By 2025, Microsoft claimed to have the “most widely used operating system in the world” with more than 1.4 billion monthly active devices. This dominant market share makes it a target for many bad actors who invest time and resources attempting to exploit security vulnerabilities. However, Microsoft has implemented various settings that allow you to protect yourself.
With a little know-how, you can stay protected in Windows without downloading third-party software. Windows has a wide range of secure authentication methods for accessing your device, a firewall, antivirus, and even a way to encrypt your drives and locate your device if it’s lost or stolen.
So, if you have been using Windows for a while and any of the security settings mentioned below seem new to you, it is essential that you start using them immediately. Since official support for Windows 10 ended in October 2025, this guide will focus on Windows 11.
Activate Windows Hello
If you are looking for an easier and more secure way to sign in to your Windows PC, you should enable Windows Hello. Once done, you no longer need to use a password to unlock your Windows device. Instead, you can use a PIN or biometric data (facial recognition or fingerprint recognition). These methods are more convenient and, in the case of biometrics, cannot be forgotten or guessed. PINs are easier to remember and are actually more secure than passwords for on-device authentication.
To enable Windows Hello, follow the steps below:
-
Go to Settings > Accounts > Sign-in Options.
-
Click Face Recognition, Fingerprint Recognition, or PIN.
-
Click Configure.
-
Follow the instructions to set everything up.
-
In the Additional Settings section, enable “For enhanced security, only allow Windows Hello sign-in for Microsoft accounts on this device.” »
The beauty of the PIN in particular is that once you’ve linked your Microsoft account (more on that later) to the Windows PC, you can use it to reset your Hello PIN if necessary. If you are using a local account, you will need to log in with your password first when you forget your PIN and then reset it.
Enable Windows Firewall
If you are a heavy Internet user, a firewall is an essential security tool that cannot be ignored. Indeed, not all traffic passing through the Internet or the network to which you are connected has good intentions. Some of them are unsolicited, like hackers who try to hijack your device by remotely injecting malicious code. Your PC needs a way to stop what comes with bad intentions, to prevent it from causing damage. This is where a firewall comes in, because it knows what to report or reject as suspicious traffic trying to access your system.
Windows has a built-in firewall. Here’s how you can enable it:
-
Go to Settings > Privacy & Security > Windows Security > Firewall & Network Protection.
-
Click Public Network.
-
Enable Microsoft Defender Firewall.
-
Click the back arrow in the upper left corner.
-
Repeat steps two and three for the domain network and the private network.
Enable Microsoft Defender
Firewalls aren’t enough to protect your Windows PC from online threats: you also need an antivirus. Microsoft Defender is one of the best antivirus applications on the market and it’s built into Windows. You just need to make sure that some of the important features are enabled. One is real-time protection, which constantly monitors your PC for malware.
To enable real-time protection, follow these steps:
-
Go to Settings > Privacy & Security > Windows Security > Virus & Threat Protection.
-
Under Virus and threat protection settings, click Manage settings.
-
Enable real-time protection.
You should also enable Controlled Folder Access, which allows only applications that Windows trusts to make changes to protected folders. To enable it, follow these steps:
-
Go to Settings > Privacy & Security > Windows Security > Virus & Threat Protection.
-
Under Ransomware Protection, click Manage Ransomware Protection.
-
Enable Controlled Folder Access.
-
Click Protected Folders.
-
Click Add Protected Folder.
-
Navigate to the folder you want to protect and add it.
-
Repeat steps five and six until you have added all the folders you want to control access to.
Basic isolation is another feature that helps isolate the code executed by applications. It first runs it in a virtual environment to determine that the software is safe before allowing Windows to run it.
-
Go to Settings > Privacy & Security > Windows Security > Device Security.
-
Under Core Isolation, click Core Isolation Details.
-
Enable Memory Integrity.
-
Also enable local security authority protection.
Use Windows with a Microsoft account
When setting up Windows, you must associate your Microsoft account with it. However, if you are one of those who have managed to bypass this requirement, perhaps now is the time to consider using that Microsoft account after all. Beyond the benefits of using a Microsoft account, such as syncing across devices, moving your Windows license when upgrading the device, and purchasing apps and movies from the Microsoft Store, it also lets you take advantage of Microsoft’s multi-factor authentication, authenticator apps, passkeys, passwordless sign-in, security keys, recovery methods, and more.
If you don’t already have a Microsoft account, go to the Microsoft website and create one. Then follow these steps below to pair it with your Windows device.
-
Go to Settings > Accounts > Your Information.
-
Under Account Settings, click Sign in with a Microsoft account instead.
-
Follow the instructions to sign in to your Microsoft account.
Microsoft will collect data about your activity on your Windows computer, but there are ways to limit the amount of data collected.
Microsoft account-dependent security features you need
One of the security features that requires a Microsoft account is device encryption. This enables BitLocker encryption for your drives and is essential if you store sensitive information on your computer. If a thief steals your device, it means they won’t be able to access your information even if they put your drive in another computer.
When enabled, Device Encryption stores a recovery key in your Microsoft account. Although it’s usually turned on automatically, if you need to turn it on manually, go to Settings > Privacy & Security > Device Encryption and turn on the toggle.
If your computer is stolen, another useful security feature of your Microsoft account can locate it for you. To enable Find My Device for your Windows PC, follow these steps:
-
Go to Settings > Privacy & Security > Location.
-
Enable Location Services.
-
Go back and click on the Find my device page.
-
Enable Find my device.
Here’s how to use Find My Device to locate or lock your Windows computer if it’s stolen:
-
Sign in to your Microsoft account in a web browser.
-
Click Devices in the left menu.
-
Under your PC name, click Find my device.
-
A map will open, showing you the last known location of your device.
-
To lock it, click Lock.
-
Enter the message you want to display on the lock screen.
-
Click Lock.
