Windows v3.7 - 25H2 Edition#135
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Windows v3.7 - 2025-10-15 - 25H2 Edition
Added 🆕
Settings Catalog
🆕Win - OIB - SC - Device Security - D - Administrator Protection - v3.7
Prompt for credentials on the secure desktopAdmin Approval Mode with Administrator protectionImportant
As of writing this, the feature is still flagged as Windows Insider only, but I'm hoping it will be enabled soon and I didn't want that to happen mid-way through a release cycle :)
🆕Win - OIB - SC - Device Security - D - Printing - v3.7
The following settings have been moved out of the Security Hardening profile into their own profile to make them easier to find and manage:
DisabledEnabledFalseTrueShow warning and elevation promptShow warning and elevation promptEnabledThe following settings have been added to match the Microsoft Security Baseline and CIS Intune Benchmark:
DisabledEnabledRedirection Guard EnabledRPC over TCPDefaultEnabledNegotiateRPC over TCPEnabled0🆕Win - OIB - SC - Windows User Experience - D - Settings Sync - v3.7
EnabledEnabledFalseEnabledNote
This feature needs enabling by navigating to: Devices > Windows > Enrollment > Windows Backup and Restore.
For more information, see Windows Backup and Restore - Microsoft Intune | Microsoft Learn
Endpoint Security
🆕Win - OIB - ES - Local Group Membership - D - Local Administrators - v3.7
AdministratorsReplaceManualWLapsAdminNote
Autopilot is not a security boundary, and blocking launching a command prompt from within OOBE can negatively impact the troubleshooting capabilities of IT Admins. This means that a savvy or malicious user can create an additional Admin account prior to running through Autopilot. To combat this, it's good practice to ensure that only accounts you explicitly want in the local Administrators group are present.
Changed/Updated 🔄️
Settings Catalog
🔄️Win - OIB - ES - Attack Surface Reduction - D - ASR Rules (L2)
AudittoBlockAudittoBlockAudittoBlock🔄️Win - OIB - ES - Encryption - D - BitLocker (OS Disk)
🔄️Win - OIB - SC - Device Security - D - Audit and Event Logging
Enabled🔄️Win - OIB - SC - Device Security - D - Security Hardening
EnabledNeverEnabledEnabledWin - OIB - SC - Device Security - D - Printing - v3.7profile:DisabledEnabledTrueShow warning and elevation promptShow warning and elevation promptEnabled🔄️Win - OIB - SC - Device Security - D - User Rights
S-1-5-99-216390572-1995538116-3857911515-2404958512-2623887229Note
This is the SID for the "RESTRICTED SERVICES\PrintSpoolerService" account. Huge thanks to @ajf8729 for managing to decipher this as Microsoft didn't want to document or localise it!
*S-1-5-32-546*S-1-5-32-546*S-1-5-32-544,*S-1-5-32-545*S-1-5-113,*S-1-5-32-546*S-1-5-113,*S-1-5-32-546*S-1-5-32-544, *S-1-5-90-0🔄️Win - OIB - SC - Device Security - U - Device Guard, Credential Guard and HVCI
Important
There are some implications if you need to disable these settings, however overall this change provides a better security posture.
🔄️Win - OIB - SC - Microsoft Edge - D - Security
🔄️Win - OIB - SC - Microsoft Edge - U - User Experience
Removed 🚮
🚮Win - OIB - SC - Windows Update for Business - D - Restart Warnings - v3.1
At some point, Microsoft seems to have changed the documentation for these policies to now state that they are only applicable to Windows 10, and not Windows 11 (example).
I have raised this with the Product Group to get clarification as this feels like a negative regression in functionality, but for now, I've removed the profile.
🚮Win - OIB - SC - Google Chrome - D - Security - v3.0 (Deprecated)
🚮Win - OIB - SC - Google Chrome - U - Experience and Extensions - v3.0 (Deprecated)
🚮Win - OIB - SC - Google Chrome - U - Profiles, Sign-In and Sync - v3.0 (Deprecated)
After deprecating them in v3.4, I've now removed the Google Chrome profiles from the repo completely.