Security

Windows 11 includes a full suite of security utilities and services, most of which work automatically with no intervention on your part. But there are a few configurations to consider in each that will lead to even better overall security.

Windows Update

Windows Update is a Microsoft-hosted online service that automatically keeps your PC up-to-date with security and bug fixes, OS version upgrades, driver updates, and Windows Defender antivirus updates, and more. In some ways, the rate at which these updates arrive has increased dramatically in recent years, but Microsoft has worked to reduce reboots and other interruptions this year while giving users more control over how and when to update the system.

In Windows 11, the interface you use to interact with Windows Update is found in the Settings app by navigating to Windows Update.

Defaults

Windows 11 connects to Windows Update automatically and will download and install pending updates as needed on different schedules.

Key updates delivered through Windows Update include:

  • Feature updates. This a version upgrade, usually delivered annually in the second half of the year, typically in October. Feature updates include new features and bug and security fixes, and they are cumulative, meaning that they include the contents of all previous feature updates and quality updates. You must reboot your PC to fully install a feature update.

Tip: Each supported version of Windows 11 typically includes the same features and security fixes. But feature updates can be major upgrades in which a new version of the OS is installed over the current version, or they can be minor upgrades with a smaller enablement package (eKB) installer that install more quickly than major upgrades. Windows 11 version 24H2 was a major upgrade, but Windows 11 version 25H2 is a minor upgrade, as will be 26H2.

  • Quality updates. This is a cumulative update with new features and bug and security fixes. Quality updates are typically delivered once each month, on the second Tuesday of the month, and though they can be smaller than feature updates, they also require a reboot to fully install.

Tip: Though this term is not official, the second Tuesday of each month has called Patch Tuesday since Microsoft first introduced this schedule in 2003.

  • .NET updates. Microsoft updates the legacy .NET Framework and related technologies integrated into Windows 11 along with more modern .NET releases via Windows Update. This typically occurs once each month, and they require a reboot. But these updates are timed to coincide with the monthly quality update so that both can be fully installed during the same reboot.
  • Driver updates. Though some PC makers still provide custom support applications that, among other things, install new driver updates, most driver updates install through Windows Update. Some of these updates–including firmware updates–require a reboot, but some do not. If a reboot is required, Windows 11 will typically schedule the install to coincide with the monthly quality update.
  • AI component updates. If you have a Copilot+ PC, Windows Update will download and install updates for Phi Silica and other on-device local AI models on a rolling basis. These updates do not require a reboot and there is no set schedule. But it’s typical to get at least one or two each month.
  • Microsoft Defender antivirus updates. Microsoft Defender protects your Windows 11 PC from viruses and other online threats, and Windows Update downloads security intelligence updates–previously called definition updates–multiple times each time to keep it up-to-date. These updates are small and do not require a reboot.
  • Preview updates. Microsoft also offers preview updates via Windows Update that are not downloaded and installed by default unless you enable the option “Get the latest updates as soon as they’re available.” There are preview feature updates and quality updates, and both typically arrive on the fourth Tuesday of each month, or two weeks after the most recent Patch Tuesday. Tied to that, these preview updates are, per the name, previews of the next feature update or Patch Tuesday quality update and offer the same features and security and bug updates.

By default, Windows 11 will:

  • Download and install feature updates, quality updates, .NET updates, and driver updates and then reboot the PC to complete installation outside your active hours. Unless you configure this setting otherwise, active hours is between 7:00 am and 12:00 am each day.
  • Download and install AI component updates and Microsoft Defender antivirus updates as needed in the background without disrupting your work.
  • Ignore the various updates if your PC is using a metered network that might incur additional costs from the downloads unless there is a serious security update, in which case it will download and install the update and reboot as necessary.

Customize

You customize how Windows Update interacts with your PC in Windows Update settings in the Settings app. Key features to consider here include:

  • Get the latest updates as soon as they’re available. Disabled by default, this option will download and install preview updates like other updates when enabled and increase the typical number of reboots each month from one to two.
  • Pause updates. This option lets you pause updates for up to 35 days by selecting the end date for pausing on a pop-up calendar control. This is a temporary delay to prevent interruptions, not a permanent stop. But you can also extend the pause to a maximum of 35 days, at any time. If you do nothing, Windows Update will return to its normal updating schedule when the pause period ends. You can also choose today’s date to exit the pause.

