With SRP + some Windows Policies, it is possible to apply only a limited home version of Zero Trust.
- The user works only on SUA.
- The user cannot elevate applications (by Windows policy). No UAC prompt.
- Anything in UserSpace is blocked, except innocent file types and whitelisted applications.
- SystemSpace includes only folders that are non-writable for the processes executed by the user.
- Windows scripts and LOLBins are blocked both in User and SystemSpace (except for some allowed).
- Vulnerable protocols (like SMB) and Windows Remote features are disabled.
- SAC enabled (mainly to mitigate highly privileged exploits).
It is hard to infect such a hardened system on well updated Windows 11.
However, it is also necessary to
harden the web browser and firewall.
Such a hardened system is useful when using apps from Microsoft Store. Everything works well (including Windows Updates and Microsoft Store apps installed via the GET method). Almost zero-maintenance needed.