{"id":11692,"date":"2023-06-29T08:00:00","date_gmt":"2023-06-29T15:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?p=11692"},"modified":"2026-04-09T07:49:15","modified_gmt":"2026-04-09T14:49:15","slug":"hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/","title":{"rendered":"Hardware-backed Windows 11 empowers Microsoft with secure-by-default baseline"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image alignright\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"122\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/ms-digital-stories-300x122.png\" alt=\"Microsoft Digital stories\" class=\"wp-image-7436\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/ms-digital-stories-300x122.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/ms-digital-stories.png 400w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Windows 11 makes secure-by-default viable thanks to a combination of modern hardware and software. This ready out-of-the-box protection enables us to create a new baseline internally across Microsoft, one that level sets our enterprise to be more secure for a hybrid workplace.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWe\u2019ve made significant strides to create chip-to-cloud Zero Trust out of the box,\u201d says David Weston, vice president of Enterprise and OS Security at Microsoft. \u201cWindows 11 is redesigned for hybrid work and security with built-in hardware-based isolation, proven encryption, and our strongest protection against malware.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This new baseline for protection is one of several reasons Microsoft upgraded to Windows 11.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to a better user experience and improved productivity for hybrid work, the new hardware-backed security features create the foundation for new protections. This empowers us to not only protect our enterprise but also our customers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How Windows 11 advanced our security journey<\/h2>\n\n\n\n<figure class=\"wp-block-image alignright wp-image-11699 size-medium\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"226\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_image001-300x226.jpg\" alt=\"Weston smiles in a portrait photo.\" class=\"wp-image-11699\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_image001-300x226.jpg 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_image001.jpg 500w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><figcaption class=\"wp-element-caption\">Upgrading to Windows 11 gives you more out-of-the-box security options for protecting your company, says David Weston, vice president of Enterprise and OS Security at Microsoft.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Security has always been the top priority here at Microsoft.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We process an average of 65 trillion signals per day, with 2.5 billion of them being endpoint queries, including more than 1,200 password attacks blocked per second. We can analyze these threats to get better at guarding our perimeter, but we can also put new protections in place to reduce the risk posed by persistent attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In 2019, we announced <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2019\/10\/21\/microsoft-and-partners-design-new-device-security-requirements-to-protect-against-targeted-firmware-attacks\/\" target=\"_blank\" rel=\"noopener\">Secured-core PCs designed to utilize firmware protections for Windows users<\/a>. Enabled by Trusted Platform Module (TPM) 2.0 chips, Secured-core PCs protect encryption keys, user credentials, and other sensitive data behind a hardware barrier. This prevents bad actors and malware from accessing or altering user data and goes a long way in addressing the volume of security events we experience.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cOur data shows that these devices are more resilient to malware than PCs that don\u2019t meet the Secured-core specifications,\u201d Weston says. \u201cTPM 2.0 is a critical building block for protecting user identities and data. For many enterprises, including Microsoft, TPM facilitates Zero Trust security by measuring the health of a device using hardware that is resilient to tampering common with software-only solutions.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ve long used Zero Trust\u2014always verify explicitly, offer least-privilege access, and assume breach\u2014to keep our users and environment safe. Rather than behaving as though everything behind the corporate firewall is secure, Zero Trust reinforces a motto of \u201cnever trust, always verify.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The additional layer of protection offered by TPM 2.0 makes it easier for us to strengthen Zero Trust. That\u2019s why hardware plays a big part in Windows 11 security features. The hardware-backed features of Windows 11 create additional interference against malware, ransomware, and more sophisticated hardware-based attacks.