  • Receive updates for other Microsoft products. Disabled by default, this option in Advanced options lets you use Windows Update to update other Microsoft products installed on your PC, including Microsoft Office and Visual Studio.
  • Get me up to date. This option in Advanced options is disabled by default. When enabled, Windows 11 installs pending updates immediately and restarts the PC as soon as possible, even if it’s during active hours. You will be notified before the PC reboots.
  • Download updates over metered connections. This option in Advanced options is disabled by default, but you can enable it to download updates normally over a metered connection.
  • Notify me when a restart is required to finish updating. By default, Windows 11 will automatically reboot your computer outside active hours when a pending update requires it. If you enable this option in Advanced options–it’s disabled by default–you will be prompted with a notification banner before the PC reboots and finishes an update.
  • Active hours. This option in Advanced options lets you configure active hours manually if desired and then specify custom start and end times with a maximum length between the two of 18 hours.
  • Optional updates. This link in Advanced options opens a page where you can view timely pending software updates, such as driver updates. Here, you can expand any groups–like Driver updates–if necessary, select the updates you wish to install, and then click “Download and install” to add them to the current download queue. If you ignore these updates, they will install automatically in the future.
  • Delivery Optimization. By default, Windows Update uses peer-to-peer networking capabilities to allow PCs on your home network to deliver software updates to each other over that network, reducing your overall Internet bandwidth usage. But you can configure this option in Advanced options to also enable this capability with other PCs over the Internet too, or just disable it entirely. I recommend leaving it configured as-is.

Check for updates manually

Windows Update is configured to run automatically in the background and it will prompt you if a pending update requires you to reboot your PC to complete the installation. But you can, open this page in Settings at any time to check for updates manually. If that doesn’t happen when you navigate to this page, click the “Check for updates” button to get it going.

View your update history

The Update history link displays a page where you can view previously-installed updates, and it’s neatly organized to display feature updates, quality updates, driver updates, definition updates, and other updates separately in their own collapsible and expandable sections.

The two options below that–“Uninstall updates” and “Recovery”–are useful if you experience reliability issues after installing an update:

Uninstall updates. This option displays a Settings page listing the updates that you can still uninstall. (You can uninstall some, but not all, quality updates.)

Recovery. This option is one of several throughout Settings that brings you to System > Recovery, where you can access the Windows 11 recovery tools.

Windows Security

Though Windows provides numerous features that help protect you, your data, and the PC itself, most work automatically in the background and few of them are interactive. One exception is Windows Security, a dashboard-like app that helps you quickly assess whether your PC is protected from threats and make some configuration changes.

You can quickly check that your PC is correctly secured by opening the app, as above, or you can open the overflow area of the Taskbar, where you will see a Windows Security icon that resembles a blue shield.

With this tray icon and the individual items on the Windows Security home page, Microsoft displays a colored badge overlay to indicate their relative health. You’re looking for a green checkmark, which means all is well. But if you see a yellow exclamation point (bang) or red “x” badge, you will need to make a configuration change or perform some task–like manually running an antivirus scan–to improve matters.

Defaults

Windows Security provides an at-a-glance view of the security and health of your PC, with 8 major areas of concern. Green check marks next to each area on the main page indicate that the system is healthy, secure, and up-to-date. But you may also see yellow bangs next to those areas that need attention.

Available items here include:

Virus & threat protection. This page provides a front-end to Windows Defender, the anti-virus and anti-malware solution that comes with Windows 11.

Account protection. This page provides links to various parts of the Accounts area of the Settings app related to your user account: Account info, Windows backup, Sign-in options, and Dynamic lock.

Firewall & network protection. Here, you will see a friendly interface to the network firewall that Microsoft provides with Windows 11. For the most part, you will never need to change any of the settings you see here.

Tip: While you will not usually need to access the legacy interface to the firewall, called Windows Defender Firewall with Advanced Security, you can do so by selecting the “Advanced settings” link here.

App & browser control. This page lets you configure three Windows 11 features that can help protect you against malicious and unknown apps, files, and websites. Smart App Control determines how Windows behaves when you download potentially unsafe applications from the web. Reputation-based protection helps protect you against malicious downloads, files, and websites that attempt phishing attacks to steal your identity. And Exploit protection lets you customize advanced technologies in Windows that are designed to protect the system from being compromised.

Tip: Smart App Control is not enabled by default, but Windows 11 will sometimes enable it, and it will notify you if that happens. In 2026, Microsoft updated Smart App Control to allow users to arbitrarily enable or disable this feature on the fly. If you find that it blocks your access to apps you know and trust, you can disable it.

Device security. Here, you can view but not edit the condition of whichever hardware-based security features–Core isolation (for preventing memory-based attacks), Security processor (the trusted platform module, or TPM), Secure Boot (which prevents offline attacks during reboots), and Data encryption–your PC supports. This will vary from PC to PC.

Device performance & health. This page provides a mini-dashboard related to the health of your PC, plus a link to Fresh start, a deprecated external tool.

Tip: The Fresh start commentary found on this page is a bit odd, as this feature is not part of Windows 11. Please refer to Reset this PC in the Recovery chapter to learn more about the Windows 11 equivalent of Fresh start.

Family options. This page provides links to Microsoft’s parental control functionality on the web. Family options is not a Windows 11 feature.

