Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Windows Client

ASecurity

Windows desktop operating systems (Windows 10 and Windows 11): desktop app model (Win32/UWP/MSIX/winget), editions and licensing, Intune/MDM management, Windows Update for Business, BitLocker, Windows Hello, desktop security (Defender, SmartScreen, ASR), desktop diagnostics (SFC, DISM, Reliability Monitor), and migration planning. Use when: \"Windows 10\", \"Windows 11\", \"Win10\", \"Win11\", \"Windows desktop\", \"Windows client\", \"BitLocker\", \"Intune\", \"Windows Update\", \"winget\", ...

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
securityrustgoshellgitsecurityperformance

Works with

cli

Security Analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill windows-client --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Windows Client?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Windows Client
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-windows-client/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-windows-client)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: windows-client
description: "Windows desktop operating systems (Windows 10 and Windows 11): desktop app model (Win32/UWP/MSIX/winget), editions and licensing, Intune/MDM management, Windows Update for Business, BitLocker, Windows Hello, desktop security (Defender, SmartScreen, ASR), desktop diagnostics (SFC, DISM, Reliability Monitor), and migration planning. Use when: \"Windows 10\", \"Windows 11\", \"Win10\", \"Win11\", \"Windows desktop\", \"Windows client\", \"BitLocker\", \"Intune\", \"Windows Update\", \"winget\", \"Snap Layouts\", \"Dev Drive\", \"LTSC\", \"Windows Hello\", \"Windows Autopilot\", \"Windows Defender\", \"SmartScreen\". Do NOT use for WSL configuration or Linux-on-Windows troubleshooting — use the `wsl` skill."
license: MIT
---

# Windows Client

This skill covers Windows desktop operating systems (Windows 10 and Windows 11). It provides deep knowledge of:

- Desktop app model: Win32, UWP, MSIX packaging, winget package manager, Desktop Bridge
- Editions and licensing: Home, Pro, Enterprise, Education, LTSC, Pro for Workstations, IoT Enterprise
- Intune / MDM management: Autopilot, compliance policies, configuration profiles, co-management with SCCM
- Windows Update for Business: deferral rings, Delivery Optimization, feature update targeting
- BitLocker: TPM+PIN, Device Encryption, recovery key management, Intune/AD backup
- Windows Hello: PIN, biometric, FIDO2, Windows Hello for Business
- Desktop security: Microsoft Defender Antivirus, SmartScreen, Attack Surface Reduction (ASR), Exploit Protection, Controlled Folder Access, Credential Guard, App Control for Business (WDAC)
- Desktop diagnostics: SFC, DISM, Reliability Monitor, driver troubleshooting, performance analysis
- Desktop Window Manager (DWM), Modern Standby, power management
- Migration planning: Windows 10 to Windows 11, LTSC lifecycle, ESU enrollment

> **Cross-reference:** For NT kernel internals, registry architecture, boot process, LSASS, service control manager, NTFS/ReFS, SMB, NDIS, WMI/CIM, and Virtualization-Based Security architecture, see the `windows-server` skill. Those fundamentals are shared across Windows client and server. For WSL, see the `wsl` skill.

## How to Approach Tasks

Route by request type: **troubleshooting** → `references/diagnostics.md`; **security hardening** → `references/best-practices.md`; **architecture** → `references/architecture.md`; **edition selection or licensing** → `references/editions.md`; **administration** → the guidance below.

**Identify Windows 10 vs Windows 11 first** — feature availability, UI behavior, hardware requirements, and support status all differ. Apply Windows desktop-specific reasoning, not generic OS or server advice. Validate with cmdlets, event log checks, and Settings app confirmation.

## Core Expertise

### Desktop App Model

Windows supports multiple application models that coexist on the desktop:

- **Win32** -- Classic desktop apps using kernel32/user32/gdi32. No sandboxing, full system access, installed via MSI/EXE. Still the dominant model for LOB and productivity apps.
- **UWP** -- Sandboxed AppContainer model with declarative capabilities. Lifecycle managed by PLM (Process Lifetime Manager). Delivered via Store or sideloading.
- **MSIX** -- Modern packaging format unifying MSI and App-V. Container-based virtual registry and filesystem. Clean install/uninstall with no orphaned artifacts. Supports Win32 apps via Desktop Bridge.
- **winget** -- CLI package manager supporting MSI, MSIX, EXE, Inno, NSIS, Burn, and Portable installers. DSC integration via `winget configure`. Enterprise-ready with private repo sources.
- **WinUI 3 / Windows App SDK** -- Current recommended UI framework, decoupled from OS cadence, ships via NuGet.

```powershell
# winget essentials
winget search <app>                          # Search community repo
winget install <id> --silent --accept-package-agreements --accept-source-agreements
winget upgrade --all --silent                # Upgrade everything
winget list                                  # Installed app inventory
winget export -o apps.json                   # Export for migration
winget configure --file config.dsc.yaml      # DSC-style machine setup
```

### Intune / MDM Management

Intune is the cloud-native management plane for Windows desktops, replacing or augmenting Group Policy:

**Enrollment methods:** Windows Autopilot (OOB provisioning), bulk enrollment (PPKG), auto-enrollment via Group Policy (hybrid), BYOD user-initiated, Entra ID join at OOBE.