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote quote-body is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">At a high level, Windows 11 enforced sets of functionalities that we needed anyway. It drove the environment to demonstrate that we were more secure by default. Now we can enforce security features in the Windows 11 pipeline to give users additional protections.<\/p>\n\n\n\n<p class=\"source wp-block-paragraph\">\u2014Carmichael Patton, principal program manager, Digital Security and Resilience<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Windows 11 is the alignment of hardware and software to elevate security capabilities. By enforcing a hardware requirement, we can now do more than ever to keep our users, products, and customers safe.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Setting a new baseline at Microsoft<\/h2>\n\n\n\n<figure class=\"wp-block-image alignright wp-image-11700 size-medium\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"200\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_image002-300x200.jpg\" alt=\"Patton smiles in a portrait photo.\" class=\"wp-image-11700\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_image002-300x200.jpg 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_image002.jpg 500w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><figcaption class=\"wp-element-caption\">Windows 11 reduces how many policies you need to set up for your security protections to kick in, says Carmichael Patton, a principal program manager with Microsoft Digital Security and Resilience.<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">While some security features were previously available via configuration, TPM 2.0 allows Windows 11 to protect users immediately, without IT admins or security professionals having to set specific policies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAt a high level, Windows 11 enforced sets of functionalities that we needed anyway,\u201d says Carmichael Patton, a principal program manager with Digital Security and Resilience, the organization responsible for protecting Microsoft and our products. \u201cIt drove the environment to demonstrate that we were more secure by default. Now we can enforce security features in the Windows 11 pipeline to give users additional protections.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thus, getting Windows 11 out to our users was a top priority.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Over the course of five weeks, we were able to deploy Windows 11 across 90 percent of eligible devices at Microsoft. Proving to be the least disruptive release to date, this effort assured our users would be immediately covered by baseline protections for a hybrid world.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We can now look across our enterprise and know that users running Windows 11 have a consistent level of protection in place.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The real impact of secure-by-default<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Moving from configurable to built-in protection means that Windows 11 becomes the foundation for secure systems as you move up the stack.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote quote-body is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">It simplifies everything for everyone, including IT admins who may not also be security experts. You can change configurations and optimize Windows 11 protections based on your needs or rely on default security settings. Secure-by-default extends the same flexibility to users, allowing them to safely choose their own applications while still maintaining tight security.<\/p>\n\n\n\n<p class=\"source wp-block-paragraph\">\u2014David Weston, vice president, Enterprise and OS Security<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Applications, identity, and the cloud are able to build off the hardware root-of-trust that Windows 11 derives from TPM 2.0. Application security measures like Smart App Control and passwordless sign-in from Windows Hello for Business are all enabled due to hardware-backed protections in the operating system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Secure-by-default does all of this without removing the important flexibility that has always been part of Windows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIt simplifies everything for everyone, including IT admins who may not also be security experts,\u201d Weston says. \u201cYou can change configurations and optimize Windows 11 protections based on your needs or rely on default security settings. Secure-by-default extends the same flexibility to users, allowing them to safely choose their own applications while still maintaining tight security.\u201d<\/p>\n\n\n\n<div data-bi-aN=\"Key Takeaways\" class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-fe9cc265 wp-block-group-is-layout-flex\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"124\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways.png\" alt=\"Key Takeaways\" class=\"wp-image-7448\" style=\"width:300px\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways.png 500w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways-300x74.png 300w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\">Going forward, IT admins working in Windows 11 no longer need to put extra effort in enabling and testing security features for performance compatibility. Windows 11 makes it easier for us to gain security value without extra work.