Security Baseline for Windows 10 and 11 Clients

Objective

  • To enhance security measures on Win 10 and 11 client machines
  • To comply with University OnePass password policy
  • To mitigate the risk to an acceptable level in balancing the convenience and security
  • To serve as a guideline for departmental IT staff aligning security to a certain extent

Scope

  • Windows 10 and 11 (version 21H2 or above)

Methodology

  • By applying group policy on Win 10 and 11 AD-domain joined computers
    • Apply on Computer OU, not individual user OU
  • For those non AD-domain joined computers, the setting can be applied by script

Recommended Settings

Proposed CUHK Setting based on evaluation of the following sets:

  • CUHK Current Setting
  • University OnePass password policy
  • Default Value from Windows
  • Default Setting from Security Compliance Manager (SCM)
  • Recommendation from Microsoft consultants
  • User impacts

 

Settings involves:

Win 10/11 : 657 settings
  • 00 Password policy
  • 01 Advanced Audit Policy
  • 02 Security Options
  • 03 User Rights Assignment
  • 04 MSS
  • 05 Firewall
  • 06 Event Log
  • 07 AT – Computer
  • 08 BitLocker

 

Deliverables

 

 

Last Updated On:  Feb 2022