**Key policy types:**
- **Compliance policies** -- Define minimum security bar (BitLocker, Secure Boot, Defender, OS version); non-compliant devices blocked by Conditional Access
- **Configuration profiles** -- Settings Catalog (CSP-backed), Security Baselines, Endpoint Security, Administrative Templates (ADMX), Custom OMA-URI
- **Update rings** -- Map to WUfB registry policies: Ring 0 (Pilot, 0d defer), Ring 1 (Early, 7d/30d), Ring 2 (Broad, 14d/90d)

**Co-management with SCCM:** Workloads slide between SCCM and Intune -- compliance, endpoint protection, device configuration, Windows Update, Office apps, client apps.

### Windows Update for Business

WUfB provides policy-based update management without on-premises WSUS:

| Update Type | Typical Deferral | Notes |
|---|---|---|
| Quality (monthly CU) | 0-30 days | Security + non-security |
| Feature (annual) | 0-365 days | Major version upgrade |
| Driver | 0-30 days | Optional via WUfB |
| Microsoft products | Via WUfB setting | Office, .NET, etc. |

**Delivery Optimization (DO)** reduces WAN bandwidth via peer-to-peer within subnets or across the organization. Modes: LAN (1), Group (2), Internet (3).

```powershell
# Check WUfB deferral settings
Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' -EA SilentlyContinue |
    Select-Object DeferQualityUpdates, DeferQualityUpdatesPeriodInDays,
                  DeferFeatureUpdates, DeferFeatureUpdatesPeriodInDays,
                  TargetReleaseVersion, TargetReleaseVersionInfo

# Pin to specific feature version
Set-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' `
    -Name 'TargetReleaseVersion' -Value 1
Set-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' `
    -Name 'TargetReleaseVersionInfo' -Value '24H2'

# Check DO mode
Get-DeliveryOptimizationStatus | Select-Object DownloadMode, DownloadModeSrc
```

### BitLocker Management

BitLocker provides full-volume encryption with multiple protector modes:

| Method | TPM | PIN | Scenario |
|---|---|---|---|
| TPM-only (Device Encryption) | Required | None | Consumer, simplified |
| TPM + PIN | Required | Yes (6+ digit) | Enterprise recommended |
| TPM + Network Unlock | Required | Network-based | Domain-joined, auto-unlock on corp |
| Password-only | Not required | Password | USB/removable (BitLocker To Go) |

```powershell
# Enable BitLocker with TPM+PIN
$pin = ConvertTo-SecureString "123456" -AsPlainText -Force
Enable-BitLocker -MountPoint C: -EncryptionMethod XtsAes256 -TPMandPINProtector -Pin $pin

# Add recovery password and back up to AD
Add-BitLockerKeyProtector -MountPoint C: -RecoveryPasswordProtector
$keyID = (Get-BitLockerVolume C:).KeyProtector |
    Where-Object KeyProtectorType -eq RecoveryPassword
Backup-BitLockerKeyProtector -MountPoint C: -KeyProtectorId $keyID.KeyProtectorId

# Check status
Get-BitLockerVolume | Select-Object MountPoint, VolumeStatus, EncryptionMethod,
    ProtectionStatus, LockStatus, KeyProtector
```

### Desktop Security

**Microsoft Defender Antivirus** is the built-in AV/AM engine with real-time protection, cloud-delivered protection, and tamper protection.

**Attack Surface Reduction (ASR) rules** block specific malware behaviors (Office child processes, obfuscated scripts, email executable content). Deploy via Intune or `Set-MpPreference`.

**Exploit Protection** provides per-process mitigations: CFG, DEP, ASLR, SEHOP. Configure via `Get-ProcessMitigation` / `Set-ProcessMitigation`.

**Controlled Folder Access** protects Documents, Desktop, Pictures from ransomware-like writes. Allowlist trusted apps that need write access.

**SmartScreen** checks downloaded files and URLs against Microsoft's reputation service. Blocks unknown or known-bad executables at launch.

**App Control for Business (WDAC)** enforces code integrity at the kernel level -- only signed or explicitly trusted binaries execute. Strategic replacement for AppLocker.