<\/li>\n\n\n\n<li class=\"wp-block-list-item\">This is important when you consider productivity, one of the other drivers for Windows 11. We need to empower our users to stay productive wherever they are. These new security components go hand-in-hand with our productivity requirements. Our users stay safe without seeing any decline in quality, performance, or experience.<\/li>\n\n\n\n<li class=\"wp-block-list-item\">\u201cWith Windows 11, the focus is on productivity and thinking about security from the ground up,\u201d Patton says. \u201cWe know we can do these amazing things, especially with security being front and center.\u201d<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Now that Windows 11 is deployed across Microsoft, we can take advantage of TPM 2.0 to bring even greater protections to our users, customers, and products. We\u2019ve already seen this with the Windows 11 2022 update.<\/li>\n\n\n\n<li class=\"wp-block-list-item\">For example, Windows Defender App Control (WDAC) enables us to prevent scripting attacks while protecting users from running untrusted applications associated with malware. Other updates include improvements to IT policy and compliance through config lock: a feature that monitors and prevents configuration drift from occurring when users with local admin rights change settings.<\/li>\n\n\n\n<li class=\"wp-block-list-item\">These are the kinds of protections made possible with Windows 11.<\/li>\n\n\n\n<li class=\"wp-block-list-item\">\u201cFuture releases of Windows 11 will continue to add significant security updates that add even more protection from the chip to the cloud by combining modern hardware and software,\u201d Weston says. \u201cWindows 11 is a better way for everyone to collaborate, share, and present, all with the confidence of hardware-backed protections.\u201d<\/li>\n<\/ul>\n<\/div>\n\n\n\n<div data-bi-aN=\"Key Takeaways\" class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-fe9cc265 wp-block-group-is-layout-flex\">\n<figure class=\"wp-block-image size-medium is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"68\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/07\/OKR_Try_it_out-300x68.png\" alt=\"Try it out\" class=\"wp-image-11919\" style=\"width:360px\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/07\/OKR_Try_it_out-300x68.png 300w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/07\/OKR_Try_it_out-1024x234.png 1024w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/07\/OKR_Try_it_out-768x175.png 768w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/07\/OKR_Try_it_out.png 1319w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/en-us\/windows\/windows-11?OCID=InsideTrack_Product_10466\" target=\"_blank\" rel=\"noopener\">Learn about and upgrade to Windows 11.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2021\/06\/25\/windows-11-enables-security-by-design-from-the-chip-to-the-cloud\/?OCID=InsideTrack_Product_10466\" target=\"_blank\" rel=\"noopener\">Learn more about the security benefits of Windows 11.<\/a><\/li>\n<\/ul>\n<\/div>\n\n\n\n<div data-bi-aN=\"Key Takeaways\" class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-fe9cc265 wp-block-group-is-layout-flex\">\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"135\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links.png\" alt=\"Related links\" class=\"wp-image-7482\" style=\"width:300px\" srcset=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links.png 500w, https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links-300x81.png 300w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/zero-trust\" target=\"_blank\" rel=\"noopener\">Discover how Microsoft uses Zero Trust to protect our users.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2022\/09\/20\/new-windows-11-security-features-are-designed-for-hybrid-work\/\" target=\"_blank\" rel=\"noopener\">Learn how new security features for Windows 11 help protect hybrid work.<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2019\/10\/21\/microsoft-and-partners-design-new-device-security-requirements-to-protect-against-targeted-firmware-attacks\/\" target=\"_blank\" rel=\"noopener\">Get more information about how Secured-core devices protect against firmware attacks.<\/a><\/li>\n<\/ul>\n<\/div>\n\n\n\n<div data-bi-aN=\"Key Takeaways\" class=\"wp-block-group is-vertical is-layout-flex wp-container-core-group-is-layout-fe9cc265 wp-block-group-is-layout-flex\">\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/05\/Customer-Survey-580x85-1.png\" alt=\"We'd like to hear from you!\" style=\"width:580px\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list is-style-list-no-bullets\">\n<li class=\"wp-block-list-item\"><a href=\"mailto:msitstaff@microsoft.com\">Want more information? Email us and include a link to this story and we\u2019ll get back to you.