...
Windows Defender antivirus is deployed to all Windows PaaS client systems. Antivirus definitions are updated automatically multiple times per day. Configuration policies for Windows Defender are deployed centrally using SCCM. Customized configuration policies may be deployed on a per-unit basis. To read detailed information about the Windows Defender configuration, view theĀ Windows Defender Configuration topic.
Security Configurations
Windows PaaS systems share many of the same security settings that are implemented on MiWorkspace Windows systems. The baseline security configuration for Windows PaaS systems is designed to enable users to securely access institutional and personal data while still preserving an easy to use computing experience. The settings were developed in consultation with the University of Michigan Information Assurance (IA) team. The specific settings that comprise the baseline security configuration have been tested by the MiWorkspace Quality Assurance (QA) Team to ensure compatibility with major university systems and applications.
The baseline security settings are implemented by Active Directory Group Policies. Settings are implemented in the following Group Policy Objects (GPO):
- EUC PaaS Workstation Admins
- EUC Windows - NTFS Enable Last Access Time
- EUC Windows 10 - Core Security Settings 1607 Base
- EUC Windows 10 - Firewall Settings 1607
Virtual Private Network (VPN)
...