### Desktop Diagnostics

**SFC and DISM** are the primary system file repair tools:
```powershell
sfc /scannow                                  # Scan and repair protected files
DISM /Online /Cleanup-Image /ScanHealth       # Full component store scan
DISM /Online /Cleanup-Image /RestoreHealth    # Repair from Windows Update
```

**Reliability Monitor** (`perfmon /rel`) shows a graphical timeline of crashes, errors, and installs.

**Performance counters** for desktop:
- `\Processor(_Total)\% Processor Time` -- >90% sustained = critical
- `\Memory\Available MBytes` -- <10% of total = warning
- `\PhysicalDisk(_Total)\Avg. Disk sec/Read` -- >50ms = warning
- `\GPU Engine(*)\Utilization Percentage` -- desktop-specific GPU monitoring

**Driver diagnostics:** `Get-PnpDevice | Where-Object Status -ne 'OK'` for problem devices, `pnputil /enum-drivers` for driver store inventory, Event ID 4101 for GPU TDR events.

## Common Pitfalls

**1. Ignoring TPM and Secure Boot for Windows 11**
Windows 11 strictly requires TPM 2.0 and UEFI Secure Boot. Verify before upgrade with `Get-Tpm` and `Confirm-SecureBootUEFI`. Devices without TPM 2.0 cannot run Windows 11.

**2. Not backing up BitLocker recovery keys before hardware changes**
Any TPM reset, BIOS update, or motherboard replacement invalidates the TPM protector. Always ensure recovery keys are backed up to AD, Entra ID, or a secure file share before hardware changes.

**3. Running Windows 10 Home/Pro past EOL without ESU**
Home and Pro 22H2 reached EOL October 14, 2025. Devices on these editions receive no security updates unless enrolled in the paid ESU program. Enterprise/Education 22H2 is supported until October 2027.

**4. Over-deferring quality updates**
Deferring monthly security updates beyond 14 days increases vulnerability exposure. Use ring-based deployment (Pilot 0d, Early 7d, Broad 14d) rather than blanket long deferrals.

**5. Not disabling SMBv1 on desktops**
SMBv1 is the WannaCry attack vector. Disable on all desktops: `Set-SmbServerConfiguration -EnableSMB1Protocol $false -Force`. Check with `Get-SmbServerConfiguration | Select EnableSMB1Protocol`.

**6. Ignoring unsigned drivers with HVCI enabled**
HVCI (Hypervisor-Protected Code Integrity) blocks unsigned kernel-mode drivers at runtime. Audit drivers before enabling VBS/HVCI to avoid breaking hardware functionality.

**7. Relying on Device Encryption without managed recovery keys**
Device Encryption (the simplified BitLocker on Home) backs up the recovery key to the user's Microsoft Account. In enterprise environments, this means recovery keys are outside IT control. Use managed BitLocker with AD/Entra ID key escrow instead.

**8. Not monitoring Delivery Optimization bandwidth**
DO peer-to-peer traffic can saturate LAN segments. Monitor with `Get-DeliveryOptimizationPerfSnapThisMonth` and configure bandwidth limits via Group Policy or Intune.

**9. Skipping Reliability Monitor during troubleshooting**
`perfmon /rel` is the fastest way to correlate a user-reported issue with the first crash event. It shows application failures, Windows failures, and software installs on a timeline.

**10. Deploying LTSC as a general-purpose desktop**
LTSC is designed for fixed-function devices (kiosks, medical, industrial). It lacks Store, Edge (in 2019), and annual feature updates. Using LTSC for general knowledge workers creates app compatibility and user experience gaps.

## Version-Specific Guidance

| Version | Reference | What's version-specific |
|---|---|---|
| 10 | `references/versions/10.md` | LTSC management, ESU enrollment, migration to Windows 11, Enterprise features, end-of-life posture |
| 11 | `references/versions/11.md` | Snap Layouts, Dev Drive, Widgets, Copilot, Windows Studio Effects, ARM64 support, AI features, 24H2/25H2 |

## Reference Files

Load these when you need deep knowledge for a specific area:

- `references/architecture.md` -- Desktop app model (Win32/UWP/MSIX/winget), driver model (WDDM, audio), DWM, Modern Standby, Store/MSIX delivery. Read for "how does X work" questions.
- `references/best-practices.md` -- CIS desktop hardening, Intune/MDM setup, update management, BitLocker deployment, application management. Read for design and operations questions.
- `references/diagnostics.md` -- SFC/DISM, Reliability Monitor, driver diagnostics, startup/performance tools, storage cleanup. Read when troubleshooting.
- `references/editions.md` -- Edition feature matrices (Win10 + Win11), hardware limits, upgrade paths, LTSC details. Read for edition selection and licensing questions.

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes
View all in security →