Windows 11 Security Book

Windows 11 Security Book

Built with Zero Trust principles at the core to safeguard data and access anywhere, keeping you protected and productive.

Introduction

The acceleration of digital transformation and the expansion of remote and hybrid workplaces bring new opportunities to organizations, communities, and individuals. As a result, our work styles have transformed. And now more than ever, employees need simple, intuitive user experiences to collaborate and stay productive wherever work happens. But the expansion of access and ability to work anywhere has also introduced new threats and risks. According to the latest data from the Microsoft commissioned Security Signals report, 75% of security decision-makers at the vice-president level and above feel that the move to hybrid work leaves their organization more vulnerable to security threats.

At Microsoft, we work hard to empower every person and every organization on the planet to achieve more. We’re committed to helping customers get secure—and stay confident. With over $1 billion invested in security each year, more than 3,500 dedicated security professionals, and some 1.3 billion Windows 10 devices used around the world, we have deep insight into the threats our customers face.

Our customers need modern security solutions that deliver end-to-end protection anywhere. Windows 11 is a build with Zero Trust principles for the new era of hybrid work. Zero Trust is a security model based on the premise that no user or device anywhere can have access until safety and integrity are proven. Windows 11 raises the security baselines with new requirements built into both hardware and software for advanced protection from chip to cloud. With Windows 11, our customers can enable hybrid productivity and new experiences without compromising security.

Approximately 80% of security decision makers say that software alone is not enough protection from emerging threats.1

In Windows 11, hardware and software work together for protection from the CPU to the cloud. See the layers of protection in this simple diagram and get a brief overview of our security priorities below.

How Windows 11 enables Zero Trust protection

The Zero Trust principles are threefold. First, verify explicitly. Always authenticate and authorize based on all available data points, including user identity, location, device health, service or workload, data classification, and anomalies. The second uses least privileged access, limiting user access with just-in-time and just-enough-access, risk-based adaptive policies, and data protection to help secure data and productivity. And lastly, assume breach. Assume breach operates in a manner that minimizes blast radius and segments access. Verify end-to-end encryption and use analytics to gain visibility to improve threat detection and defenses.

For Windows 11, the Zero Trust principle of verification explicitly applies to the risks introduced by both devices and users. In addition, windows 11 provides chip-to-cloud security, giving IT administrators the attestation and measurements to determine whether a device meets requirements and can be trusted. And Windows 11 works out of the box with Microsoft Intune and Azure Active Directory, so access decisions and enforcement are seamless. Plus, IT Administrators can easily customize Windows 11 to meet specific user and policy requirements for access, privacy, compliance, and more.

Individual users also benefit from robust safeguards, including new standards for hardware-based security and passwordless protection. Now, all users can replace potentially risky passwords by providing secure proof of identity with the Microsoft Authenticator app, signing in with a face or fingerprint,2 a security key or a verification code sent to a phone or email.

Overview of Windows 11 security priorities

Security, by default

Nearly 90% of security decision-makers surveyed say that outdated hardware leaves organizations more open to attacks, and that more modern hardware would help protect
against future threats. Building on the innovations of Windows 10, we’ve worked with our manufacturer and silicon partners to provide additional hardware security capabilities to meet the evolving threat landscape and enable more hybrid work and learning. The new set of hardware security requirements with Windows 11 is designed to build a foundation that is even stronger and more resilient to attacks.

Enhanced hardware and operating system security

With hardware-based isolation security that begins at the chip, Windows 11 stores sensitive data behind additional security barriers, separated from the operating system. As a result, information including encryption keys and user credentials are protected from unauthorized access and tampering. In Windows 11, hardware and software protect the operating system, with virtualization-based security (VBS) and Secure Boot built-in and enabled by default on new CPUs. Even if bad actors get in, they don’t get far. VBS uses hardware virtualization features to create and isolate a secure region of memory from the operating system. This
isolated environment hosts multiple security solutions, greatly increasing protection from vulnerabilities in the operating system and preventing the use of malicious exploits. With device health attestation with cloud services, Windows 11 is zero trust ready.

Robust application security and privacy controls

To help keep personal and business information protected and private, Windows 11 has multiple layers of application security to safeguard critical data and code integrity. Application isolation and controls, code integrity, privacy controls, and least-privilege principles enable developers to build-in security and privacy from the ground up. This integrated security protects against breaches and malware, helps keep data private, and gives IT administrators the necessary controls.

