637 default-decision declared checks • 7 modules • BAVR pattern (Backup-Apply-Verify-Restore)
📥 Quick Start • 📚 Documentation • 🎯 Key Features • 💬 Community
NoID Privacy 2.2.5 interactive PowerShell menu on Windows 11 25H2 · click to enlarge
⚠️ DISCLAIMER: This tool modifies Windows Registry and system state. It seals exact prestate for its declared mutation targets (BAVR pattern), not a full-machine backup. Always create an independent system backup before running. Use at your own risk.
⚠️ CRITICAL: Domain-Joined Systems & System Backup (click to expand)
WARNING: This tool is NOT recommended for production domain-joined systems without AD team coordination!
- This tool writes effective local policy/security state; it does not create or edit AD Group Policy objects
- Domain Group Policy can overwrite overlapping local effective values during startup, sign-in, manual or background refresh
- Your hardening may be reset automatically by domain GPOs
Recommended for: Standalone systems, Home/Personal PCs, VMs, air-gapped systems, test/dev environments.
For Enterprise/Domain Environments: Integrate these settings into your Domain Group Policies instead!
Before running this tool, create:
- Windows System Restore Point (recommended)
- Full System Image/Backup (critical!)
- VM Snapshot (if running in virtual machine)
The tool creates internal backups for rollback (BAVR pattern), but a full system backup protects against unforeseen issues, hardware failures, and configuration conflicts.
Backup Tools: Windows Backup, wbadmin, Macrium Reflect, Acronis, Hyper-V/VMware Snapshots.
What? Microsoft Security Baseline + Advanced Hardening for Windows 11 25H2 How? PowerShell: Backup Apply Verify Restore with exact target-state restoration For whom? Professionals, power users, SMBs without Intune/Active Directory
637 default-decision declared checks • 7 modules • exact BAVR for declared configuration targets
Because security and privacy are inseparable. You can't have one without the other.
🛡️ Security Foundation
- 425 executable targets derived from the MS Security Baseline for Win11 25H2
- 19 Microsoft Edge v139 baseline values + 4 separately labelled privacy additions
- 19 rules: Attack Surface Reduction
- VBS + Credential Guard*: policy configuration for supported hardware/licensing
🔒 Privacy Layer
- DNS: Choose a documented public resolver with Windows DNS-over-HTTPS enforcement; filtering depends on the selected provider
- Telemetry: 3 modes (MSRecommended/Strict/Paranoid)
- AntiAI: 12 reversible AI policy groups (Recall, Copilot compatibility/agents, URI sources, Paint, Notepad, Edge, etc.)
- Bloatware removal is two-tier and explicit about its destructive boundary: policy/registry state restores exactly; sealed Tier 1/Tier 2 app identities enable separate original-user package re-registration with verified Store fallback, but deleted app data cannot be recovered
🎯 The Result: A documented, reversible hardening profile whose declared targets are verified explicitly.
*Microsoft lists Credential Guard edition entitlement for Windows Enterprise and Education; hardware, firmware and licensing requirements still apply.
| SECURITY | PRIVACY | RELIABILITY | SAFETY |
|---|---|---|---|
| Microsoft Baseline 25H2 | AI Policy Hardening | Declared-Scope Verification | Reversible Design |
| 637 default-decision declared checks | Reversible AI policy hardening | Verification accounts for applied, failed and NotChecked targets | BAVR Architecture |
| 19 declared ASR rules (18 Windows-client applicable) | Telemetry & Ads Blocked | Detailed Logging | Exact Pre-State Restore |
| Legacy .lnk path-rule defense-in-depth | DNS-over-HTTPS (DoH) policy | Modular Design | Exact Scoped Pre-State |
| VBS & Credential Guard* | Edge policy hardening | Open Source / Auditable | Release-validated full profile: Windows 11 25H2 |
Full BAVR pattern (Backup → Apply → Verify → Restore) • Windows inbox tools only • native Windows PowerShell 5.1
| Property | NoID Privacy contract |
|---|---|
| Focus | 25H2 baseline-derived profile plus ASR, DNS, Privacy, AntiAI, Edge and AdvancedSecurity |
| BAVR | Backup → Apply → Verify → Restore for every declared configuration target; optional destructive app-removal effects have a separately documented non-exact boundary |
| Verification | Every declared target reconciles to Verified, Failed, NotChecked or NotApplicable |
| Runtime dependencies | Windows PowerShell 5.1 plus Windows inbox cmdlets/tools |
| AI policy scope | 43 typed registry targets plus 4 real URI source-hive checks, filtered by applicability |
🔄 BAVR = Backup-Apply-Verify-Restore (every declared configuration mutation requires sealed prestate and exact scoped verification)
The open-source engine contains no usage telemetry, analytics SDK or license check. Its network-capable paths are explicit and user-scoped: resolver validation/configuration and optional GitHub installer/update downloads. Website behavior is outside this repository's verification scope.
