Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / Windows 11 Enterprise Baseline Security Profiles Go Mandatory
Transcript
- Lucas: Microsoft has been shipping Security Baseline recommendations for Windows since Windows 10 version 1809, but they were always just that—recommendations. You could import them into Group Policy, tweak them, ignore them, whatever your environment needed. Luna: Right, they were like the dietary guidelines for IT. Follow them if you want, but no one's checking your fridge. Lucas: Exactly. But with the 2026 H1 feature update for Windows 11 Enterprise, that changes. Microsoft is turning those baselines into enforced defaults for any device enrolled in Intune or Windows Update for Business. Luna: Enforced defaults meaning… you can't opt out? Lucas: You can opt out, but the process is no longer a checkbox in a GPO. Under the new model, devices that fall below the baseline get a compliance warning in the Windows Security Center for 30 days. After that, if nothing's changed, the system autonomously remediates—turns on Credential Guard, enables BitLocker with TPM plus PIN, applies the default Windows Defender Application Control policy. Luna: So the IT admin gets a month to say 'no thanks,' and if they miss the window, the OS just locks things down automatically. Lucas: That's the headline. Microsoft calls it 'trust but verify with a deadline.' The stated reason is that too many enterprises are still running with security features disabled because of inertia or legacy compatibility fears. They want to raise the floor. Luna: And I get that—the number of breaches that happen because Credential Guard was never turned on is not zero. But what about the labs that need to disable BitLocker for performance benchmarking? Or the HPC clusters that run with WDAC off because they use unsigned scientific compute kernels? Lucas: Those are exactly the pain points. Microsoft has introduced what they call Role-Based Access Control overrides—basically, a finance-designated or legal-designated person can approve an exemption for a specific device or device group without giving that person full global admin rights. The exemption is logged in the audit trail and expires after 90 days. Luna: Ninety-day exemption with a renewal process. That's better than a permanent carve-out, but it's still paperwork. For a research lab with 200 workstations that each need custom security posture, that's a lot of exemption requests. Lucas: And Microsoft knows it. They've also added a compliance grace period toggle—a ten-day window that an IT admin can extend once per device via a new Defender for Cloud Apps connector. But it's a one-time extension. After that, you're back to the 30-day enforcement clock. Luna: So the exit hatch exists, but it's not trivial to use. That seems intentional. Lucas: Completely intentional. The message is: if you need to deviate from the baseline, you need to have a documented business reason and a plan to eventually come back into compliance. This is a departure from the legacy Group Policy era where the baseline was a starting point you could permanently diverge from. Luna: Let's talk about what specific settings are being enforced. You mentioned Credential Guard, BitLocker, WDAC. Are there others? Lucas: The enforcement list includes about 35 settings. Key ones: Credential Guard with UEFI lock, BitLocker with TPM plus startup PIN, WDAC with the default base policy, Local Administrator Password Solution or LAPS being required for all local admin accounts, and Windows Defender Firewall with default inbound block. Luna: That's a lot of things that, in many enterprises, are still configured manually or via third-party tools. The LAPS requirement alone is going to force a lot of IT teams to either deploy Microsoft's LAPS tool or find a compatible alternative. Lucas: And the WDAC default base policy is interesting because it's not the strictest WDAC policy—Microsoft has a 'deny by default, allow by signer' policy available. The default base is more like 'allow by default, block known bad.' But it still blocks PowerShell scripts that aren't signed by a trusted publisher, which is going to break a lot of internal automation. Luna: Yeah, every IT shop has those ten-year-old PowerShell scripts that run as scheduled tasks and have never been signed. They just work, because the execution policy is set to Bypass. Lucas: Under the enforced baseline, Bypass execution policy won't be enough—you'll need to either sign those scripts or add an WDAC file path rule to allow them from a specific folder. And file path rules are less secure, so Microsoft is discouraging them. Luna: So the path of least resistance is to get a code signing certificate and start signing scripts. That's a process, but it's doable. What about devices that aren't enrolled in Intune or WUfB? Are they affected? Lucas: Not directly. The enforcement only applies to devices managed by those services. If you're still using on-premises Group Policy with Configuration Manager, you're on your own schedule. But Microsoft has said that in 2027, they'll extend enforcement to devices that receive security updates via WSUS as well. Luna: So the timeline is: 2026 H1 for Intune and WUfB, 2027 for WSUS. That gives IT teams roughly eighteen months to get ready. Lucas: But eighteen months goes fast when you have thousands of devices. And the enforcement is tied to the feature update, so if you're still on 23H2 or 24H2, you won't see the automatic remediation until you upgrade. But you will start seeing compliance warnings in the Security Center even on older versions if they're connected to Intune. Luna: That's clever—they're nudging you before you even upgrade. The warnings appear, the admin sees them, and ideally starts planning. Lucas: One thing I want to highlight: the enforcement is not a hard block. If a setting fails to apply because of hardware limitations—say, a device without TPM 