windows-v3.7 #136
SkipToTheEndpoint
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Windows v3.7 - 2025-10-15 - 25H2 Edition
Added 🆕
Settings Catalog
🆕Win - OIB - SC - Device Security - D - Administrator Protection - v3.7
Prompt for credentials on the secure desktopAdmin Approval Mode with Administrator protectionImportant
As of writing this, the feature is still flagged as Windows Insider only, but I'm hoping it will be enabled soon and I didn't want that to happen mid-way through a release cycle :)
🆕Win - OIB - SC - Device Security - D - Printing - v3.7
The following settings have been moved out of the Security Hardening profile into their own profile to make them easier to find and manage:
DisabledEnabledFalseTrueShow warning and elevation promptShow warning and elevation promptEnabledThe following settings have been added to match the Microsoft Security Baseline and CIS Intune Benchmark:
DisabledEnabledRedirection Guard EnabledRPC over TCPDefaultEnabledNegotiateRPC over TCPEnabled0🆕Win - OIB - SC - Windows User Experience - D - Settings Sync - v3.7
EnabledEnabledFalseEnabledNote
This feature needs enabling by navigating to: Devices > Windows > Enrollment > Windows Backup and Restore.
For more information, see Windows Backup and Restore - Microsoft Intune | Microsoft Learn
Endpoint Security
🆕Win - OIB - ES - Local Group Membership - D - Local Administrators - v3.7
AdministratorsReplaceManualWLapsAdminNote
Autopilot is not a security boundary, and blocking launching a command prompt from within OOBE can negatively impact the troubleshooting capabilities of IT Admins. This means that a savvy or malicious user can create an additional Admin account prior to running through Autopilot. To combat this, it's good practice to ensure that only accounts you explicitly want in the local Administrators group are present.
Changed/Updated 🔄️
Settings Catalog
🔄️Win - OIB - ES - Attack Surface Reduction - D - ASR Rules (L2)
AudittoBlockAudittoBlockAudittoBlock🔄️Win - OIB - ES - Encryption - D - BitLocker (OS Disk)
🔄️Win - OIB - SC - Device Security - D - Audit and Event Logging
Enabled🔄️Win - OIB - SC - Device Security - D - Security Hardening
EnabledNeverEnabledEnabledWin - OIB - SC - Device Security - D - Printing - v3.7profile:DisabledEnabledTrueShow warning and elevation promptShow warning and elevation promptEnabled🔄️Win - OIB - SC - Device Security - D - User Rights
S-1-5-99-216390572-1995538116-3857911515-2404958512-2623887229Note
This is the SID for the "RESTRICTED SERVICES\PrintSpoolerService" account. Huge thanks to @ajf8729 for managing to decipher this as Microsoft didn't want to document or localise it!
*S-1-5-32-546*S-1-5-32-546*S-1-5-32-544,*S-1-5-32-545*S-1-5-113,*S-1-5-32-546*S-1-5-113,*S-1-5-32-546*S-1-5-32-544, *S-1-5-90-0🔄️Win - OIB - SC - Device Security - U - Device Guard, Credential Guard and HVCI
Important
There are some implications if you need to disable these settings, however overall this change provides a better security posture.
🔄️Win - OIB - SC - Microsoft Edge - D - Security
🔄️Win - OIB - SC - Microsoft Edge - U - User Experience
Removed 🚮
🚮Win - OIB - SC - Windows Update for Business - D - Restart Warnings - v3.1
At some point, Microsoft seems to have changed the documentation for these policies to now state that they are only applicable to Windows 10, and not Windows 11 (example).
I have raised this with the Product Group to get clarification as this feels like a negative regression in functionality, but for now, I've removed the profile.
🚮Win - OIB - SC - Google Chrome - D - Security - v3.0 (Deprecated)
🚮Win - OIB - SC - Google Chrome - U - Experience and Extensions - v3.0 (Deprecated)
🚮Win - OIB - SC - Google Chrome - U - Profiles, Sign-In and Sync - v3.0 (Deprecated)
After deprecating them in v3.4, I've now removed the Google Chrome profiles from the repo completely.
This discussion was created from the release windows-v3.7.
Beta Was this translation helpful? Give feedback.
All reactions