Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A secure Windows 11 PC depends on layered protections, not one switch. Keep Windows and drivers updated, review Windows Security, and enable protections such as reputation-based blocking and Memory integrity when your hardware and software support them.

Check firmware protections such as TPM and Secure Boot before changing UEFI settings. Before clearing the TPM or changing Smart App Control, understand the compatibility and recovery consequences.

1. Install Windows and driver updates

Many Windows security features depend on current operating-system and hardware components. Open Settings > Windows Update, select Check for updates, and install available security, cumulative, and firmware updates. Restart when Windows requests it, then check again until no important updates remain.

For hardware that Windows Update does not update, use the support page for the PC or component manufacturer. This is particularly important when Windows Security reports an incompatible driver for Memory integrity or Kernel-mode Hardware-enforced Stack Protection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

2. Review Windows Security’s protection areas

Open Windows Security from the Start menu. Review its protection areas, including the following:

Windows Security area What it controls
Virus & threat protection Malware scanning and Microsoft Defender protection.
App & browser control Smart App Control, reputation-based protection, and exploit protection.
Device security TPM, Secure Boot, Core isolation, Memory integrity, and hardware-security status.
Firewall & network protection Windows Firewall profiles and network warnings.
Account protection Sign-in and Windows Hello-related security features.

If Windows Security displays a yellow or red warning, open that section rather than ignoring the notification. Some warnings indicate a setting is disabled; others identify an incompatible driver, missing firmware support, or a protection that needs attention.

3. Turn on reputation-based protection

Go to Windows Security > App & browser control > Reputation-based protection. This page contains controls for Microsoft Defender SmartScreen and potentially unwanted app blocking.

Review these settings:

  • Check apps and files checks downloaded applications and files against Microsoft’s reputation service.
  • SmartScreen for Microsoft Edge warns about known malicious or deceptive websites and downloads in Edge.
  • Phishing protection can warn if the Windows sign-in password is entered into a malicious website or application, reused, or typed into Notepad or Microsoft 365 applications.
  • Potentially unwanted app blocking helps block software that may show unwanted advertising, install other software, or behave in ways users do not want. Keep both available PUA-blocking controls enabled.
  • SmartScreen for Microsoft Store apps checks Store applications.

Microsoft says phishing protection currently protects only the password used to sign in to Windows 11. It is not a general-purpose password manager and does not protect every password used for websites or other accounts.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Decide whether Smart App Control is suitable

Open Windows Security > App & browser control > Smart App Control settings. Smart App Control is an application-execution control, not an antivirus replacement. It works alongside Microsoft Defender or a third-party antivirus program.

Its available states are:

State Meaning
Evaluation Windows observes the PC and determines whether Smart App Control is suitable. It does not block applications during evaluation.
On Windows blocks applications it considers malicious, potentially unwanted, or untrusted.
Off Smart App Control does not make application-execution decisions.

When cloud analysis cannot make a confident decision, Smart App Control allows an application only if it has a valid digital signature. An unsigned or invalidly signed application is treated as untrusted and may be blocked.

This can affect legitimate specialist software, old utilities, internal business tools, installers, updates, and uninstallers. A known edge case involves Windows Installer Transform files with the .MST extension; Microsoft says these files currently cannot be digitally signed, so an installer that depends on one may be blocked.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

There is no per-application bypass for Smart App Control. If a legitimate program is blocked, the documented choices are to obtain a properly signed version from its developer or turn Smart App Control off. Do not disable it merely because an unverified download is inconvenient to install.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s App & browser control article says that, after evaluation ends or after manually selecting a state, the device cannot return to Evaluation without reinstalling or resetting Windows. However, Microsoft’s newer FAQ says recent Windows updates can enable Smart App Control from Windows Security without a clean installation and can allow it to be re-enabled after it was temporarily disabled. Check the current behavior on your Windows build before changing the state, and consider compatibility with your software first.

