Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • What BeyondTrust Has to Say about Windows 10 current page
Link copied

What BeyondTrust Has to Say about Windows 10

Apr 28, 2015
Author:
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor
Blog banner default
What BeyondTrust Has to Say about Windows 10
Morey Haber Headshot 2024
Morey J. Haber
Chief Security Advisor

Microsoft is on the verge of releasing its latest operating system, Windows 10. It has taken several nontraditional strides for this release including being free Microsoft 10 for one year for all Windows 7 and Windows 8 users (a play from Apple’s OS X playbook). Additionally, Windows 10 will allow upgrades for unlicensed copies of previous versions (this will not provide a valid license, just allow for the upgrade). Based on our understanding of the beta releases and what is currently published, several key components will be worth watching as we near the imminent release:Windows-10-LogoMicrosoft Windows Hello – The concept of Hello is based on Microsoft Kinect and Passport technology. Hello provides a credential to a system that can’t be stolen or copied by another user (theoretically). Since it is based on advanced biometrics, and not simply face recognition from a photo, it would be difficult or near impossible to impersonate a user. Since the various methods (facial, iris, fingerprint, etc.) require special hardware (and not a common camera built into a laptop or tablet today), it is yet to be seen how this equipment will be adopted and the cost it will add to systems.

Providing a unique credential to a user that can only be associated with them is a great way to ensure passwords are not shared and are unique per individual. There is one potential draw back that could circumvent this system – the password can never be changed. You cannot change your face, infrared heat patterns of your skin, iris blood vessels, or even your fingerprint. If a database was stolen that keeps this PII, it is just a matter of time before someone could technically own your likeness forever.

Project Spartan – Whatever the final name will be, I am certain it will be a safer browser than Internet Explorer. Microsoft has completely rewritten the rendering engine and certainly had security in mind when doing so. In order to keep up with the other players, Spartan will have to adopt features found in Safari, Chrome, and Firefox and do them better – like iCloud Password KeyChains and Session passing. It is yet to be seen how it will support Active X controls and other plug-ins like browser bars that have traditionally caused security holes.

Windows 10 will improve on the concepts of least privilege. Modern applications should be designed and complied to fully operate as standard user and Microsoft has embraced the need to change the OS in order to do so. New programs will be able to launch processes for auto update, etc. without the need for administrator credentials. While this is a huge improvement, it does not dissolve the need for tools that support legacy applications, all operating system functions, and vendors that truly need administrator access like VMware workstation. In addition, application allow listing with a focus on least privilege is still void in this latest release. This means, that there are little provisions to “absolutely” control what executes, is installed, and what permissions are used when a user interacts with a system.

For all of these solutions, BeyondTrust tests beta builds from Microsoft to determine scope, effort, and timelines for support of these new solutions. Whether this is just basic compatibility or support with new features, BeyondTrust strives to meet compatibility within 3 months of GA by Microsoft. We are looking forward to supporting Microsoft with our upcoming Privilege Account Management and Vulnerability Management releases.

Will you be at Microsoft Ignite next week in Chicago? Stop by booth #308 to learn more about how BeyondTrust proactively eliminates data breaches from insider privilege abuse and external hacking attacks.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Better Application Group Management in Privilege Guard 2.8
    Oct 20, 2017 Better Application Group Management in Privilege Guard 2.8
    Blog
    1m
  • Don’t be too cool for two-factor [authentication]
    Nov 28, 2017 Don’t be too cool for two-factor [authentication]
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.