Don't take our word for it — verify: run
netstat -ano(or Wireshark) while the tool runs. NoID sends no telemetry. Network activity is limited to explicitly selected operations: DNS pre-apply queries to the chosen resolver, normal Windows traffic after that resolver is configured, and optional GitHub release/update downloads.
Implements a 425-target profile derived from Microsoft's Windows 11 v25H2 Security Baseline, with documented NoID deviations. The recorded 1,247,155-byte Microsoft package and every parsed identity/type/data item were compared against the embedded profile; RDVDenyWriteAccess (BitLocker USB, 1→0) and SubmitSamplesConsent (Defender sample submission, 3→1 safe samples only) are the two declared data deviations, each restorable to Microsoft's value through its documented Apply choice. See SecurityBaseline provenance and deviations.
- 335 Registry Policies Computer + User Configuration
- 67 Security Template Settings Password Policy, Account Lockout, User Rights, Security Options
- 23 Advanced Audit Policies Exact selected audit-subcategory state
- Credential Guard* Configures VBS-backed isolation of supported credential secrets on entitled, compatible devices
- BitLocker Policies USB drive protection, enhanced PIN, DMA attack prevention
- VBS & HVCI Virtualization-based security
19 declared ASR rules: 16 applicable Block defaults + 2 configurable + 1 Exchange-server-only NotApplicable
- Helps block common ransomware, macro, exploit, and credential theft techniques
- Office/Adobe/Email protection
- Script & executable blocking
- PSExec/WMI: Audit mode (if management tools used), Block otherwise
- New/Unknown Software: Audit mode (if installing untrusted software), Block otherwise
DNS-over-HTTPS with Secure Default (REQUIRE)
- Quad9 (Default) Security-focused, malware blocking, 9.9.9.9
- Cloudflare Unfiltered resolver with documented, independently audited privacy commitments, 1.1.1.1
- AdGuard Ad/tracker blocking built-in
- REQUIRE mode (default): no unencrypted fallback
- ALLOW mode (optional): fallback allowed for VPN/mobile/enterprise networks
- IPv4 + IPv6 dual-stack support
3 Operating Modes
- MSRecommended (Default) least-disruptive selected policy/registry controls; preserves stricter existing app-permission policy
- Strict selected deny/disable controls (AllowTelemetry=0 is effective as Diagnostic Data Off only where the edition supports it; other app-permission policy is preserved)
- Paranoid Broadest declared deny/disable policy set; may disrupt conferencing and other apps that require denied permissions
Features:
- Diagnostic-data policy is set per selected mode; effective level remains edition-dependent
- Two-tier bloatware removal, honest about restore guarantees:
- Tier 1 (opt-in, default No): Microsoft's native
RemoveDefaultMicrosoftStorePackagespolicy, Enterprise/Education Windows 11 24H2/build 26100+ only; its 27 policy values restore exactly, and a sealed original-user inventory feeds the separate non-exact app recovery; deleted data remains unrecoverable; NotApplicable elsewhere - Tier 2 (best-effort, opt-in, default No): classic per-user AppX removal on any edition; separate
Restore-BloatwareAppsfirst re-registers recorded staged package families and uses verified current Store products through winget only as fallback
- Tier 1 (opt-in, default No): Microsoft's native
- HKCU targets apply to the current interactive desktop user; offline profiles remain untouched
- OneDrive feedback/sync-health reporting disabled; existing Personal OneDrive policy is preserved
- App permissions configurable per mode
12 reversible groups are configured and exact owned state is verified
- AppPrivacy Force-denies documented generative-AI app access
- Windows Recall Configures component-availability/snapshot policies and scoped protection policies
- Windows Copilot Legacy/user UI controls + hardware key remap; current MSIX app is not claimed removed
- Click to Do permanent policy applied on documented servicing levels/editions; the feature itself remains Copilot+/eligible-Cloud-PC-only
- Paint AI Cocreator, Generative Fill and Image Creator policies configured; current Paint can retain Generative Erase because Microsoft publishes no corresponding policy
- Notepad AI GPT writing tools disabled on supported Notepad versions
- Settings Agent permanent policy applied on documented servicing levels and commercial editions; runtime presence remains Copilot+-only
Build/edition/Insider/product caveats and the explicit current-Copilot AppLocker gap are tracked in Windows 11 AI applicability.
