Basic_Recommended_Settings on Windows 8+.
This is a predefined setting profile that allows EXE (TMP) and MSI files globally.
The scripts, shortcuts and other files with unsafe extensions are still
blocked by default in UserSpace.
This profile can harden Windows 8+ while maintaining maximum functionality
and compatibility. It could be probably called Recommended Settings
for cautious users.
The "Run By SmartScreen" entry in the Explorer context menu can be used
to check the standalone application installers (EXE and MSI) by SmartScreen
Application Reputation service. This entry should be also used for unsafe
executables listed below:
1. Files downloaded from the Internet, especially email attachments and executables
from the archives (7-zip, Zip, Arj, Rar, etc.).
2. Executables shared with other people via USB drives, Memory cards, etc.
The users can install/execute/update applications via EXE and MSI files. The
only exceptions are EXE and MSI files executed directly from an archive or
email client. In such cases, the archive has to be first unpacked and email attachment
has to be downloaded to hard disk. Next, it is recommended to use
"Run By SmartScreen" to execute those files via SmartScreen.
It is also recommended to use this profile with ConfigureDefender HIGH
Protection Level (if WD is the main antivirus) and "Recommended H_C" firewall
outbound block rules (see <FirewallHardening> option). The profile
can be used with any antivirus which can apply strong proactive detection.
Is it safe?
It is as safe as the H_C Recommended Settings if the user is cautious enough
to use the "Run By SmartScreen" entry in the Explorer context menu. If not
then EXE and MSI files will be covered only by the Antivirus.
PLEASE NOTE: This profile will be not enough for children. They will be
better protected by the H_C Recommended Settings and SmartScreen set to
Block, with occasional help from more experienced users.