<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Windows 11 makes secure-by-default viable thanks to a combination of modern hardware and software. This ready out-of-the-box protection enables us to create a new baseline internally across Microsoft, one that level sets our enterprise to be more secure for a hybrid workplace. \u201cWe\u2019ve made significant strides to create chip-to-cloud Zero Trust out of the box,\u201d [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":11694,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_hide_featured_on_single":false,"_show_featured_caption_on_single":true,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[850,848,300],"coauthors":[138],"class_list":["post-11692","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-end-user-services-and-support","tag-security-and-risk-management","tag-windows","program-ms-digital-stories","m-blog-post"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How Windows 11 Makes Microsoft Secure-by-Default - Inside Track Blog<\/title>\n<meta name=\"description\" content=\"Learn how Windows 11 gives us a new security baseline that is enabling us to better protect the company.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How Windows 11 Makes Microsoft Secure-by-Default - Inside Track Blog\" \/>\n<meta property=\"og:description\" content=\"Learn how Windows 11 gives us a new security baseline that is enabling us to better protect the company.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/\" \/>\n<meta property=\"og:site_name\" content=\"Inside Track Blog\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-29T15:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-09T14:49:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_wordpress_hero.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2300\" \/>\n\t<meta property=\"og:image:height\" content=\"1293\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Lukas Velush\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/luvelush\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lukas Velush\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/\"},\"author\":{\"name\":\"Lukas Velush\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/9a0f1c52bf68827638ed385b108d2e35\"},\"headline\":\"Hardware-backed Windows 11 empowers Microsoft with secure-by-default baseline\",\"datePublished\":\"2023-06-29T15:00:00+00:00\",\"dateModified\":\"2026-04-09T14:49:15+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/\"},\"wordCount\":1264,\"image\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2023\\\/06\\\/10466_wordpress_hero.jpg\",\"keywords\":[\"End user services and support\",\"Security and risk management\",\"Windows\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/\",\"name\":\"How Windows 11 Makes Microsoft Secure-by-Default - Inside Track Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2023\\\/06\\\/10466_wordpress_hero.jpg\",\"datePublished\":\"2023-06-29T15:00:00+00:00\",\"dateModified\":\"2026-04-09T14:49:15+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/9a0f1c52bf68827638ed385b108d2e35\"},\"description\":\"Learn how Windows 11 gives us a new security baseline that is enabling us to better protect the company.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2023\\\/06\\\/10466_wordpress_hero.jpg\",\"contentUrl\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2023\\\/06\\\/10466_wordpress_hero.jpg\",\"width\":2300,\"height\":1293,\"caption\":\"Windows 11 gives us a secure-by-default baseline that is enabling us to better protect the company.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hardware-backed Windows 11 empowers Microsoft with secure-by-default baseline\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/\",\"name\":\"Inside Track Blog\",\"description\":\"How Microsoft does IT\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/9a0f1c52bf68827638ed385b108d2e35\",\"name\":\"Lukas Velush\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/084d8da5c208fc0fff3f36c46e508e9a706b1d8a928ad139b5a720a54cd5b263?s=96&d=mm&r=g3598919c570ecead29b9b22837aad0ca\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/084d8da5c208fc0fff3f36c46e508e9a706b1d8a928ad139b5a720a54cd5b263?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/084d8da5c208fc0fff3f36c46e508e9a706b1d8a928ad139b5a720a54cd5b263?s=96&d=mm&r=g\",\"caption\":\"Lukas Velush\"},\"description\":\"Lukas Velush tells the story of how Microsoft uses its own technology on this blog and on the Microsoft Digital Inside Track website (link near the top left of your screen). He's a recovering journalist who needs to not take himself too seriously.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/lukas-velush-5573762\\\/\",\"https:\\\/\\\/x.com\\\/https:\\\/\\\/twitter.com\\\/luvelush\"],\"url\":\"https:\\\/\\\/www.microsoft.com\\\/insidetrack\\\/blog\\\/author\\\/lukas-velush\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How Windows 11 Makes Microsoft Secure-by-Default - Inside Track Blog","description":"Learn how Windows 11 gives us a new security baseline that is enabling us to better protect the company.