De-Enshittify Windows 11: Make Windows 11 More Secure ⭐

Note: This is an early peek at a chapter from my new book, De-Enshittify Windows 11.  --Paul

--

In sharp contrast with its approach to privacy, Windows 11 security is in a good place, with no major enshittification issues. However, security is too big an issue to ignore, and Windows 11 ironically doesn't always provide the most secure possible default configure in the name of—wait for it—privacy. And so it's important to make sure that Windows 11 is as secure as possible.
✅ Tip: If you are buying a new PC, the most secure and reliable option is a Copilot+ PC using a Qualcomm Snapdragon X-series processor that runs Windows 11 on Arm. All Copilot+ PCs, including the less reliable x64 models with Intel- or AMD-based processors, offer dramatic security improvements over normal Windows 11 PCs. But Windows 11 on ARM with Snapdragon X is the best choice overall.
Fortunately, most people reading this will sign into Windows 11 using a Microsoft account. Doing so will configure your PC in a reasonably secure manner, though there are additional steps to consider. But some power users may prefer to sign in using a local account that is specific to that PC and is too easy to configure in a non-secure manner. So let's look at account security first.
⛔ The problems with not using a Microsoft account
When you first set up Windows 11 on a new or recently reset PC, you complete the Windows Setup Out of Box Experience (OOBE), during which you typically sign in with a Microsoft account. Doing so is nearly mandatory, but it comes with some pros and cons, the latter of which are tied to enshittification via online tracking, targeted advertising, upsells, and more. Those behaviors can be overcome, at least, and signing in with a Microsoft account comes with important security advantages that I feel outweigh the problems.

These advantages include:

Your Microsoft account can (and should) be secured with two-factor authentication (2FA), a form of passwordless authentication that is more secure than using just a password.
Windows 11 creates a device-bound passkey for your Microsoft account when you sign in that way, and this is used for passthrough authentication to in-box apps and experiences like OneDrive, the Microsoft Store, Microsoft Edge, and more.
Your Microsoft account can be recovered if it is compromised.
Your Microsoft account automatically backs up some Windows 11 configurations to the cloud so that they can be recovered and automatically reused when you sign into a different PC or reset this PC.
The disk on which Windows 11 is installed is automatically encrypted when you sign in with a Microsoft account, protecting your private data and other contents if the PC if ever lost or stolen. The recovery key for that encrypted disk is automatically stored in the OneDrive cloud storage associated with your Microsoft account.
Windows 11 will automatically configure OneDrive Folder Backup when you sign in with a Microsoft account to...

Gain unlimited access to Premium articles.

With technology shaping our everyday lives, how could we not dig deeper?

Thurrott Premium delivers an honest and thorough perspective about the technologies we use and rely on everyday. Discover deeper content as a Premium member.

Tagged with

Share post

Thurrott