Protection history. If everything goes accordingly, this page will be blank, noting only that there are “no recent actions.” However, if Windows 11 encountered any threats, they will be listed here.

Customize

By default, Windows 11 doesn’t automatically enable a few features surfaced in Windows Security because of their privacy implications. You should make sure these features are enabled.

They are:

Reputation-based protection. This feature helps block potentially unwanted apps (PUAs) while you’re downloading or using them. It’s off by default in Windows 11 Home and Pro because this feature integrates with cloud-based machine learning capabilities that examine app behaviors rather than using lists of trusted and untrusted apps. To enable this feature, select “App & browser control” and then click “Turn on” under “Reputation-based protection.”

Standard hardware security. Depending on the capabilities of your PC, Windows 11 can use a range of Core isolation, Security processor, Secure boot, and Data encryption features to help protect your PC using hardware-backed enhancements. Whichever of these features is available, all should be configured to “On.” But I occasionally see some PCs with a Core isolation feature called Memory integrity disabled. If so, enable this feature by selecting “Device security” and selecting the “Core isolation details” link under “Core isolation.”

Tip: In 2026, Microsoft added a new security feature called Administrator protection to Windows 11. This is a new level of protection in which user accounts with administrator privileges behave much like Standard accounts and require you to verify your identity with Windows Hello before completing potentially dangerous tasks. This sounds like a good idea, but in practice, it’s incredibly annoying. There are too many verification prompts and clearing them is tedious and requires too many steps. So for now, I don’t recommend enabling this feature. But you may want to experiment with it. If so, you can enable it in Windows Security > Account Protection > Administrator protection settings.

Windows Defender

Protecting Windows 11 against viruses, malware, and other electronic attacks requires a combination of common sense and using and relying on the system’s built-in security tools. Key among the latter is a service called Windows Defender.

Defaults

Windows Defender provides protection from online threats such as viruses, malware, and ransomware. But the best things about this service, perhaps, are that it’s free, effective, and automatic. It comes with Windows 11, works in the background, and is always enabled. Unless something bad happens, the only time you’ll notice it exists is when it displays a notification once each week just to let you know it’s doing its thing.

Customize

There are several Windows Defender options you could configure in Virus & threat protection settings in the Windows Security app. But you should leave that alone for the most part: Windows Defender works automatically in the background and it’s configured optimally for that.

There is, however, one option you might consider disabling. But you do that in Windows Security settings: If you navigate to Notification settings in Windows Security, you will find an option under “Virus & threat protection notifications” named “Get informational notifications.” It’s enabled by default, and this is why Defender displays a banner notification once each week. If you find that annoying, as I do, you can just disable it here.

Scan a file or folder

While Windows Defender usually works without any intervention, you may occasionally want to perform a manual scan of a file (or a group of files), a folder (or a group of folders) or even the entire PC.

To scan one or more files or folders–a suspicious file, perhaps–navigate to the appropriate destination with File Explorer, select the item(s) in question, right-click, choose “Show more options,” and then select “Scan with Windows Defender” from the context menu that appears. When you do, the Windows Security app opens to the Virus & threat protection page and runs what’s called a custom scan on the selected items.

Scan your PC

You can manually run a quick, full, or custom Windows Defender scan of your entire PC at any time. To do so open Windows Security and navigate to Virus & threat protection. Click the “Quick scan” button if that’s what you want. Otherwise, click “Scan options” to choose the type of scan you want.

Click “Scan now” to start the scan.

Tip: Select “Microsoft Defender Antivirus (offline scan)” to perform an offline scan of your PC outside of Windows. This option requires the PC to reboot so it can scan the disk while Windows 11 isn’t running and it can take a long time.

Find My Device

Windows 11 includes a feature called Find my device feature that can help you locate your PC if it’s lost or stolen. This feature is located in the Settings app by navigating to Privacy & security > Find my device.

Tip: Find my device requires that you sign in to Windows 11 with a Microsoft account. If you do, it is enabled by default.

Tip: Find my device also requires that location settings are enabled.

You can view the location of this PC and your other PCs and devices by selecting the “See all your devices linked to your account” option. This opens your default web browser and navigates to the Devices page on the Microsoft account website. Click “Find my device” at the top of this page to display the Find my device page with a zoomable map view with a list of your PCs appears.

Now, select the PC you’re trying to find in the list. The view expands to display more options.

From here, you can select the “Find” button to locate that particular PC on the map. Or, select the “Lock” button to remotely lock the PC, preventing anyone who finds it from accessing your data. This function will also enable location tracking so that you can continue to find it in the event of theft.

Gain unlimited access to Premium articles.

With technology shaping our everyday lives, how could we not dig deeper?

Thurrott Premium delivers an honest and thorough perspective about the technologies we use and rely on everyday. Discover deeper content as a Premium member.

Tagged with

Share post

Thurrott