
"The enhancement, called Windows Baseline Security Mode, will ensure that only properly signed applications, drivers, and services can run, thus preventing tampering and unauthorized changes. For those cases where exceptions are needed, users and administrators will have the option to override the safeguards. "Developers can also check whether these protections are active and whether any exceptions have been granted - giving them insight and control over the conditions under which their apps run," Microsoft notes."
"The tech giant announced the improvement simultaneously with revealing that Secure Boot certificates will begin to expire in June, and that refreshed certificates will be rolled out to supported Windows releases. Secure Boot protects devices from the moment they are powered on, preventing the execution of unsigned software before Windows starts. To provide additional visibility into Windows' security decisions, Microsoft introduced User Transparency and Consent, which will notify users whenever an application attempts to access sensitive resources or to install additional software."
Windows will enable runtime integrity safeguards by default with Windows Baseline Security Mode, allowing only properly signed applications, drivers, and services to run while permitting administrator overrides for exceptions. Developers can check whether these protections are active and whether exceptions exist, giving insight and control over app runtime conditions. Secure Boot certificates will begin to expire in June and refreshed certificates will be rolled out to supported Windows releases. Secure Boot prevents execution of unsigned software before Windows starts. User Transparency and Consent will notify users when applications access sensitive resources and will allow users to review and change prior choices. Apps and AI agents must meet higher transparency standards for greater visibility.
#windows-baseline-security-mode #secure-boot-certificates #user-transparency-and-consent #runtime-integrity
Read at SecurityWeek
Unable to calculate read time
Collection
[
|
...
]