Privacy target provenance, corrected user/device hives, edition applicability and the exact-state/runtime boundary are tracked in Privacy policy provenance.
Microsoft Edge Security Baseline
- SmartScreen enforced when the documented managed-Windows prerequisite is applicable
- Tracking Prevention strict
- SSL/error-override and legacy-auth policy hardening
- Extension security
- IE Mode restrictions
Beyond Microsoft Baseline
- Legacy SRP .lnk path rules — exact registry configuration only; runtime enforcement is not claimed and Microsoft recommends WDAC/AppLocker
- RDP Hardening — Disabled by default, TLS + NLA enforced
- Wireless Display Security — exact Miracast/Wireless Display policy, service, adapter and firewall state
- Legacy Protocol Hardening — NetBIOS adapter/service/firewall state, LLMNR firewall state, WPAD auto-discovery and PowerShell v2; the Security Baseline separately owns SMBv1 and LLMNR policy targets
- TLS Hardening — disables SCHANNEL TLS 1.0/1.1 client and server state; it does not force-enable later TLS versions
- UPnP/SSDP Blocking — disables selected discovery services and blocks the module-owned traffic rules
- Discovery Protocols — Optional WS-Discovery + mDNS disable (Maximum profile)
- Windows Update — Interactive configuration
- Finger Protocol — module-owned TCP/79 block rules as legacy-protocol defense-in-depth
📖 Detailed Feature Documentation
Every declared mutation must have sealed prestate, an exact target definition, and post-Apply/post-Restore verification.
[1/4] BACKUP Exact prestate for the module-owned targets before changes
[2/4] APPLY Owned targets applied with structured result/error logging
[3/4] VERIFY Automated compliance checks confirm what was applied
[4/4] RESTORE One command restores every sealed target in the selected session
What this means in practice:
- BAVR for all declared settings — every configuration target NoID writes is backed up and re-checkable; opted-in app removal explicitly warns where downstream app/data recovery is not exact
- Fail-closed error handling — advanced functions, structured logs, no successful module result after a failed required target
- Typed restore coverage — owned Registry, service, scheduled-task, DNS, firewall and adapter state
- Runtime contract: Windows PowerShell 5.1 on Windows 11; the release-validated full seven-module profile targets 25H2. Windows 11 26H2 is recognized only as an Experimental Preview and is currently not runtime-validated or release-approved.
Pre-publication client evidence is captured with the Windows 11 release acceptance gate.
Important Limitations:
| Threat | Why Not Protected |
|---|---|
| Social Engineering | If users deliberately bypass all warnings and run malicious files |
| Supply-Chain Attacks | Malware embedded in legitimate signed software |
| Physical Access | Stolen device without BitLocker (use BitLocker!) |
| Nation-State Actors | Sophisticated targeted attacks require enterprise EDR/XDR |
| Zero-Day Exploits | Unknown vulnerabilities not yet patched by Microsoft |
What you need additionally:
- Regular Windows Updates — Critical for security patches
- BitLocker — For lost/stolen device protection
- User Awareness — Don't click suspicious links/attachments
- Backups — 3-2-1 backup strategy for ransomware resilience
NoID Privacy hardens your system significantly, but no security solution provides 100% protection. Defense in depth is always recommended.