2.0—the compliance warning notes it but doesn't force remediation. The policy is adaptive. If the hardware can't support it, it won't break the device. Luna: That's important. So it's not a bricking mechanism. It's more like a nag that eventually becomes an autofix if the hardware supports it. Lucas: Exactly. And the autofix is reversible—if you have an approved exemption, you can roll back the remediation within the 30-day window. But once the 30 days pass and the fix applies, rolling back requires a fresh exemption request. Luna: Let's zoom out. How does this compare to what Apple and Google are doing? Apple has been doing 'blessed' configurations for years with their Device Enrollment Program, but they don't enforce security baselines at the OS level the same way. Lucas: Apple's approach is more 'here's the recommended configuration, and you can enforce it via MDM if you want.' Google, with ChromeOS, has a much more locked-down model out of the box—verified boot, mandatory encryption, sandboxing—but they don't have a baseline that IT can customize and then have the OS enforce automatically. Luna: So Microsoft is treading a middle path: give IT the flexibility to customize, but if they don't, the OS will eventually enforce a standard. It's like a default that becomes mandatory after a grace period. Lucas: It's a shift from 'configuration is optional' to 'configuration is optional, but non-compliance is temporary.' And that's a cultural change for a lot of IT departments. Luna: Speaking of cultural change—this also affects how IT teams think about testing. Before, you could test a new security setting on a pilot group and decide not to roll it out. Now, if you delay testing, the OS might just enable it anyway. Lucas: Right. So IT teams need to proactively test the baseline in a lab environment that mirrors their production setup, identify conflicts, and file exemptions before the feature update lands. That's a new operational rhythm. Luna: I wonder how many organizations are even aware of this change. The 2026 H1 update is already in Release Preview ring for Insiders. If you're not following Windows IT Pro blogs, you might not know until the warnings start appearing on users' desktops. Lucas: And that's where the conversation gets real. Because the first time a finance user sees a security warning saying 'Your device will be automatically secured in 27 days,' they're going to call the help desk. The help desk needs to have an answer. Luna: We should probably warn our listeners: if you're an IT admin for a midsize or large enterprise running Windows 11, now is the time to spin up a test device with the 2026 H1 update, enroll it in Intune, and see what happens. Lucas: Absolutely. And look, we do this show because we believe detailed, practical conversations help IT pros make better decisions. And a handful of our listeners help keep this show ad-free and independent by chipping in through buy me a coffee dot com slash fexingo. That support is what lets us spend time digging into specifics like this rather than chasing clickbait. Luna: Yeah, we don't have sponsors, we don't run ads, and we don't have a paywall. It's just listener support. If you get value from episodes like this one, consider joining the group that makes it possible. Lucas: Alright, back to the technical details. One more feature worth noting: the new compliance dashboard in the Intune admin center now shows a 'baseline deviation score' for each device. It's a percentage that tells you how many enforced settings are currently non-compliant. Luna: That's useful for tracking progress. You can see which devices are at 80 percent compliance and which are at 20 percent, and prioritize remediation. Lucas: And the dashboard also shows the top reasons for non-compliance across your fleet. In early previews, the most common reason was 'BitLocker not configured with PIN.' Second was 'Local admin password not managed by LAPS.' Luna: Those are both relatively easy to fix if you have the right tools in place. The hard ones are WDAC exclusions for legacy apps. Lucas: Right. And Microsoft has published a compatibility assessment tool that scans your installed software and generates a list of applications that would be blocked by the default WDAC policy. You can run it now, before the enforcement kicks in. Luna: That's a good proactive step. Run the tool, identify the blockers, decide whether to sign the apps, add file path exceptions, or replace them. Lucas: One more thing: the enforcement does not apply to Windows 11 Education or Pro editions. Only Enterprise. So if you're running Pro on a managed device, you're not affected—but Microsoft has hinted that Pro might get a similar treatment in 2027. Luna: So the pressure is on Enterprise first, then Pro later. That gives smaller businesses a bit more runway. Lucas: And for organizations that use third-party MDM like VMware Workspace ONE or Jamf, the enforcement only applies if the device is also enrolled in Intune. If you're purely third-party MDM, you won't see the automatic remediation, but you'll still get compliance warnings in the Security Center. Luna: So it's not mandatory unless you're using Microsoft's management stack. But the warnings are universal. Lucas: Exactly. And the warnings themselves are a form of pressure—users will ask IT, 'What's this warning?', and IT will have to respond. Luna: I think the bottom line is: the era of the security baseline as an optional starting point is ending. Microsoft is moving to a model where the baseline is the default, and deviation requires justification. Lucas: And that's probably a net positive for overall security posture across the enterprise, but it's going to cause short-term friction for IT teams that have grown accustomed to flexibility. The key is to start planning now. Luna: Agreed. And we'll keep an eye on how the rollout goes once the 2026 H1 update hits general availability later this year.