{"id":15399,"date":"2019-05-24T19:01:57","date_gmt":"2019-05-25T03:01:57","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/05\/24\/news-9148\/"},"modified":"2019-05-24T19:01:57","modified_gmt":"2019-05-25T03:01:57","slug":"news-9148","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/05\/24\/news-9148\/","title":{"rendered":"New browser extensions for integrating Microsoft\u2019s hardware-based isolation"},"content":{"rendered":"<p><strong>Credit to Author: Eric Avena| Date: Thu, 23 May 2019 15:50:07 +0000<\/strong><\/p>\n<p>The hardware-based isolation technology on Windows 10 that allows Microsoft Edge to isolate browser-based attacks is now available as a browser extension for Google Chrome and Mozilla Firefox.<\/p>\n<p>We <a href=\"https:\/\/blogs.windows.com\/msedgedev\/2016\/09\/27\/application-guard-microsoft-edge\/\">introduced the container technology<\/a> in 2017. Since then, we have been evolving the technology and engaging with customers to understand how hardware-based isolation can best help solve their security concerns. We know that many of our customers depend on multi-browser environments to allow enterprise apps to meet various compatibility requirements and enable productivity. And while modern browsers are continuously working to mitigate vulnerabilities, there are still exposures across these complex engines that can lead to irreversible and costly damages.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-89463\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/browser-vulnerabilities-2.png\" alt=\"\" width=\"600\" height=\"354\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/browser-vulnerabilities-2.png 842w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/browser-vulnerabilities-2-300x177.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/browser-vulnerabilities-2-768x453.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/browser-vulnerabilities-2-440x260.png 440w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>To provide customers with a comprehensive solution to isolate potential browser-based attacks, we have designed and developed Windows Defender Application Guard extensions, now generally available, to allow customers to integrate hardware-based isolation with Google Chrome and Mozilla Firefox.<\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-89454\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-chrome-store-903x1024.png\" alt=\"\" width=\"700\" height=\"794\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-chrome-store-903x1024.png 903w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-chrome-store-264x300.png 264w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-chrome-store-768x871.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-chrome-store.png 1382w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/p>\n<h3>How it works<\/h3>\n<p>The extensions for Google Chrome and Mozilla Firefox automatically redirect untrusted navigations to Windows Defender Application Guard for Microsoft Edge. The extension relies on a native application that we\u2019ve built to support the communication between the browser and the device\u2019s <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-application-guard\/configure-wd-app-guard\">Application Guard settings<\/a>.<\/p>\n<p>When users navigate to a site, the extension checks the URL against a list of enterprise sites defined by enterprise administrators. If the site is determined to be untrusted, the user is redirected to an isolated Microsoft Edge session. In the isolated Microsoft Edge session, the user can freely navigate to any site that has not been explicitly defined as enterprise-trusted by their organization without any risk to the rest of system. With our upcoming dynamic switching capability, if the user tries to go to an enterprise site while in an isolated Microsoft Edge session, the user is taken back to the default browser.<\/p>\n<p>To configure the Application Guard extension under managed mode, enterprise administrators can follow these recommended steps:<\/p>\n<ol>\n<li>Ensure devices <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-application-guard\/reqs-wd-app-guard\">meet requirements<\/a>.<\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-application-guard\/install-wd-app-guard#install-application-guard\">Turn on<\/a> Windows Defender Application Guard.<\/li>\n<li>Define the <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-application-guard\/configure-wd-app-guard#network-isolation-settings\">network isolation settings<\/a> to ensure a set of enterprise sites is in place.<\/li>\n<li>Install the new Windows Defender Application Guard companion application from the <a href=\"https:\/\/go.microsoft.com\/fwlink\/?linkid=2086033\">Microsoft Store<\/a>.<\/li>\n<li>Install the extension for <a href=\"https:\/\/go.microsoft.com\/fwlink\/?linkid=2086034\">Google Chrome<\/a> or <a href=\"https:\/\/go.microsoft.com\/fwlink\/?linkid=2086035\">Mozilla Firefox<\/a> browsers provided by Microsoft.<\/li>\n<li>Restart the device.<\/li>\n<\/ol>\n<h3>Intuitive user experience<\/h3>\n<p>We designed the user interface to be transparent to users about Windows Defender Application Guard being installed on their devices and what it does. We want to ensure that users are fully aware that their untrusted navigations will be isolated and why.<\/p>\n<ol>\n<li>When users initially open Google Chrome or Mozilla Firefox after the extension is deployed and configured properly, they will see a Windows Defender Application Guard landing page.\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-89455\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-components-complete.png\" alt=\"\" width=\"1728\" height=\"936\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-components-complete.png 1728w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-components-complete-300x163.