
Of these 4,800 settings, only some are security-related. Security baselines are an essential benefit to customers because they bring together expert knowledge from Microsoft, partners, and customers.įor example, there are over 3,000 Group Policy settings for Windows 10, which does not include over 1,800 Internet Explorer 11 settings. These settings are based on feedback from Microsoft security engineering teams, product groups, partners, and customers. These devices must be compliant with the security standards (or security baselines) defined by the organization.Ī security baseline is a group of Microsoft-recommended configuration settings that explains their security impact. The one thing that all organizations have in common is a need to keep their apps and devices secure. For example, an e-commerce company may focus on protecting its Internet-facing web apps, while a hospital may focus on protecting confidential patient information. However, the types of security threats that are of most concern to one organization can be completely different from another organization.

What are security baselines?Įvery organization faces security threats. Here is a good blog about Sticking with Well-Known and Proven Solutions. This helps increase flexibility and reduce costs. We recommend that you implement an industry-standard configuration that is broadly known and well-tested, such as Microsoft security baselines, as opposed to creating a baseline yourself. Microsoft provides this guidance in the form of security baselines. To navigate the large number of controls, organizations need guidance on configuring various security features. In addition to the security assurance of its products, Microsoft also enables you to have fine control over your environments by providing various configuration capabilities.Įven though Windows and Windows Server are designed to be secure out-of-the-box, many organizations still want more granular control over their security configurations. Microsoft is dedicated to providing its customers with secure operating systems, such as Windows and Windows Server, and secure apps, such as Microsoft Edge.


In this article Using security baselines in your organization