Step 1: Open PowerShell as Administrator
- Press
Win + X→ Click "Terminal (Admin)"
Step 2: Run installer
# Download from the exact reviewed repository tag; do not pipe network content to execution.
$installer = Join-Path $env:TEMP 'NoIDPrivacy-install-v2.2.5.ps1'
Invoke-WebRequest -Uri 'https://raw.githubusercontent.com/NexusOne23/noid-privacy/v2.2.5/install.ps1' -OutFile $installer -UseBasicParsing
# Inspect or independently compare this exact local file before executing it.
Get-Content -LiteralPath $installer
& $installerWhat it does:
- Checks Administrator privileges
- Verifies a recognized Windows 11 client profile; the release-validated SecurityBaseline profile targets 25H2, while Windows 11 26H2 is recognized only as an Experimental Preview and is currently not runtime-validated or release-approved
- Resolves an exact tagged release and requires its exact ZIP plus
CHECKSUMS.sha256 - Verifies the ZIP and rejects unsafe archive paths/types/resource bounds before extraction, validates version/syntax/JSON in same-volume staging, then swaps the installation with rollback protection
- Unblocks the staged PowerShell files and starts interactive mode
The installer fails closed if GitHub is unavailable, the tagged assets are ambiguous/missing, the checksum differs, or staged validation fails. It never falls back to an unverified main-branch archive.
The release ZIP is authenticated by its manifest. The bootstrap remains a separate trust boundary, so it is downloaded from an exact tag and inspected or independently verified before local execution; see Security Best Practices.
Alternative - Manual Install:
# 1. Clone repository
git clone https://github.com/NexusOne23/noid-privacy.git
cd noid-privacy
# 2. Run as Admin
.\Start-NoIDPrivacy.bat
# 3. Verify after reboot
.\Tools\Verify-Complete-Hardening.ps1Downloaded ZIP? Run
Start-NoIDPrivacy.bat- it automatically unblocks all files!
繁體中文: NoID Privacy 是 Windows 11 安全與隱私強化框架:630+ 項設定、7 大模組,以 BAVR(備份 → 套用 → 驗證 → 還原)確保每項變更皆可回復。免費、開源(GPL-3.0);商業版 NoID Privacy Pro 提供圖形介面。完整中文介紹請見官網:noid-privacy.com(繁體中文)
简体中文: NoID Privacy 是 Windows 11 安全与隐私加固框架:630+ 项设置、7 大模块,以 BAVR(备份 → 应用 → 验证 → 恢复)确保每项更改均可回退。免费、开源(GPL-3.0);商业版 NoID Privacy Pro 提供图形界面。完整中文介绍请见官网:noid-privacy.com(简体中文)
# Start interactive menu
.\Start-NoIDPrivacy.bat
# Follow prompts:
# 1. Select modules (all or custom)
# 2. Choose settings (DNS provider, Privacy mode, etc.)
# 3. Automatic backup → apply → verify
# 4. Reboot prompt# Apply all modules
.\NoIDPrivacy.ps1 -Module All
# Apply specific module
.\NoIDPrivacy.ps1 -Module Privacy
# Dry-run (no changes)
.\NoIDPrivacy.ps1 -Module All -DryRun# Full verification (active canonical target set)
.\Tools\Verify-Complete-Hardening.ps1
# The report reconciles every declared target into exactly one state:
# Verified, Failed, NotChecked, or NotApplicable.
# Counts are loaded from Config/SettingsCounts.json and module target inventories;
# no hard-coded success count is authoritative.# Restore via the interactive menu
.\Start-NoIDPrivacy.bat
# Select [R] Restore from Backup, then pick a sessionBackup sessions use a collision-resistant visible ID containing timestamp,
milliseconds and a random nonce. They are retained indefinitely: the framework
has no age-, count- or size-based backup cleanup. Every directory found in the
backup root is listed, including renamed, legacy, hidden, damaged and unsealed
folders. A failed pre-Apply backup is detached from the active session, retained
with its own file/hash inventory and labelled Incomplete backup: <module>.
Damaged or incomplete records remain visible with their validation reason, but
never authorize Restore. Only an explicit user deletion outside the framework
can remove a backup directory.
A session restores exactly the targets it sealed, and its scope follows the options chosen in that run: a run that declines an optional target does not back that target up, so a later session can cover less than an earlier one. Restoring a session does not consume it — the same session can be restored again, and the list records when it was last restored.
⚠️ Backup compatibility across versions: Backups created by NoID Privacy 2.2.4 or earlier use the pre-BAVR-v2 format and cannot be restored by 2.2.5 or later (the restore engine rejects them fail-closed before touching any system state — the old backup itself stays intact on disk). If you may still need an old backup, either restore it before upgrading or keep the matching older release around to restore it later. After upgrading, create a fresh backup with the new version; from then on the sealed BAVR-v2 format applies.
