In an effort to make distributed, hybrid workplaces safer, Microsoft plans to introduce a plethora of new enterprise security capabilities to Windows 11, along with hardware compatibility.
The Pluton Security Processor is one of them, and it is updated on a regular basis via Windows Update.
Microsoft said Pluton is regularly penetration tested, optimised for performance and reliability and offers protection against physical attacks through integration with central processing units (CPUs) in computer systems.
Pluton is based on Microsoft’s Zero Trust security paradigm, which includes enhanced authentication, reduced privileged access levels, and other security features such as assumed-breach and verified end-to-end encryption.
Microsoft will upgrade the security processor’s firmware automatically, without the need for enterprise administrator participation.
Smart App Control, which uses code signing and cloud-based artificial intelligence to prevent users from running harmful and untrusted applications, will be included in Windows 11.
Microsoft claims that increased phishing detection with the Defender SmartScreen will improve user account and credential security in Windows 11 for commercial clients.
Even if malware is running with Administrator capabilities, Enterprise editions of Windows 11 will include the Credential Guard feature, which protects against typical login detail theft tactics such as pass-the-hash and pass-the-ticket.
In Windows 11, Microsoft will also make sure that the Local Security Authority (LSA) process, which is one of several used to validate user identities, is better safeguarded, guaranteeing that only trusted, signed code is loaded.


