Configuring a single app, full-screen kiosk with Microsoft Edge on Windows 11

This week is all about configuring a single app, full-screen kiosk with Microsoft Edge on Windows 11 devices. A kiosk is nothing new and the Microsoft Edge browser not either. And even the combination of both is nothing new. That being said, there are often unknowns in the configuration options and what actually happens with Microsoft Edge when configuring it as the kiosk application. And that often causes questions. So, this post should take some of those questions away. One of the things that’s often forgotten, for example, is that the Microsoft Edge browser will also run in kiosk mode. And that puts limitations on its capabilities. This post will focus on configuring a single app, full-screen kiosk with Microsoft Edge on Windows 11 devices, …

Read more

Working with in-browser protection in Microsoft Edge for Business

This week another blog post focused on the security capabilities within Microsoft Edge. With the introduction of Microsoft Edge for Business, there is a larger focus on providing a Microsoft Edge experience for work. That experience provides IT administrators with the ability to give their users a productive and secure browser for work, across managed and unmanaged devices. With that, Microsoft Edge can be the secure enterprise browser for many organizations. Especially with the focus of Microsoft Edge on security, privacy, and manageability. And not just that, it includes enhanced productivity alongside the security features. That brings us to the focus of this week and that is in-browser protection. In-browser protection is a great example of that combination as it reduces the need for proxies, …

Read more

Tightening browser security with Enhanced Security Mode in Microsoft Edge

This week is all about tightening security in Microsoft Edge and making sure that it’s one step closer to a secure enterprise browser. Especially nowadays when users spends most of their time in a web browser, it’s important to make sure that the right controls are in place to protect the users and the corporate data. That can be achieved by having a closer look at the different security features that Microsoft Edge brings to the table. And that are many different features. When specifically looking at protecting the user, think about features like Microsoft Defender SmartScreen, typosquatting protection, and Enhanced Security Mode. Three different security features, all with their own focus. Microsoft Defender SmartScreen to protect against phishing and malware, typosquatting protection to warn …

Read more

Managing Microsoft Edge browser extensions on Windows devices

This week is all about browser extensions. And more specifically, about Microsoft Edge browser extension on Windows devices. There are many reasons why organizations might want to look into managing and controlling Microsoft Edge browser extensions. Most of those reasons, however, are security related and focussed on staying in control of corporate data. Lately, there have been multiple examples of malicious browser extensions – not specific to the Microsoft Edge browser – that would collect user data and exfiltrate it to a malicious website. A good reason to get in control of the browser extensions that are being used within the organization. Either by fully controlling which browser extensions can be installed, or by at least blocking unwanted browser extensions. This post will look specifically …

Read more

Working with tamper protection on Windows devices to protect security settings

This week is all about working with tamper protection on Windows devices. Not because it’s something new, but mainly to give it some more attention. It does, by the way, introduce new management functionality. That new functionality is the ability to configure tamper protection on unmanaged devices. So, devices that are not managed by Microsoft Intune, or Configuration Manager, but that are managed via Microsoft Defender for Endpoint security settings management. Besides that, it’s just important to highlight the functionality of tamper protection again, to make sure that the functionality and usage is known. Especially as it’s nowadays enabled by default when using Microsoft Defender for Endpoint. Because it’s enabled by default, people easily forget that it’s configured and what it’s used for. This post will …

Read more

Quick tip: Blocking screen capture with app protection policies on iOS devices

This week a relatively short blog post. Not because it’s challenging to get up-and-running in this new year, but mainly to highlight a change in behavior on iOS devices. That change in behavior is all about app protection policies on iOS devices. For apps that have updated to v19.7.6 or later for Xcode 15 and v20.2.1 or later for Xcode 16 of the SDK, the default screen capture behavior will change. Before that update, blocking the screen capture was not option with app protection policies on iOS devices. That has now changed. Starting with that update, blocking screen capture is available in app protection policies and enabled by default when Send Org data to other apps is configured to anything other than “All apps“. This post will …

Read more

Getting started with Microsoft Connected Cache

This new year starts with an introduction to Microsoft Connected Cache and is sort of a follow-up on this post of about 4 years ago. That time it was about the addition of Connected Cache for Win32 apps in Configuration Manager. Now, 4 years later, Connected Cache is available as a standalone product and can be used to serve content for Windows feature and quality updates, Microsoft 365 Apps and updates, Intune apps, Store apps, and Windows Defender definition updates. Basically, Connected Cache is a software-only caching solution for delivering Microsoft content within the environment. It can be managed via the Azure portal and it can be deployed to Windows and Linux hosts. No matter if those hosts are physical or virtual. Connected Cache basically …

Read more

Getting started with Administrator protection

This week is all about the new functionality on Windows devices to help protect administrator users. That new functionality is Administrator protection. Administrator protection is aimed at protecting the users while still allowing them to perform their required elevated actions with just-in-time administrator privileges. That makes sure that when dealing with users that have local administrator privileges, instead of those users always having those high privileges, Administrator protection makes sure that those users must consent to actually activate those higher privileges. That makes sure that, by default, the user is now operating according to the least privilege concept and only gets those higher privileges when actually needed. In the end that lowers the attack vector for those users and makes sure that nothing happens without …

Read more

Adding additional hardware properties to the device inventory

This week is all about enhancing the device inventory for Windows devices. Device inventory is a new feature in Microsoft Intune that is specifically focused on enhancing the existing device inventory for Windows devices. That enables the IT administrator to add additional hardware properties to the existing inventory of Windows devices, by relying on the available properties in the Intune data platform. The additional hardware properties can help the organization to better understand the state of the Windows devices and to make potential business decisions based on that information. It really adds additional insights into Microsoft Intune that help with getting in more control and getting better overviews of the Windows devices within the environment. Basically, getting richer reporting information. This blog post will start …

Read more

Enabling hotpatch for Windows 11 Enterprise

This week is all about the latest changes in updating Windows 11 devices. That change is the introduction of hotpatch updates for Windows 11 Enterprise. Hotpatching helps organizations with keeping Windows secure, while minimizing the disruptions for the user. A significant step in keeping Windows more secure and productive. Hotpatching removes the requirement for Windows devices to reboot after every update installation, while still providing a complete set of security fixes. That’s exactly the point of importance for the user experience, as the device has less required reboots. This post will start with a brief introduction about Windows hotpatch, followed with the configuration steps. This post will end with experiencing the configuration. Note: The hotpatch technology is already being used for two years on Windows …

Read more