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/","og_locale":"en_US","og_type":"article","og_title":"How Windows 11 Makes Microsoft Secure-by-Default - Inside Track Blog","og_description":"Learn how Windows 11 gives us a new security baseline that is enabling us to better protect the company.","og_url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/","og_site_name":"Inside Track Blog","article_published_time":"2023-06-29T15:00:00+00:00","article_modified_time":"2026-04-09T14:49:15+00:00","og_image":[{"width":2300,"height":1293,"url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_wordpress_hero.jpg","type":"image\/jpeg"}],"author":"Lukas Velush","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/twitter.com\/luvelush","twitter_misc":{"Written by":"Lukas Velush","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/#article","isPartOf":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/"},"author":{"name":"Lukas Velush","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/9a0f1c52bf68827638ed385b108d2e35"},"headline":"Hardware-backed Windows 11 empowers Microsoft with secure-by-default baseline","datePublished":"2023-06-29T15:00:00+00:00","dateModified":"2026-04-09T14:49:15+00:00","mainEntityOfPage":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/"},"wordCount":1264,"image":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_wordpress_hero.jpg","keywords":["End user services and support","Security and risk management","Windows"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/","name":"How Windows 11 Makes Microsoft Secure-by-Default - Inside Track Blog","isPartOf":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/#primaryimage"},"image":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/#primaryimage"},"thumbnailUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_wordpress_hero.jpg","datePublished":"2023-06-29T15:00:00+00:00","dateModified":"2026-04-09T14:49:15+00:00","author":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/9a0f1c52bf68827638ed385b108d2e35"},"description":"Learn how Windows 11 gives us a new security baseline that is enabling us to better protect the company.","breadcrumb":{"@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/#primaryimage","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_wordpress_hero.jpg","contentUrl":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_wordpress_hero.jpg","width":2300,"height":1293,"caption":"Windows 11 gives us a secure-by-default baseline that is enabling us to better protect the company."},{"@type":"BreadcrumbList","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/hardware-backed-windows-11-empowers-microsoft-with-secure-by-default-baseline\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.microsoft.com\/insidetrack\/blog\/"},{"@type":"ListItem","position":2,"name":"Hardware-backed Windows 11 empowers Microsoft with secure-by-default baseline"}]},{"@type":"WebSite","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#website","url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/","name":"Inside Track Blog","description":"How Microsoft does IT","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.microsoft.com\/insidetrack\/blog\/#\/schema\/person\/9a0f1c52bf68827638ed385b108d2e35","name":"Lukas Velush","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/084d8da5c208fc0fff3f36c46e508e9a706b1d8a928ad139b5a720a54cd5b263?s=96&d=mm&r=g3598919c570ecead29b9b22837aad0ca","url":"https:\/\/secure.gravatar.com\/avatar\/084d8da5c208fc0fff3f36c46e508e9a706b1d8a928ad139b5a720a54cd5b263?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/084d8da5c208fc0fff3f36c46e508e9a706b1d8a928ad139b5a720a54cd5b263?s=96&d=mm&r=g","caption":"Lukas Velush"},"description":"Lukas Velush tells the story of how Microsoft uses its own technology on this blog and on the Microsoft Digital Inside Track website (link near the top left of your screen). He's a recovering journalist who needs to not take himself too seriously.","sameAs":["https:\/\/www.linkedin.com\/in\/lukas-velush-5573762\/","https:\/\/x.com\/https:\/\/twitter.com\/luvelush"],"url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/author\/lukas-velush\/"}]}},"jetpack_featured_media_url":"https:\/\/www.microsoft.com\/insidetrack\/blog\/uploads\/prod\/2023\/06\/10466_wordpress_hero.jpg","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9hcZA-32A","_links":{"self":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/11692","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/comments?post=11692"}],"version-history":[{"count":11,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/11692\/revisions"}],"predecessor-version":[{"id":23078,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/11692\/revisions\/23078"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/media\/11694"}],"wp:attachment":[{"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/media?parent=11692"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/categories?post=11692"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/tags?post=11692"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.microsoft.com\/insidetrack\/blog\/wp-json\/wp\/v2\/coauthors?post=11692"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}