Counts below are mirrored from
Config/SettingsCounts.json, the canonical source consumed byTools/Verify-Complete-Hardening.ps1and every module's "Applied N settings" log marker. Update the JSON and the verifier and module reports follow automatically; this table is documentation only.
| Module | Settings | Description | Status |
|---|---|---|---|
| SecurityBaseline | 425 | Microsoft Security Baseline 25H2 | v2.2.5 |
| ASR | 19 | Attack Surface Reduction Rules | v2.2.5 |
| DNS | 5 | Exact IPv4/IPv6 resolver, DoH registration and fallback-policy aggregates | v2.2.5 |
| Privacy | 57 default | Non-relaxing telemetry, OneDrive/Store hardening, and Tier 1 policy-based bloatware removal (30 base + 27 Tier 1 policy values; Strict: 51+27; Paranoid: 77+27 declared targets). Tier 1 restores policy values exactly; both app-removal tiers seal original-user identities for separate local-first/Store-fallback recovery. Deleted app data remains outside BAVR. Tier 2's 25 base app actions plus separately selected Weather/Widgets action are not counted here | v2.2.5 |
| AntiAI | 47 | Reversible AI hardening (43 registry + 4 URI checks across 12 groups) | v2.2.5 |
| EdgeHardening | 23 | 19 Microsoft Edge v139 baseline values + 4 explicit privacy additions; default selects 22; four SmartScreen values are NotApplicable without AD join or eligible Pro/Enterprise MDM registration | v2.2.5 |
| AdvancedSecurity | 61 | Beyond MS Baseline (17 deterministic firewall targets + 44 non-firewall checks; unsupported Home-edition policy/host targets are NotApplicable) | v2.2.5 |
| TOTAL | 637 | All 7 modules with canonical default decisions; actual declared/applicable count varies by mode, edition, build, and explicit selection/skip decisions ¹ | v2.2.5 |
¹ On Windows 11, Microsoft's support matrix makes the Exchange Webshell rule NotApplicable, leaving 18 applicable ASR rules. With a third-party endpoint product as the primary engine, those 18 are NotChecked rather than passed; the other 618 declared checks remain outside ASR. Host-specific NotApplicable and unselected-option NotChecked states remain in the declared total — see Antivirus Compatibility.
Release Highlights:
- v2.2.5: Quality & robustness release — backup/restore symmetry work, exact-BAVR and verification hardening across all seven modules, and CI safety nets (module-GUID validation, canonical count checks and tag checksum generation); release-validated on Windows 11 Pro 25H2. Release evidence is recorded from the exact audited tree; historical pass counts below are not reused as current certification.
- v2.2.4: Third-party endpoint-product detection — ASR is reported Skipped/NotChecked when Defender is not positively proven as the primary active engine (#15)
- v2.2.3: Restore Mode crash fix, Recall snapshot storage verification fix (#14)
- v2.2.2: Firewall snapshot 60-120s → 2-5s (batch query performance fix)
- v2.2.1: Multi-run session bug fix,
.Countproperty bug in 5 files - v2.2.0: Verification coverage extended to all 7 modules (EdgeHardening + AdvancedSecurity added), SRP .lnk protection, RDP/TLS hardening, legacy protocol blocking
📖 Detailed Module Documentation
🔎 Microsoft Edge v139 provenance, exact package hash and deviations
Small/Medium Business (SMB)
- No Active Directory/Intune licenses
- Cloud-first (Microsoft 365, Google Workspace)
- Remote/hybrid work security
- Compliance without enterprise infrastructure
Freelancers & Consultants
- Client data protection
- Secure workstations without domain
- Professional security standards
- Safer experimentation through sealed, module-scoped backups; keep an independent system/image backup for failures outside the declared target scope
Power Users & Privacy-Conscious
- Real security, not just "debloat"
- AI/Telemetry lockdown
- Understand every setting
- Declared-target control plus sealed restore evidence
IT Pros Without Intune
- Standalone Windows 11 hardening
- Microsoft Baseline compliance locally
- Quick deploy for clients
- No domain controller required
Enterprise with Intune/AD
- Use Microsoft Security Baselines with Group Policy instead
Windows 10 or Older
- This tool is designed for recognized Windows 11 client profiles only
Legacy Software Dependencies
- If you rely on unsafe SMB1/RPC/DCOM
Strict MDM Reporting
- If compliance must be centrally reported
NoID Privacy is designed for modern Windows 11 client systems.