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-components-complete-768x416.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-components-complete-1024x555.png 1024w\" sizes=\"auto, (max-width: 1728px) 100vw, 1728px\" \/><\/li>\n<li>If there are any problems with the configuration, users will get instructions for resolving any configuration errors.\u00a0<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-89456\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-components-not-complete.png\" alt=\"\" width=\"1728\" height=\"936\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-components-not-complete.png 1728w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-components-not-complete-300x163.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-components-not-complete-768x416.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-components-not-complete-1024x555.png 1024w\" sizes=\"auto, (max-width: 1728px) 100vw, 1728px\" \/><\/li>\n<li>Users can initiate an Application Guard session without entering a URL or clicking on a link by clicking the extension icon on the menu bar of the browser.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-89457 aligncenter\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-menu.png\" alt=\"\" width=\"322\" height=\"502\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-menu.png 322w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2019\/05\/windows-defender-application-guard-menu-192x300.png 192w\" sizes=\"auto, (max-width: 322px) 100vw, 322px\" \/><\/p>\n<h3>Commitment to keep enterprise users and data safe<\/h3>\n<p>Hardware-based isolation is one of the innovations that enhance platform security on Windows 10. It is a critical component of the <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-atp\/overview-attack-surface-reduction\">attack surface reduction capabilities<\/a> in Microsoft Defender Advanced Threat Protection (<a href=\"https:\/\/www.microsoft.com\/en-us\/windowsforbusiness\/windows-atp?ocid=cx-blog-mmpc\">Microsoft Defender ATP<\/a>) and the broader unified security in <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Security-Privacy-and-Compliance\/Announcing-Microsoft-Threat-Protection\/ba-p\/262783\">Microsoft Threat Protection<\/a>. With the new Application Guard extension for Google Chrome and Mozilla Firefox, customers can extend the security benefits of isolation in their environments and further reduce attack surface. Customers can confidently navigate the expansive internet with protection for enterprise and personal data.<\/p>\n<p>The Windows Defender Application Guard extensions for Google Chrome and Mozilla Firefox are now available for Windows 10 Professional, Enterprise, and Education SKUs, version 1803 and later with latest updates.<\/p>\n<p>&nbsp;<\/p>\n<p><strong><em>Rona Song<\/em><\/strong><br \/> <em>Windows platform security team<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<h3>Talk to us<\/h3>\n<p>Questions, concerns, or insights on this story? Join discussions at the\u00a0<a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Windows-Defender-Advanced-Threat\/ct-p\/WindowsDefenderAdvanced\">Microsoft Defender ATP community<\/a>.<\/p>\n<p>Follow us on Twitter <a href=\"https:\/\/twitter.com\/MsftSecIntel\" target=\"_blank\" rel=\"noopener\"><strong>@MsftSecIntel<\/strong><\/a>.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/2019\/05\/23\/new-browser-extensions-for-integrating-microsofts-hardware-based-isolation\/\">New browser extensions for integrating Microsoft\u2019s hardware-based isolation<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/\">Microsoft Security<a>.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2019\/05\/23\/new-browser-extensions-for-integrating-microsofts-hardware-based-isolation\/\" target=\"bwo\" >https:\/\/blogs.technet.microsoft.com\/mmpc\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Eric Avena| Date: Thu, 23 May 2019 15:50:07 +0000<\/strong><\/p>\n<p>The hardware-based isolation technology on Windows 10 that allows Microsoft Edge to isolate browser-based attacks is now available as a browser extension for Google Chrome and Mozilla Firefox. We introduced the container technology in 2017. Since then, we have been evolving the technology and engaging with customers to understand how hardware-based isolation can best help&#8230;<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/2019\/05\/23\/new-browser-extensions-for-integrating-microsofts-hardware-based-isolation\/\">New browser extensions for integrating Microsoft\u2019s hardware-based isolation<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/www.microsoft.com\/security\/blog\/\">Microsoft Security<a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10759,10378],"tags":[21873,4500,21482,11427,21874,21484,10700,17395,3924,21875,21483,10761,21876,21496],"class_list":["post-15399","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security","tag-browser-extension","tag-cybersecurity","tag-endpoint-security","tag-google-chrome","tag-hardware-based-isolation","tag-microsoft-defender-atp","tag-microsoft-edge","tag-mozilla-firefox","tag-phishing","tag-platform-security","tag-threat-protection","tag-windows-10","tag-windows-defender-application-guard","tag-windows-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15399","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15399"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15399\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15399"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15399"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15399"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}