wds hardening

About this tag
WDS hardening refers to Microsoft's security changes for Windows Deployment Services, introduced via KB5074109 for Windows 11. The update begins rolling back a long-standing behavior that could expose sensitive Unattend.xml data to network attackers. It adds telemetry and registry controls, forcing administrators to prioritize security over convenience before April 2026. This is critical for imaging teams and those relying on automated deployments. The tag covers the hardening rollout, associated registry settings, and the broader impact on Windows deployment workflows.
  1. KB5074109 WDS Hardening: Secure by Default Rollout for Windows 11

    Microsoft’s January cumulative update for Windows 11 — delivered as KB5074109 — does more than fix a handful of bugs: it begins a deliberate rollback of a long‑standing, convenience‑focused WDS (Windows Deployment Services) behavior that can expose sensitive Unattend.xml data to adjacent‑network...