Microsoft is pleased to announce the security baseline package for Windows 11, version 26H2!
Update: The Windows 11, version 26H2 security baseline has been updated to reflect the general availability of Administrator protection. An updated v2 package is now available, and organizations should review and test the existing Administrator protection configuration as appropriate for their environment.
You can download the baseline package from the Microsoft Security Compliance Toolkit, test the recommended configurations in your environment, and customize / implement them as appropriate.
Summary of Changes
This release includes several changes since the Security baseline for Windows 11, version 25H2 to further strengthen enterprise security and align the baseline with current platform capabilities and industry standards.
|
Security Policy |
Change Summary |
|
Printer\Configure Windows Ready Print driver ranking |
Configured as “Enabled” to reduce reliance on third-party print drivers in the stack, narrowing the overall print driver attack surface. |
|
Internet Explorer\Internet Control Panel\Advanced Page\Turn off encryption support |
Updated from TLS 1.1 and TLS 1.2 to TLS 1.2 and TLS 1.3 to align with current security standards. |
|
User Account Control: Configure type of Admin Approval Mode (updated) |
Configured as “Admin Approval Mode with Administrator protection” to enable Administrator protection. |
|
User Account Control: Behavior of the elevation prompt for administrators running with Administrator protection (updated) |
Configured as “Prompt for credentials on the secure desktop” to require credential verification for administrative elevation. |
Windows Ready Print driver ranking
Configure Windows Ready Print driver ranking" is the newly added setting under Administrative Templates\Printers to control whether Windows prefers the modern inbox IPP class driver over third-party OEM drivers when installing new printers. We recommend enabling this policy to reduce reliance on third-party print drivers in the stack, narrowing the overall print driver attack surface. Note that driver ranking applies when printers are installed via a connection method that supports IPP, such as USB or network multicast discovery. In those cases, if the printer supports IPP, Windows will install using the class driver even if a vendor V3/V4 driver is available. If the printer doesn't support IPP, or is installed directly as a TCP/IP printer, there's no change in behavior.
Encryption Support
We have updated the policy "Turn off encryption support" to allow only TLS 1.2 and TLS 1.3. Previous baseline releases permitted TLS 1.1 and TLS 1.2; however, TLS 1.1 is now considered obsolete and is no longer recommended for enterprise environments. This change aligns the security baseline with modern cryptographic standards while maintaining compatibility with widely deployed services that support current TLS versions.
Administrator Protection (update)
Administrator protection is now generally available. Organizations can enable it through Microsoft Intune or Group Policy.
Important: Organizations should review and test their existing configuration and adjust these settings as appropriate for their environment. The security baselines for Windows 11, versions 24H2, 25H2, and 26H2 include settings that enable Administrator protection.
The following policies are part of the security baseline:
- User Account Control: Configure type of Admin Approval Mode
- User Account Control: Behavior of the elevation prompt for administrators running with Administrator protection
An updated v2 package has been published for Windows 11, version 26H2, to reflect this change.
Please let us know your thoughts by commenting on this post or through the Security Baseline Community.