Smart App Control may be unavailable or remain off when the PC is enterprise-managed, Developer Mode is configured, Windows is running in S mode, optional diagnostic data is disabled, or Microsoft’s evaluation decides that the device is not a suitable candidate.

5. Enable Core isolation and Memory integrity

Open Windows Security > Device security > Core isolation details. The controls shown depend on the Windows version and hardware.

Memory integrity

Memory integrity, also called Hypervisor-protected Code Integrity (HVCI), uses hardware virtualization to isolate kernel code. This makes it harder for a low-level malicious driver to compromise Windows.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Turn the Memory integrity switch to On, then restart if Windows asks. Hardware virtualization must also be enabled in UEFI/BIOS; turning on the Windows switch alone is not sufficient. The firmware option may be named Intel Virtualization Technology, VT-x, AMD-V, SVM, or something similar, depending on the manufacturer.

If Windows reports an incompatible driver:

  1. Note the driver name shown by Windows Security.
  2. Check Settings > Windows Update > Advanced options > Optional updates for a driver update.
  3. Check the PC, motherboard, or device manufacturer’s support page for a newer driver.
  4. If no compatible driver exists, remove the device or application that requires it before enabling Memory integrity.

Installing a device with an incompatible driver after Memory integrity is enabled can cause the same problem.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Kernel-mode Hardware-enforced Stack Protection

On supported systems, Core isolation may also show Kernel-mode Hardware-enforced Stack Protection. It requires Memory integrity and a compatible processor supporting Intel Control-flow Enforcement Technology or AMD Shadow Stack.

This feature can fail because of an incompatible driver or service. Some applications install a service first and load their driver only when the application starts, which is why Windows may identify an associated service rather than an obviously installed driver. Update or remove the associated software if Windows identifies it as incompatible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Memory access protection

Memory access protection, also called Kernel DMA protection, helps defend against direct-memory-access attacks through PCI-connected devices such as Thunderbolt hardware. It restricts direct access to memory, particularly while the PC is locked or the user is signed out.

6. Check TPM and Secure Boot

Open Windows Security > Device security. Depending on the PC, this page may show Secured-core PC, Core isolation, Security processor, Secure boot, Data encryption, and Hardware security capability.

Check the TPM

Select Security processor details to inspect the TPM. Windows identifies the TPM in this interface as the Security processor. If the section is missing, the PC may not have TPM hardware, or TPM may be disabled in UEFI.

For TPM errors, open Security processor troubleshooting. Possible messages include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • A firmware update is needed for your security processor (TPM)
  • TPM is disabled and requires attention
  • TPM storage is not available. Please clear your TPM
  • Device health attestation isn’t available. Please clear your TPM
  • Your TPM isn’t compatible with your firmware and may not be working properly

Update the system firmware or enable TPM in UEFI where appropriate. The exact firmware procedure is manufacturer-specific. Do not select Clear TPM casually: back up important data first and make sure you have recovery information for encrypted drives and accounts. Clearing the TPM can remove stored security keys and require sign-in or encryption recovery steps afterward.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Check Secure Boot

Secure Boot prevents rootkits from loading before Windows. Enable it in UEFI when your hardware and operating system support it, but check compatibility first. Some graphics cards, Linux installations, earlier Windows versions, and other hardware configurations may require Secure Boot to remain disabled.

Windows Security’s hardware-status labels distinguish between these levels:

Status Requirements
Standard hardware security TPM 2.0, Secure Boot, DEP, and UEFI MAT.
Enhanced hardware security Standard requirements plus Memory integrity.
All Secured-core PC features enabled Enhanced requirements plus System Management Mode protection.

7. Keep the vulnerable-driver blocklist enabled

Windows 11 includes the Microsoft vulnerable driver blocklist. It blocks drivers with known vulnerabilities, malware-associated signing certificates, or behavior that bypasses the Windows security model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The blocklist is enabled when Memory integrity, Smart App Control, or Windows S mode is enabled. If a driver is stopped, Windows may show a Program Compatibility Assistant notification saying that a driver cannot load or that a security setting is preventing it from loading.

