Microsoft Looks to Enable Practical Zero-Trust Security With Windows 11 – DARKReading

Npressfetimg 1882.png

Organizations aiming to boost their security with zero-trust initiatives got some help from Microsoft this week, when the computing giant announced that a slew of zero-trust features are now available in its Windows 11 operating system.

The zero-trust approach to security aims to secure workers’ access to sensitive systems, network, and data by using additional context, analysis, and security controls. The goal is to give “the right people the right access at the right time,” Microsoft stated in the Windows 11 Security Book, a 74-page report on Windows 11’s security architecture.

The model checks a user’s identity and location, as well as their device’s security status, and only allows access to the appropriate resources, according to the Windows 11 Security Book. In addition, zero-trust capabilities include continuous visibility and analysis to catch threats and improve defenses.

The latest version of the operating system and software platform adds a variety of features, from support for the Pluton security processor and trusted platform modules (TPMs) to comprehensive features around Trusted Boot, cryptography, and code-signing certificates, says David Weston, vice president of enterprise and OS security at Microsoft.

“Organizations worldwide are adopting a zero-trust security model based on the premise that no person or device anywhere can have access until safety and integrity is proven,” he says. “We know that our customers need modern security solutions with tightly integrated hardware and software that protects from entire classes of attack.”

The Zero-Trust Buzz Gets a Boost

The zero-trust concept has been knocking around for years, with technologists and government agencies first discussing it for security with the dawning realization that network perimeters were rapidly disappearing. Then, the work-from-home surge caused by the coronavirus pandemic injected more urgency into the movement. Now, three-quarters of security decision-makers (75%) believe that the increase in hybrid work creates vulnerabilities at their organization, leaving them more open to attacks.

“When employees are given the freedom to choose their work location, device, tools, and/or software, it becomes a challenge to establish trust based on static attributes,” says Ben Herzberg, chief scientist at Satori. “As the competitive pressure pushes companies to democratize data and release new customer value faster, employees will be provided more flexibility, and zero trust will be the go-to approach for enabling that flexibility while ensuring security.”

That said, implementing zero trust is a complex endeavor, as evidenced by the list of aspects that Microsoft has now built in:

Microsoft’s Windows 11 security architecture. Source: Microsoft’s Windows 11 Security Book.

The new Windows 11 features include Smart App Control, which uses machine learning, AI modeling, and Microsoft’s vast telemetry network of 43 trillion daily signals to determine if an application is safe. Other features also determine whether driver code and virtual-machine code have signs of maliciousness. Additional improvements include credential checks in Windows Defender, password-less support with Windows Hello for Business, and protection against credential-harvesting websites, the company stated.

Complexity has hampered zero-trust rollouts, but adding these feature directly into Windows 11 makes it more likely that companies can easily deploy zero-trust capabilities, says Microsoft’s Weston.

“Building in instead of bolting on makes deployment and management of zero-trust capabilities much simpler and efficient,” he says. “In addition, having these [features] directly integrated in the OS enables Windows to provide key measurements in hardware increasing the trust and validity of measurements.”

He adds, “The minute zero-trust capabilities are embedded into enterprise infrastructure, it becomes accessible for many companies that would otherwise have a hard …….

Source: https://www.darkreading.com/operations/microsoft-practical-zero-trust-security-windows-11

Leave a comment

Your email address will not be published. Required fields are marked *