In Windows 11, Microsoft Defender Application Guard 3 uses Hyper-V virtualization technology to isolate untrusted websites and Microsoft Office files in containers, separate from and unable to access the host operating system and enterprise data. To protect privacy, Windows 11 also provides more controls over which apps and features can collect and use data such as device location or access resources like camera and microphone.

Secured identities

Passwords are inconvenient to use and prime targets for cybercriminals—and they’ve been an important part of digital security for years. That changes with the passwordless protection available with Windows 11. After a secure authorization process, credentials are protected behind layers of hardware and software security, giving users secure, passwordless access to their apps and cloud services.

Individual users can remove the password from their Microsoft account and use the Microsoft
Authenticator app,4 Windows Hello,5 a FIDO2 security key, a smart card, or a verification code sent to their phone or email. IT administrators and consumers can set up Windows 11
devices as passwordless out-of-the-box, taking advantage of technologies such as Windows Hello in alignment with Fast Identity Online (FIDO) standards. Windows 11 protects credentials with chip-level hardware security including TPM 2.0 combined with VBS and Microsoft Credential Guard.

Connecting to cloud services

Windows 11 security extends zero-trust all the way to the cloud, enabling policies, controls, procedures, and technologies that work together to protect your devices, data, applications, and identities from anywhere. Microsoft offers comprehensive cloud services for identity, storage, and access management in addition to the tools to attest that any Windows device connecting to your network is trustworthy. You can also enforce compliance and conditional access with a modern device management (MDM) service such as Microsoft Intune which works with Azure Active Directory to control access to applications and data through the cloud.6

Hardware Security

Modern threats require modern security with a strong alignment between hardware security and software security techniques to keep users, data and devices protected. The operating system alone cannot protect from the wide range of tools and techniques cybercriminals use to compromise a computer. Once inside, intruders can be difficult to detect while engaging in multiple nefarious activities from stealing important data or credentials to implanting malware into low-level device firmware that becomes difficult to identify and remove. These new threats call for computing hardware that is secure down to the very core, including hardware chips and processors which store sensitive business information. By building security capabilities in the hardware we can remove entire classes of vulnerabilities that
previously existed in software alone. This also often provides significant performance wins compared to implementing the same security capability in software, thereby increasing the system’s overall security without taking a measurable hit to system performance.

With Windows 11, Microsoft has raised the hardware security bar to design the most secure version of Windows ever. We have carefully chosen the hardware requirements and default security features based on threat intelligence and input from leading experts around the globe including the DoD, NSA, and UK’s NCSC, and our own Microsoft Security team. We have worked with our chip and device manufacturing partners to integrate advanced security capabilities across software, firmware, and hardware to create tight integration that protects from the chip to the cloud.

Through a powerful combination of hardware root-of-trust and silicon-assisted security, Windows 11 delivers built-in hardware protection out-of-the-box.

Hardware root-of-trust

A hardware root-of-trust helps protect and maintain the integrity of the system as the hardware turns on, loads firmware, and then launches the operating system. Hardware rootof-trust meets two important security goals for the system. It securely measures the firmware and operating system code that boots the system so that malware cannot infect boot code and hide its presence. Hardware root-of-trust also provides a highly-secure area isolated from the operating system and applications for storing cryptographic keys, data, and code. This protection safeguards critical resources such as the Windows authentication stack, single sign-on tokens, the Windows Hello biometric stack, and BitLocker volume encryption keys.

Trusted Platform Module (TPM)

A TPM is designed to provide hardware-based security-related functions and help prevent unwanted tampering. TPMs provide security and privacy benefits for system hardware, platform owners, and users. Windows Hello, BitLocker, Windows Defender System Guard, and numerous other Windows features rely on the TPM for key generation, secure storage, encryption, boot integrity measurements, attestation, and numerous other capabilities. These capabilities in turn help customers strengthen protection of their identities and data.

The 2.0 version of the TPM specification includes important enhancements such as the cryptographic algorithm flexibility that enables stronger crypto algorithms and the ability for customers to use preferred alternative algorithms. Starting with Windows 10, Microsoft’s hardware certification required all new Windows PCs to include TPM 2.0 built in and enabled by default. With Windows 11, both new and upgraded devices must have TPM 2.0. The requirement strengthens the security posture across all Windows 11 devices and helps ensure that these devices can benefit from future security capabilities that depend on a hardware root-of-trust.

