Microsoft detailed two Windows security initiatives—Windows Baseline Security Mode and User Transparency and Consent—aimed at making Windows 11 behave more like mobile platforms in how it gates access to sensitive resources. Under User Transparency and Consent, Windows will prompt users when applications request access to protected data and device features (e.g., files, camera, microphone) and when installers attempt to add additional software; decisions will be recorded so users can review and change permissions later, including revoking previously granted access.
Windows Baseline Security Mode is intended to enable runtime integrity safeguards by default, allowing only properly signed applications, services, and drivers to run while still permitting user/IT-admin exceptions for operational needs. Microsoft positioned the changes under its Secure Future Initiative and aligned them with the Windows Resiliency Initiative, noting a phased rollout in partnership with developers and enterprises and building on prior controls such as Smart App Control and administrator protection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-10, Microsoft announced two new Windows security initiatives: Windows Baseline Security Mode and User Transparency and Consent. The changes will add smartphone-style permission prompts for sensitive resources and make runtime integrity protections default so only properly signed apps, services, and drivers can run, with phased rollout and override options for users and administrators.
Microsoft launched its Secure Future Initiative in response to criticism and major nation-state intrusions, positioning it as a company-wide effort to improve security and resiliency. The initiative also encompassed measures such as securing Entra ID sign-ins, disabling ActiveX in Microsoft 365 and Office 2024, and tightening Microsoft 365 legacy-auth defaults.
Following the Storm-0558 breach, a U.S. DHS Cyber Safety Review Board report concluded that Microsoft's security culture was inadequate and had deprioritized security investments. The findings increased pressure on Microsoft to make broad security changes.
In January 2024, Microsoft disclosed that Russian state-linked hackers had compromised some of its source code repositories and internal systems. The disclosure added to scrutiny over Microsoft's internal security posture.
In July 2023, the China-linked Storm-0558 intrusion compromised Outlook/Exchange Online-related email accounts, resulting in email theft from 25 organizations. The incident later became a major catalyst for criticism of Microsoft's security practices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcehelpnetsecurity.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.