Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Threat Intelligence

2/10/2017
01:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

Microsoft Beefs Up Enterprise Security In Windows 10, Surface

Microsoft's wave of security news targets hardware, Azure, Office 365, Windows 10, and SQL Server to safeguard business data.

Microsoft is making a series of announcements at next week's RSA Conference as part of its broader enterprise security strategy.

It has been more than a year since Microsoft announced plans to invest $1B in an integrated security strategy across products and services including Windows, Azure, and Office. Initiatives have driven progress in identity protection, data management, and staying ahead of attackers.

Now Microsoft is expanding on its security efforts with updates related to Windows 10, Surface hardware, Windows Defender Advanced Threat Protection (WDATP), Windows Hello, and Windows Analytics.

Surface is getting extra protection at the hardware layer with Surface Enterprise Management Mode (SEMM). This is geared towards heavily regulated industries that need physical protection; for example, the option to disable cameras or microphones in classified areas.

SEMM lets businesses control hardware configuration and OS processes within device firmware. Configuration can be applied to specific times of day, WiFi networks, Ethernet, Bluetooth, app access, and certificates that can be launched via initial deployments or pushed to cloud.

"In some of the most secure and locked-down environments, customers want to know how software is deployed and whether it's in policy," says Rob Lefferts, Microsoft's director of program management for Windows Enterprise and Security.

Admins must have physical possession of the device, and unique certificate signatures, to make any changes. This Surface security update can be deployed on Surface Pro 4, Surface Book, or Surface Studio.

Microsoft is also broadening device management in Windows 10 by bringing security configurations in Security Baseline Policies to MDM solutions. Previously, these settings were limited to Group Policy. It's also shipping the MDM Migration Analytics Tool to help report on Group Policy settings and configure policies for Windows 10 MDM managed devices.

WDATP, first announced at last year's RSA Conference, is getting a few adjustments. Users will be able to add customize detection rules and use "time travel" detections to look back through the previous six months of data and find undiscovered attacks.

Microsoft is also integrating security alerts from across the Windows security stack. Users can view malware reports, state of antivirus, and other advanced threats in one place.

In a one-year update following the $1B security investment, Microsoft CVP and CISO Bret Arsenault said one of his goals was to completely eliminate passwords within the next two years.

It's getting one step closer with new adjustments to Windows Hello, which is being expanded to all organizations with on-prem Active Directory-only environments. Previously, it was only available to devices with Windows 10.

"We want to make sure as many customers as possible can take advantage of new security features," says Lefferts of the news.

Windows Hello is also being updated with Dynamic Lock, which automatically locks down a device when the user walks away. Bluetooth signals determine the distance between the user's mobile phone and Windows 10 device, and can help block unauthorized device access.

Microsoft is working with Intel on an initiative called Project EVO, which will integrate Windows Hello with Intel's Authentice tech. The idea is to bring the hardware-based authentication of Intel's tool to protect Hello users from more advanced threats.

On the analytics front, Microsoft is broadening its Windows Analytics portfolio to include Update Compliance. The idea behind this is to give a broad view of Windows 10 update compliance for both monthly and feature updates. Businesses can use it to watch deployment progress, pinpoint problems, and maintain a broader view of their patched environment.

Update Compliance will be free; it's in public preview starting today.

Finally, Microsoft is announcing that the National Security Agency (NSA) is adding Surface devices (Pro 3, Pro 4, and Surface Book) to its list of Commercial Solutions for Classified Programs (CSfC).

"The cybersecurity landscape is in a situation of ever-increasing threats," says Lefferts. "As the world becomes more connected, the opportunities keep coming up for bad guys to do bag things, and profit from it."

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Former CISA Director Chris Krebs Discusses Risk Management & Threat Intel
Kelly Sheridan, Staff Editor, Dark Reading,  2/23/2021
Edge-DRsplash-10-edge-articles
Security + Fraud Protection: Your One-Two Punch Against Cyberattacks
Joshua Goldfarb, Director of Product Management at F5,  2/23/2021
News
Cybercrime Groups More Prolific, Focus on Healthcare in 2020
Robert Lemos, Contributing Writer,  2/22/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Building the SOC of the Future
Building the SOC of the Future
Digital transformation, cloud-focused attacks, and a worldwide pandemic. The past year has changed the way business works and the way security teams operate. There is no going back.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-20327
PUBLISHED: 2021-02-25
A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Node....
CVE-2021-20328
PUBLISHED: 2021-02-25
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in inte...
CVE-2020-27543
PUBLISHED: 2021-02-25
The restify-paginate package 0.0.5 for Node.js allows remote attackers to cause a Denial-of-Service by omitting the HTTP Host header. A Restify-based web service would crash with an uncaught exception.
CVE-2020-23534
PUBLISHED: 2021-02-25
A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.
CVE-2021-27330
PUBLISHED: 2021-02-25
Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.