{"id":183,"date":"2019-10-01T16:30:32","date_gmt":"2019-10-01T15:30:32","guid":{"rendered":"https:\/\/increasec.com\/?p=183"},"modified":"2021-02-28T23:39:15","modified_gmt":"2021-03-01T04:39:15","slug":"standard-laptop-build","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=183","title":{"rendered":"Standard Laptop build"},"content":{"rendered":"\n<p>Recommand same build across Laptop &amp; Desktop <\/p>\n\n\n\n<p>Choose Hardware from Tier1 vendor (IBM,HP,Dell) these provide firmware updates for longer.  Favor hardware that include; TPM module, finger print scanner.<br>Bios        <br>     WakeOnLan   = on<br>     Wake @ 7am    a standard time for installing updates<br>     Power loss state = last   <br>     TPM = on     Trusted Platform Module<br>Windows 10 Enterprise; to avoid users unknowingly or purposefully installing malware, engage &#8220;<a href=\"https:\/\/www.howtogeek.com\/354057\/what-is-windows-10-in-s-mode\/\">S mode<\/a>&#8220;.  Which only allows installs from Windows store.  This can be enabled after installing company standard software.  Controlling this via Group Policy requires a Forest and Domain level of Windows2016+.  This trade off allows users to install programs that have passed the scrutiny of the Microsoft Store.  To manually test this,  Settings &gt; Apps &gt; Apps &amp; Features; under the Installing Apps heading, choose Allow Apps From The Store Only.  I will be testing how this feature works with  Group Policy Published Applications.  <a href=\"https:\/\/osddeployment.dk\/2017\/03\/11\/preventing-installation-of-apps-from-outside-the-store-in-windows-10-creators-update-configure-app-install-control\/\">Link<\/a><br>     encrypted HDD   <br>     Rename local administrator to AdminL, set 63 char password  <br>     Automatic Updates @ 7am <br>     System Restore ON   <br>     HVCI ON  https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-exploit-guard\/enable-virtualization-based-protection-of-code-integrity    <br>     Disable WPAD    https:\/\/increasec.com\/wp-admin\/post.php?post=82&amp;action=edit<br>     Wins\/Netbios\/MasterBrowser  Off.  Set 1-2 wired PC&#8217;s ON (per subnet) if no Domain present.<br>     Disable Powershell to Public    https:\/\/increasec.com\/wp-admin\/post.php?post=167&amp;action=edit<br> Firefox \/ Chrome browser        <br>     uBlock Origin plugin<br>     LastPass plugin<br> NonEmail Chat    Microsoft Teams\/Slack\/RocketChat\/Telegram\/Wire\/Signal\/Google Hangouts<br> Asset Mgt    Spiceworks? <br> VPN Client    Fortinet \/ ZeroTier \/ Tunnel Bear<br> Fingerprint reader    https:\/\/www.amazon.ca\/Fingerprint-PQI-Matching-Biometric-Security\/dp\/B06XG4MHFJ\/ref=sr_1_5?keywords=fingerprint+keyboard&amp;qid=1566494596&amp;s=gateway&amp;sr=8-5    <br> Remote access laptop    teamviewer, remotedesktop.google.com, splashtop  <br> Video Conference &amp; screen sharing; WebEx \/ Zoom \/ Join.me \/ BigBlueButton<\/p>\n\n\n\n<p>Disable IPv6; windows  prefers IPv6 over IPv4.  an intruder can use this to create a Preferred DC or DNS service.<\/p>\n\n\n\n<p>Windows Admin Center; convenient management<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recommand same build across Laptop &amp; Desktop Choose Hardware from Tier1 vendor (IBM,HP,Dell) these provide firmware updates for longer. Favor hardware that include; TPM module, finger print scanner.Bios WakeOnLan =&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3],"class_list":["post-183","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-smb"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/183","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=183"}],"version-history":[{"count":9,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/183\/revisions"}],"predecessor-version":[{"id":1249,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/183\/revisions\/1249"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=183"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=183"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=183"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}