I use ACLs to restrict access to mmc.exe to the admin account only. That way, lots of mmc things are not available to the attacker since I use the Standard account daily.
me neither.normally do not go online with the admin account.
The same here, always logged into the standard account.I normally do not go online with the admin account.
+1me neither.
I'm experiencing the same issue on my freshly installed system, suggesting it's a Windows 11 24H2 bug.@rashmi you can check Pegasun System Utilities, it is the best tool I used so far, thanks for @roger_m for recommending it, it finds 40 services to optimize on my device in safe mode and 53 services in maximum mode, and there is noticeable performance improvement, but the only issue I found is that it shows my internet disconnected on the settings app while it is not, I couldn't find the service responsible about this to re-enable it.
I think the developer still on Windows 10 (depending on his video tutorial), and this feature (the network & internet connection shortcut on settings app) is just available in Windows 11, so I guess he didn't notice this bug, I'm still on 23H2 so it is not just related to 24H4.I'm experiencing the same issue on my freshly installed system, suggesting it's a Windows 11 24H2 bug.
I reverted to a clean system image, and the settings panel displays internet connection. I'll see if I can identify the problem.I think the developer still on Windows 10 (depending on his video tutorial), and this feature (the network & internet connection shortcut on settings app) is just available in Windows 11, so I guess he didn't notice this bug, I'm still on 23H2 so it is not just related to 24H4.
I could not find the problem. After the clean image backup, the only operations I performed were disabling Windows Services, disabling Microsoft Defender and Firewall, and installing Comodo Firewall. I repeated these operations on a clean system image, and the settings dashboard shows "internet connected."I reverted to a clean system image, and the settings panel displays internet connection. I'll see if I can identify the problem.
Thank you so much @rashmi for your efforts, I think I should contact the developer to fix the issue, anyway the recommended services from you and other members in this thread and the article from @oldschool were very helpful for me, which makes me understand what I'm disabling (or make manual instead of automatic) rather than following 3rd party app blindly (with respect to the app because the issue is not crucial).I could not find the problem. After the clean image backup, the only operations I performed were disabling Windows Services, disabling Microsoft Defender and Firewall, and installing Comodo Firewall. I repeated these operations on a clean system image, and the settings dashboard shows "internet connected."
Yes, manually disabling services is better. Third-party tools might forcefully disable services that display "access denied" error messages.Thank you so much @rashmi for your efforts, I think I should contact the developer to fix the issue, anyway the recommended services from you and other members in this thread and the article from @oldschool were very helpful for me, which makes me understand what I'm disabling (or make manual instead of automatic) rather than following 3rd party app blindly (with respect to the app because the issue is not crucial).

Is this the one?If you want security then OSA System Hardener has a good list of services to disable, paid program but the dev knows what he is doing. Sadly it hasn't been updated in awhile but it's still a good piece of kit.
My machine specs are low; VM will bring it downt ground.@lokamoka820
For extreme configuration :
For windows 10/11, If you use only a pc in a admin account and you have your own media player and you don't use VSC (Visual Studio Code) , with no outside accessories like servers and printer etc.. (no remote) the only thing you need is the NET Framework with sharing port enabled if you use a logical firewall not physical, and a sandbox windows ( available only on a windows pro or higher and want to isolate ONLY third party process that are not signed with a windows certificate accepted in your kernel -> See CertMgr.msc ). Also if you use VMWARE Workstation pro or other virtual Machine and a sandbox is already inside your VM (you don't need Hyper V (can cause a conflict) and windows sandbox anymore).
My recommendation of a local configuration : (without independent soft)
- hyper V enabled (without VMWARE) - Host Guardian Service enabled (if you want to harden your VM on a compatible Os server)
- NET framework (all versions you have) with sharing TCP port enabled
- sandbox windows (Pro - Enterprise) enabled (without Sandboxie or other Sandbox solution like deepfreeze) - Configure your Bios - Virtualisation must be active.