Covers Windows LAPS, local user group membership, Credential Guard and Windows Hello for Business in a single Intune endpoint security policy type for Windows. Since July 2024 it has replaced the Identity protection template.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Account protection in context, with comparison tables and the common traps.
Terms in this definition
- Windows LAPS
Looks after a device's local administrator password and keeps a copy in Active Directory or Microsoft Entra ID. It is set up through Intune account protection policies.
- Local user group membership
A Windows profile under Endpoint security > Account protection. Through the LocalUsersAndGroups CSP it can put people into, take them out of, or completely replace the membership of local groups like Administrators.
- Credential Guard
Uses virtualisation-based security to isolate Kerberos TGTs and NTLM hashes. Windows Server 2025 enables it automatically on domain-joined member servers (not DCs), which breaks live migration relying on CredSSP.
- Windows Hello for Business
Sign-in for Windows that needs no password and resists phishing, provided the device has suitable hardware.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Security policy
Implements row-level security for Fabric warehouses or SQL analytics endpoints by attaching an inline table-valued function, acting as filter predicate, onto a table. Excluded rows vanish quietly from reads, updates and deletes.
- Entra ID Protection
Calculates sign-in risk and user risk and enforces the MFA registration policy; it comes with Entra ID P2.