Do not work around the warning by disabling security immediately. First:

  1. Run Windows Update.
  2. Open Device Manager and inspect the affected device for an update or warning icon.
  3. Download a current driver from the hardware manufacturer.
  4. Replace or remove the hardware or application if the manufacturer provides no compatible driver.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

8. Use Credential Guard where the edition supports it

Credential Guard protects authentication tokens by placing them in a protected virtualized environment. It is available on Windows Enterprise and Education editions, not generally on Home or Pro.

On a supported, managed PC, check the organization’s security policy and Windows Security status before changing virtualization-based security settings. Credential Guard can affect older authentication methods and should be tested against business applications before broad deployment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

9. Use safer everyday settings

  • Use a standard user account for routine work and reserve an administrator account for installations and system changes.
  • Use Windows Hello, a strong PIN, or another phishing-resistant sign-in method where available.
  • Lock the PC with the Windows key plus L when leaving it unattended.
  • Download applications from the developer’s official site or the Microsoft Store. Avoid cracks, key generators, and repacked installers.
  • Keep browser extensions to a minimum and remove extensions you no longer use.
  • Do not approve an administrator prompt unless you recognize the program and expected the change.
  • Keep backups disconnected or protected from accidental deletion. Security settings reduce risk but cannot replace a recoverable backup.

10. A practical order for securing a new PC

  1. Complete Windows Update and restart.
  2. Open Windows Security and resolve existing warnings.
  3. Turn on reputation-based protection and PUA blocking.
  4. Review Smart App Control before installing specialist or unsigned software.
  5. Check the TPM and Secure Boot status under Device security.
  6. Enable Memory integrity, then resolve incompatible drivers rather than ignoring the warning.
  7. Confirm that Windows Firewall and Microsoft Defender are active unless a trusted security product manages them.
  8. Set up Windows Hello, a standard daily-use account, and tested backups.

After a major hardware, driver, or firmware change, revisit Windows Security > Device security > Core isolation details and Windows Security > App & browser control. A previously working protection can become unavailable after an incompatible driver or configuration change.

FAQ

What is the most important Windows 11 security setting?

There is no single setting that protects every layer. Keep Windows updated, use reputation-based protection, check TPM and Secure Boot, and enable Memory integrity when compatible drivers are available. These controls cover applications, boot security, and the Windows kernel respectively.

Should Smart App Control be turned on?

It is a strong option for users who mostly install signed, mainstream software. It can block unsigned applications and installers that use Windows Installer Transform files, and it has no per-application bypass. Check compatibility with your software before enabling it.

Why can’t I turn on Memory integrity?

The usual cause is an incompatible driver, although hardware virtualization may also be disabled in UEFI/BIOS. Update or remove the identified driver or application, and confirm that virtualization is enabled in firmware.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is Windows Security’s phishing protection a password manager?

No. Microsoft says the current feature protects the password used to sign in to Windows 11. It can warn about entering or reusing that password in certain locations, but it is not general protection for every account password.

What happens if I clear the TPM?

Clearing the TPM removes stored security keys. Back up important data and make sure you have encryption recovery information before using the Clear TPM option under Windows Security’s Security processor troubleshooting page.

Why is Secure Boot not available or causing a problem?

Secure Boot depends on firmware, boot configuration, and hardware compatibility. Some graphics cards, Linux installations, older Windows versions, and other configurations may require it to remain disabled. Check the PC or motherboard manufacturer’s instructions before changing it.

The Bottom Line

Secure Windows 11 in layers: update the operating system and drivers, enable reputation-based protection, use Smart App Control when its application restrictions fit your software, and turn on Memory integrity after resolving driver conflicts. Then verify TPM, Secure Boot, the vulnerable-driver blocklist, Windows Firewall, sign-in protection, and backups. Security is strongest when these controls remain enabled without sacrificing the compatibility checks that keep the PC usable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.