome, can we expect adminless user to be default standard for upcoming windows 11 update on all devices?
1
0
2
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 months
@AathifMahir @Lenovo won't be the default in the first go, but optional in the first release.
1
0
3
@parityzero
Will Harris
4 months
@dwizzzleMSFT @Lenovo When I go to the Lenovo store the default is Windows 11 Home - $60 extra for Pro? Do all these security features work on the Home edition?
2
0
1
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 months
@parityzero @Lenovo I *think* all are in home except Drtm is in pro, cred guard is in ent
0
0
1
@Myriachan
Myria
4 months
@dwizzzleMSFT I worry that eventually computer owners won’t be able to run their own software with maximum privilege, turning Windows into Xbox.
1
3
24
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 months
@Myriachan you can turn any or all of this off if you want to.
2
1
17
@CyberCakeX
HotCakeX ✡︎ סגול
4 months
@dwizzzleMSFT @Lenovo But Adminless how?? latest build doesn't have it yet?
1
0
1
@dwizzzleMSFT
David Weston (DWIZZZLE)
4 months
@CyberCakeX @Lenovo an admin account is created under the hood a "runas" is done in the context of that session with an NGC auth (e.g. Hello) so basically fingerprint/face/pin runas admin
1
0
6
@NerdPyle
Ned Pyle
4 months
@dwizzzleMSFT @brandonleblanc @Lenovo Also in Win11 for 2024 SMB signing required by default SMB server brute force password protection on by default SMB guest fallback disabled by default in Pro SMB1 uninstalled in all editions SMB NTLM blocking available SMB encryption mandate available
9
18
92
@never_unsealed
noct
4 months
@dwizzzleMSFT @Lenovo That's exciting, I didn't expect to see these changes that early. Does the signing enforcement also count for DLLs? Is DRTM used for key sealing by default?
1
0
1
@mcohmi
Ohm-I (Oh My) @ RenderATL
4 months
@dwizzzleMSFT @Lenovo Smart App Control out of the box on a non-enterprise laptop? That's kinda wild, even if you can turn it off in options, especially with all the certificate signing discourse.
0
0
2
@Koto_Sumire
S u m i ~
4 months
@dwizzzleMSFT @Lenovo Is it seriously about the standard user account by default? I hope this helps resolve the compatibility issues when using that kind of account, Windows UAC has always had those issues since it was introduced in Vista.
0
0
0
@danonit
Daniel Schell
4 months
@dwizzzleMSFT @Lenovo SAC shipped in enforcement mode?
0
0
1
@rstat1
Ryan S
4 months
@dwizzzleMSFT @Lenovo so will this Smart App Control thing flag harmless files that are very much not malicious as "malicious" like SmartScreen does today?
1
0
0
@snowwsquire
Snoww
4 months
Tweet media one
0
0
0
@m1ru1
@m1ru1
4 months
1
0
1
@_ForrestOrr
Forrest Orr
4 months
@dwizzzleMSFT @Lenovo Microsoft’s terminology is somewhat confusing here as per usual: these “app” features AppSilo, SmartApp etc. do they apply to any EXE launched by the user? Or only to literal apps aka UWP apps from the App Store?
0
0
0
@0xThatName
ThatName
4 months
@dwizzzleMSFT @never_unsealed @Lenovo People now will not worry much about being hacked by someone. The dangers is from signed and “legitimate” apps and cloud services that will exfiltrate your data after you agree on their long terms and conditions.
0
0
0
@a_arknu
Asbjørn
4 months
@dwizzzleMSFT @Lenovo How do you install anything not in the Store, then? And no, installing per user doesn't count, programs belong in Program Files, not in some random folder in my user profile!
0
0
0