windows 8.1 securitydownload.microsoft.com/download/9/3/2/932cc5d7-9f9e-4264...builds on windows 7...

25
| Basel Windows 8.1 Security TechNet Event November 25 th , 2013 Martin Weber Technology Solution Professional Microsoft Switzerland Ltd.

Upload: others

Post on 03-May-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

| Basel

Windows 8.1 SecurityTechNet Event November 25th, 2013

Martin Weber

Technology Solution Professional

Microsoft Switzerland Ltd.

Page 3: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Windows 8 and 8.1 Security Capabilities

Securing the Sign-In

Secure Access to Resources

Securing Device with EncryptionSecuring the Boot

Securing the Code and Core

Securing the Desktop

First Class Biometric Experience

Multifactor Auth for BYOD

Trustworthy Identities and Devices

Virtual SmartCard

Provable PC Health

Improved Windows Defender

Improved Internet Explorer

Improved System Core Hardening

Pervasive Device Encryption

Selective Wipe of Corp Data

Page 4: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Refresh and Reset

Enhanced BitLocker Drive Encryption Protection

New Secure Boot Options

What’s New in Windows 8.1 Security

Page 5: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Tools for Windows 8.1 Recovery

Windows Tools & Techniques:

• System Restore

• Safe Mode and related

New Windows 8.1 Refresh and Reset capabilities

Page 6: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Windows 8.1 Refresh vs. Reset

Refresh: Reset:

Does not keep customizations and data

Keeps customizations and data

Keeps Windows 8.1 Apps

Does not format before reinstall Formats the drive before reinstall

Does not keep Windows 8.1 Apps

Page 7: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Groundbreaking Enterprise Security

Builds on Windows 7 Technologies

Enhanced BitLocker Protection

UEFI Support for Trusted Boot

Windows Defender andWindows Firewall

Page 8: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

BitLocker Enhancements in Windows 8.1

Encryption of Full Disk or just the data at rest (aka “used Disk Space”)

Encrypt during installation

Support for eDrives, iSCSI and

Fiber Channel Drives

Page 9: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

EFI System

Partition

(bootmgr.efi)

OS Partition

(Windows

Runtime,

User Data)

Data Partition

(User Data)WinRE

Partition

OEM

Partition

= Encrypted = Not Encrypted

Hard Disk

Recovery

Image

Partition

FVEKSRK

VMK

Page 10: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Trusted Platform Module 2.0 Support

Page 11: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

New BitLocker Recovery Options

SkyDrive Recovery Key escrow is new to Windows 8.1Several recovery options

Page 12: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Group Policy (GPO) and BitLocker

Numerous Group Policy settings

around the unlock method

Policies for enterprise scenarios

Page 13: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

BitLocker Protectors

Numerous protectors:• Password protector for non-TPM

• Active Directory

• Network

Page 14: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Network Unlock for OS Volumes Scenario:

Enables PCs connected to corporate network to boot without PIN

Simplifies patch process for servers and desktops, wake on LAN, ease of use for end users

Requirements:

UEFI 2.3.1 support for DHCPv4 and DHCPv6 Network

Key

ServerEFI DHCP

PROTOCOL

Key Request

Client Key

Secure Network

TPM

Page 15: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Windows RT Device Encryption

Available for Windows RT devices

Optimized for slate form factor

Page 16: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Complex

PINs and

FIPs

MBAM is

enterprise-level

tool for

BitLocker

Role-based

access

control

Compliance

reports

Microsoft BitLocker Administration and Monitoring: Compliance and security

Page 17: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

UEFI Support in Windows 8.1

The new UEFI BIOS (System on a Chip – SoC) helps ensure that the computer loads only trusted operating systems.

Page 18: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Legacy vs. Modern, Trusted UEFI Boot Process

Windows 7 BIOSOS Loader

(Malware)

3rd Party

Drivers

(Malware)

Anti-Malware

Software

Start

Windows

Logon

Windows 8Native

UEFI

Windows 8

OS Loader

Anti-Malware

Software

Start

3rd Party

Drivers

Windows

Logon

Malware is able to boot before Windows and Anti-Malware• Malware able to hide and remain undetected

• Systems can be compromised before Anti-Malware starts

Trusted Boot loads Anti-Malware early in the boot process• Early Load Anti-Malware (ELAM) driver is specially signed by Microsoft

• Windows starts Anti-Malware software before any 3rd party boot drivers

• Malware can no longer bypass AM inspection

Page 19: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Trusting the UEFI Boot Process

Updates to UEFI are secure

(Firmware, Drivers, OS Boot Loader have to be all

digitally signed)

UEFI does self-check

Page 20: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Secure, Trusted and Measured Boot

Trusted boot prevents unauthorized boot loaders

Measured boot provides measurements about the boot process

Page 21: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Protect against the Known and the Unknown

Malware resistant by design

Familiar tools updated for Windows 8.1

Page 22: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Windows 8.1 Client Protection

Page 23: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Windows 8.1 Modern App Protection

Strong screening process for Windows Store

Low privilege and capability declaration

Discrete app containers

Page 24: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows

Summary of Security Enhancements

Familiar tools still used in Windows 8.1

DaRT and MDOP have been updated for Windows 8.1

Trusted boot and post-boot protected

BitLocker includes numerous enhancements

Page 25: Windows 8.1 Securitydownload.microsoft.com/download/9/3/2/932CC5D7-9F9E-4264...Builds on Windows 7 Technologies Enhanced BitLocker Protection UEFI Support for Trusted Boot Windows