Learn more about the Windows 11 TPM specifications and enabling TPM 2.0 on your PC.

Pluton security processor

Microsoft Pluton security processor, provides security at the chip. Pluton is a hardware root-of-trust designed by Microsoft in partnership with our silicon partners that is intended to provide the robustness and flexibility needed by modern PCs to address the evolving threat landscape. The Pluton design embeds the hardware root-of trust directly into the same silicon substrate as the CPU. This important design principle eliminates a common weakness when the root-of-trust is located in another discrete chip on the motherboard that is separate from the CPU. The weakness is that while the root-of-trust chip itself may be very secure there is a weak link in the communication path between the discrete root-of-trust and the CPU that can be exploited by physical attacks.

Pluton supports the TPM 2.0 industry standard allowing customers to immediately benefit from the enhanced security in Windows features that rely on TPMs including BitLocker, Windows Hello, and Windows Defender System Guard. In addition to being a TPM 2.0, Pluton also supports other security functionality beyond what is possible with the TPM 2.0 specification, and this extensibility allows for additional Pluton firmware and OS features to be delivered over time via Windows Update.

As with other TPMs, credentials, encryption keys, and other sensitive information cannot be extracted from Pluton even if an attacker has installed malware or has complete physical possession of the PC. Storing sensitive data like encryption keys securely within the Pluton processor, which is isolated from the rest of the system, helps ensure that emerging attack techniques such as speculative execution cannot access key material. Pluton also includes the unique Secure Hardware Cryptography Key (SHACK) technology. SHACK helps ensure that keys are never exposed outside the protected hardware, even to the Pluton firmware itself, providing an unprecedented level of security for Windows customers.

Pluton also solves the major security challenge of keeping system firmware up to date across the entire PC ecosystem. Today customers receive updates to their security firmware from a variety of different sources than can be difficult to manage, resulting in widespread update issues. Pluton provides a flexible, updateable platform for running firmware that implements end-to-end security functionality authored, maintained, and updated by Microsoft. Pluton is integrated with the Windows Update service benefitting from over a decade of operational experience reliably delivering updates across over a billion endpoint systems.

The Microsoft Pluton security processor will ship with select new Windows PCs starting in 2022. 7

Silicon assisted security

In addition to a modern hardware root-of-trust, there are numerous other capabilities in the latest CPUs that harden the operating system against threats such as by protecting the boot process, safeguarding the integrity of memory, isolating security sensitive compute logic, and more.

Secured kernel

Virtualization-based security (VBS), also known as core isolation, is a critical building block in a secure system. VBS uses the CPU’s hardware virtualization instructions to create a secure region of memory isolated from the normal operating system. Windows uses this isolated VBS environment to protect security sensitive operating system functions such as the secure kernel and security assets such as authenticated user credentials. Even if malware gains access to the main OS kernel, VBS greatly limits and contains exploits because the hypervisor and virtualization hardware help prevent the malware from executing code or accessing platform secrets running within the VBS secure environment.

Hypervisor-protected code integrity (HVCI), also called memory integrity, uses VBS to run Kernel Mode Code Integrity (KMCI) inside the secure VBS environment instead of the main Windows kernel. This helps prevent attacks that attempt to modify kernel mode code such as drivers. The KMCI role is to check that all kernel code is properly signed and hasn’t been tampered with before it is allowed to run.

HVCI ensures that only validated code can be executed in kernel-mode. The hypervisor leverages processor virtualization extensions to enforce memory protections that prevent kernel-mode software from executing code that has not been first validated by the code integrity subsystem. HVCI protects against common attacks like WannaCry that rely on the ability to inject malicious code into the kernel. HVCI can prevent injection of malicious kernel-mode code even when drivers and other kernel-mode software have bugs.

All Windows 11 devices will support HVCI and most new devices will come with VBS and HVCI protection turned on by default.

Windows 11 Secured-core PCs

The March 2021 Security Signals report shows that more than 80% of enterprises have experienced at least one firmware attack in the past two years. For customers in data sensitive industries like financial services, government, and healthcare, Microsoft has worked with OEM partners to offer a special category of devices called Secured-core PCs. The devices ship with additional security measures enabled at the firmware layer, or device core, that underpins Windows.

