Skip to content

Miscellaneous Configurations | Harden System Security

Miscellaneous Configurations - Harden Windows Security


  • Blue Check mark denoting Group Policy Sets Early launch antimalware engine's status to 8 which is Good only. The default value is 3, which allows good, unknown and 'bad but critical'. that is the default value, because setting it to 8 can prevent your computer from booting if the driver it relies on is critical but at the same time unknown or bad. Rotating green checkmark denoting CSP CSP

    • By being launched first by the kernel, ELAM is ensured to be launched before any third-party software and is therefore able to detect malware in the boot process and prevent it from initializing. ELAM drivers must be specially signed by Microsoft to ensure they are started by the Windows kernel early in the boot process.


  • Blue Check mark denoting Group Policy Disables location services (Location, Windows Location Provider, Location Scripting) system wide. Websites and apps won't be able to use your precise location, however they will still be able to detect your location using your IP address. Rotating green checkmark denoting CSP CSP Rotating green checkmark denoting CSP CSP Rotating green checkmark denoting CSP CSP


  • Blue Check mark denoting Group Policy Enables svchost.exe mitigations. built-in system services hosted in svchost.exe processes will have stricter security policies enabled on them. These stricter security policies include a policy requiring all binaries loaded in these processes to be signed by Microsoft, and a policy disallowing dynamically generated code. Rotating green checkmark denoting CSP CSP


  • Rotating pink checkmark denoting registry or cmdlet Turns on Enhanced mode search for Windows indexer. The default is classic mode. Rotating green checkmark denoting CSP CSP
    • This causes some UI elements in the search settings in Windows settings to become unavailable for Standard user accounts to view, because it will be a managed feature by an Administrator.




  • Rotating pink checkmark denoting registry or cmdlet Enables Edge browser (stable/beta/dev channels) to download and install updates on any network, metered or not; because the updates are important and should not be suppressed.






  • Blue Check mark denoting Group Policy Enables a policy that requests claims and compound authentication for Dynamic Access Control and Kerberos armoring. Rotating green checkmark denoting CSP CSP



  • Rotating pink checkmark denoting registry or cmdlet Configures the SSH client's configurations to use the following secure MACs (Message Authentication Codes): MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com.




  • Blue Check mark denoting Group Policy Rotating green checkmark denoting Subcategory Reduced Telemetry. This sub-category applies all of the policies mentioned below. They do not have any effect on security.

  • Disable Online Tips. Rotating green checkmark denoting CSP CSP

  • Disable Find My Device feature. Rotating green checkmark denoting CSP CSP

  • Disable Automatic Update of Speech Data. Rotating green checkmark denoting CSP CSP

  • Turn off the advertising ID. Rotating green checkmark denoting CSP CSP

  • Turn off cloud optimized content. Rotating green checkmark denoting CSP CSP

  • Do not show Windows tips. Rotating green checkmark denoting CSP CSP

  • Do not show feedback notifications. Rotating green checkmark denoting CSP CSP

  • Turn off Automatic Download and Update of Map Data. Rotating green checkmark denoting CSP CSP

  • Disable Message Service Cloud Sync for cellular text messages. Rotating green checkmark denoting CSP CSP

  • Disable support for web-to-app linking with app URI handlers. Rotating green checkmark denoting CSP CSP

  • Disable "Continue experiences on this device" feature. Rotating green checkmark denoting CSP CSP

  • Disable Font Providers. Rotating green checkmark denoting CSP CSP

  • Don't search the web or display web results in Search. Rotating green checkmark denoting CSP CSP

  • Do not allow web search. More Info