5 Windows Security Settings You Should Never Skip Over

August 30, 2026

Microsoft has announced that it boasts the world’s “most widely used operating system,” with over 1.4 billion active devices each month. This impressive market share, however, makes it a prime target for malicious actors seeking to exploit security vulnerabilities. In response, Microsoft has integrated a variety of protective measures to help users safeguard their devices.

With a bit of knowledge, Windows users can enhance their security without the need for third-party software. The operating system offers a plethora of secure authentication methods, a built-in firewall, antivirus protection, and even options for drive encryption and device location tracking in case of loss or theft. For those who may not be familiar with these features, especially as official support for Windows 10 has concluded, focusing on Windows 11 is crucial.

Enable Windows Hello

For a seamless and secure login experience, enabling Windows Hello is essential. This feature allows users to bypass traditional passwords, opting instead for a PIN or biometric authentication methods such as facial or fingerprint recognition. These alternatives are not only more convenient but also more secure, as they cannot be easily forgotten or guessed. To activate Windows Hello, follow these steps:

  1. Navigate to Settings > Accounts > Sign-in options.
  2. Select either Facial recognition, Fingerprint recognition, or PIN.
  3. Click Set up and follow the on-screen instructions.
  4. In the Additional settings section, toggle on “For improved security, only allow Windows Hello sign-in for Microsoft accounts on this device.”

The advantage of using a PIN is that it can be reset through your Microsoft account if forgotten, providing an extra layer of convenience.

Enable Windows Firewall

For avid internet users, a firewall is an indispensable security tool. Not all internet traffic is benign; some can be malicious attempts to breach your device. A firewall acts as a barrier, identifying and blocking suspicious traffic. To enable the built-in Windows Firewall, follow these steps:

  1. Go to Settings > Privacy & security > Windows Security > Firewall & network protection.
  2. Select Public network.
  3. Toggle on Microsoft Defender Firewall.
  4. Return to the previous menu and repeat for Domain network and Private network.

Enable Microsoft Defender

While a firewall is crucial, it is not sufficient on its own. An antivirus solution is also necessary to protect against online threats. Microsoft Defender, which comes pre-installed with Windows, is a robust antivirus option. To ensure it is fully operational, enable the following features:

  1. Go to Settings > Privacy & security > Windows Security > Virus & threat protection.
  2. Under Virus & threat protection settings, click Manage settings.
  3. Toggle on Real-time protection.

Additionally, enable Controlled folder access to restrict changes to protected folders:

  1. Return to Virus & threat protection settings and click Manage ransomware protection.
  2. Toggle on Controlled folder access.
  3. Click Protected folders, then Add a protected folder to select folders you wish to safeguard.

Core isolation is another vital feature that runs potentially harmful code in a virtual environment before allowing it to execute on your system:

  1. Navigate to Settings > Privacy & security > Windows Security > Device security.
  2. Click Core isolation details and toggle on Memory integrity and Local Security Authority protection.

Use Windows with a Microsoft account

Linking a Microsoft account to your Windows setup opens the door to numerous benefits, including cross-device syncing and access to advanced security features. If you haven’t yet created a Microsoft account, visit the Microsoft website to do so. To link it to your Windows device, follow these steps:

  1. Go to Settings > Accounts > Your info.
  2. Click Sign in with a Microsoft account instead and follow the prompts to log in.

While Microsoft collects data about your usage, there are options to limit this data collection.

Microsoft account-dependent security features you need

Device Encryption, which requires a Microsoft account, is essential for protecting sensitive information stored on your device. This feature utilizes BitLocker encryption, ensuring that even if your device is stolen, your data remains inaccessible. To activate Device Encryption, navigate to Settings > Privacy & security > Device encryption and toggle it on if necessary.

Another valuable feature linked to your Microsoft account is the ability to locate your device if it goes missing. To enable Find My Device, follow these steps:

  1. Go to Settings > Privacy & security > Location.
  2. Toggle on Location services.
  3. Return to the previous menu and click Find my device.
  4. Toggle on Find my device.

In the unfortunate event that your device is stolen, you can locate or lock it by logging into your Microsoft account via a web browser, selecting Devices, and clicking Find my device to view its last known location.

Winsage
5 Windows Security Settings You Should Never Skip Over