Secured-core PCs strengthen protection against advanced threats such as kernel attacks from ransomware. Secured-core PCs help prevent malware attacks and minimize firmware vulnerabilities by launching into a clean and trusted state at startup, with a hardware-enforced root of trust, stopping infections in their tracks. Virtualization-based security comes enabled by default. And with built-in hypervisor-protected code integrity that protects system memory, Secured-core PCs ensure that all operating system code is trustworthy, and executables are signed by known and approved authorities only.

Benefits of a Secured-core Windows 11 PC include:

  • Powerful security capabilities integrated across software, hardware, firmware,and identity protection
  • Deep integration between Microsoft, device manufacturers, and chip manufacturers to deliver powerful security capabilities that help prevent infections across software, firmware, and hardware
  • Security features across the stack are enabled by default by device manufacturers helping ensure customers are secure from the start

Memory protection in Secured-core PCs

PCIe hotplug devices such as Thunderbolt, USB4, and CFexpress allow users to attach new classes of external peripherals, including graphics cards or other PCI devices, to their PCs with an experience identical to USB. Because PCI hotplug ports are external and easily accessible, PCs are susceptible to drive-by Direct Memory Access (DMA) attacks. Memory access protection (also known as Kernel DMA Protection) protects PCs against drive-by DMA attacks that use PCIe hotplug devices by limiting these external peripherals from being able
to directly copy memory when the user has locked their PC.

Drive-by DMA attacks typically happen quickly while the system owner isn’t present. The attacks are performed with simple to moderate attacking tools created with affordable, off-the-shelf hardware and software that do not require the disassembly of the PC. For example, a PC owner might leave a device for a quick coffee break. Meanwhile, an attacker plugs in a USB-like device and walks away with all the secrets on the machine or injects malware that gives the attacker full remote control over the PC, including the ability to bypass the lock screen.

Note, Memory access protection does not protect against DMA attacks via older ports like 1394/FireWire, PCMCIA, CardBus, or ExpressCard.

Learn how to check if your PC supports Kernel DMA protection and about Kernel DMA protection requirements.

Firmware protection in Secured-core PCs

Secured-core PCs defend at the firmware level with multiple layers of protection enabled, helping ensure that devices launch safely in a hardware-controlled state.

Sophisticated malware attacks may commonly attempt to install “bootkits” or “rootkits” on the system to evade detection and achieve persistence. This malicious software may run at the firmware level prior to Windows being loaded, or during the Windows boot process itself, enabling the system to start with the highest level of privilege. Because critical subsystems in Windows leverage virtualization-based security, protecting the hypervisor becomes increasingly important. To ensure that no unauthorized firmware or software can start before the Windows bootloader, Windows PCs rely on the Unified Extensible Firmware Interface (UEFI) Secure Boot standard. The secure boot helps ensure that only authorized firmware and software with trusted digital signatures can execute. In addition, measurements of all boot components are securely stored in the TPM to help establish a non-repudiable audit log of the boot called the Static Root of Trust for Measurement (SRTM).

With thousands of PC vendors producing numerous PC models with diverse UEFI firmware components, there becomes an incredibly large number of SRTM signatures and measurements at bootup that are inherently trusted by secure boot, making it more challenging to constrain trust on any particular device to only what is needed to boot that device. Two techniques exist to constrain trust: either maintain a list of known “bad” SRTM measurements, also called a block list, which suffers from the drawback of being inherently brittle; or maintain a list of known “good” SRTM measurements, or an allow list, which is difficult to keep up-to-date at scale.

In Secured-core PCs, Windows Defender System Guard Secure Launch addresses these issues with a technology known as the Dynamic Root of Trust for Measurement (DRTM). DRTM lets the system follow the normal UEFI Secure Boot process initially, but before Windows is launched the system enters a hardware-controlled trusted state that forces the CPU(s) down hardware secured code path. If a malware rootkit/bootkit bypassed UEFI Secure Boot and had been resident in memory, DRTM will prevent it from accessing secrets and critical code protected by the virtualization-based security environment. System Management Mode (SMM) isolation complements the protections provided by DRTM by helping to reduce the attack surface from SMM, which is an execution mode in x86-based processors that runs at a higher effective privilege than the hypervisor. Relying on capabilities provided by silicon providers like Intel and AMD, SMM isolation enforces policies that enforce restrictions such as preventing SMM code from accessing OS memory. The SMM isolation policy in effect on a system can also be reliably provided to a remote attestation service.8

Robert Thorne
Author

Robert Thorne

Robert Thorne covers electric vehicle innovations, autonomous driving systems, global mobility trends, and automotive engineering developments.