Windows 10 Device Guard locks machines down for security and safety

Microsoft shared more details on a feature that will help business customers protect Windows 10 based devices. This feature, which they had apparently blogged about before but it did not have a name, is called Device Guard and allows organizations to lock those machines down to only run software from trusted sources.

Richard Hay, Senior Content Producer

April 22, 2015

2 Min Read
Windows 10 Device Guard locks machines down for security and safety

Yesterday, during the RSA Conference in California, Microsoft shared more details on a feature that will help business customers protect Windows 10 based devices.

This feature, which they had apparently blogged about before but it did not have a name, is called Device Guard and allows organizations to lock those machines down to only run software from trusted sources.

It provides better security against malware and zero days for Windows 10 by blocking anything other than trusted apps—which are apps that are signed by specific software vendors, the Windows Store, or even your own organization. You’re in control of what sources Device Guard considers trustworthy and it comes with tools that can make it easy to sign Universal or even Win32 apps that may not have been originally signed by the software vendor.

When an app is run on a system with Device Guard active it is compared against a list of trustworthy software for that device and a decision is made whether the software is valid for that organization.

Using special hardware and virtualization that decision process is independent of the Windows OS so that any attacker/malware which may have gained full privileges to the OS is unable to modify the list or execute unauthorized software.

In practice, Device Guard will frequently be used in combination with traditional AV and app control technologies. Traditional AV solutions and app control technologies will be able to depend on Device Guard to help block executable and script based malware while AV will continue to cover areas that Device Guard doesn’t such as JIT based apps (e.g.: Java) and macros within documents. App control technologies can be used to define which trustworthy apps should be allowed to run on a device. In this case IT uses app control as a means to govern productivity and compliance rather than malware prevention.

Microsoft has already partnered with several OEM’s who will support the use of Device Guard on upcoming hardware:

  • Acer

  • Fujitsu

  • HP

  • NCR

  • Lenovo

  • Par

  • Toshiba

The Redmond company believes using Device Guard in conjunction with Windows Hello and Microsoft Passport will reduce security related issues against many of the common attack vectors that are being used today and they feel Windows 10’s advanced security features are a big reason to make the move to the upcoming OS.

But, wait...there's probably more so be sure to follow me on Twitter and Google+.

About the Author

Richard Hay

Senior Content Producer, IT Pro Today (Informa Tech)

I served for 29 plus years in the U.S. Navy and retired as a Master Chief Petty Officer in November 2011. My work background in the Navy was telecommunications related so my hobby of computers fit well with what I did for the Navy. I consider myself a tech geek and enjoy most things in that arena.

My first website – AnotherWin95.com – came online in 1995. Back then I used GeoCities Web Hosting for it and WindowsObserver.com is the result of the work I have done on that site since 1995.

In January 2010 my community contributions were recognized by Microsoft when I received my first Most Valuable Professional (MVP) Award for the Windows Operating System. Since then I have been renewed as a Microsoft MVP each subsequent year since that initial award. I am also a member of the inaugural group of Windows Insider MVPs which began in 2016.

I previously hosted the Observed Tech PODCAST for 10 years and 317 episodes and now host a new podcast called Faith, Tech, and Space. 

I began contributing to Penton Technology websites in January 2015 and in April 2017 I was hired as the Senior Content Producer for Penton Technology which is now Informa Tech. In that role, I contribute to ITPro Today and cover operating systems, enterprise technology, and productivity.

https://twitter.com/winobs

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like