NoID Privacy targets current Windows 11 client releases, but application and hardware compatibility still depends on the selected hardening profile:
- OS: The release-validated full seven-module profile targets Windows 11 25H2. The framework recognizes 24H2 for modules with their own 24H2 applicability, but the 25H2 SecurityBaseline module is not admitted there. Windows 11 26H2 is recognized only as an Experimental Preview and is currently not runtime-validated or release-approved.
- CPU: Any CPU on Microsoft's Windows 11 supported processor list (the minimum advances per Windows 11 release; consult that page for the exact list)
- Firmware/TPM: individual hardware-backed protections have different requirements. Secure Boot and virtualization are required for Credential Guard; Microsoft lists TPM as recommended hardware binding there. BitLocker startup behavior depends on its chosen TPM/non-TPM policy. NoID's hardware report separately exposes TPM 2.0, SLAT and query status instead of treating every protection alike
- RAM: 8 GB minimum, 16 GB recommended for VBS
- Admin Rights: Required
- Shell: Windows PowerShell 5.1
Use DryRun and the compatibility report before Apply; official Windows 11 eligibility alone cannot prove that every selected hardening choice fits local applications, peripherals, VPNs or management tooling.
Support profile:
| OS Version | Status |
|---|---|
| Windows 11 25H2 (Build 26200–26299) | Full profile target and current release-validation scope |
| Windows 11 24H2 (Build 26100–26199) | Partial framework profile only; 25H2 SecurityBaseline is rejected |
Windows 11 26H2 official preview (Build 26300–27999 with DisplayVersion=26H2) |
Recognized Experimental preview path; not runtime-validated or release-approved in the current 25H2 gate |
| Windows 11 23H2 or older | ❌ Not Supported |
The AdvancedSecurity and SecurityBaseline modules intentionally disable legacy and insecure protocols:
- TLS 1.0/1.1 (TLS 1.2+ required)
- NetBIOS name resolution, LLMNR, WPAD
- PowerShell v2
- Administrative-share policy can prevent automatic administrative shares after reboot when that choice is selected; existing system-managed C$/ADMIN$ shares are not recreated or deleted live
- NTLMv1/LM authentication (NTLMv2 only)
This can affect very old hardware and software, for example:
- NAS, printers, IP cameras, and IoT devices that only support TLS 1.0/1.1
- Legacy Windows systems (XP, 7) and old Samba implementations
- Old management tools that rely on hidden admin shares
If you still depend on legacy devices, use the built-in BAVR pattern (Backup → Apply → Verify → Restore) to roll back if something breaks.
NoID does not replace or certify an antivirus/EDR product. It queries Windows/Defender state to decide whether the Defender-specific ASR module is applicable:
| Your Setup | NoID Modules Applied | Modules Skipped |
|---|---|---|
| Microsoft Defender as primary engine | All 7 modules — SecurityBaseline, ASR, DNS, Privacy, AntiAI, Edge, AdvancedSecurity | None |
| Third-party endpoint product as primary (any vendor — consumer AV or enterprise EDR/XDR) | 6 modules — SecurityBaseline, DNS, Privacy, AntiAI, Edge, AdvancedSecurity | ASR (see note below) |
Why ASR is Defender-specific: ASR (Attack Surface Reduction) is a set of Microsoft Defender controls. NoID applies its declared targets through Defender's native device-policy values and verifies the resulting effective state with
Get-MpPreference. When Defender is not the primary engine, NoID cannot configure or verify ASR rules.A skipped ASR module makes no statement about the quality or configuration of the other endpoint product. NoID cannot read vendor-specific controls and therefore does not attempt to verify them.
Recommendation if you run a third-party endpoint product: consult your vendor's documentation or management console to confirm equivalent attack-surface-reduction features are enabled. The other 6 NoID modules are unaffected.
When a third-party endpoint product is detected, NoID shows a clear notification:
========================================
ASR Module Skipped
========================================
Third-party endpoint product detected: <Product Name>
ASR (Attack Surface Reduction) is a Microsoft-Defender-specific API and
cannot be configured by NoID when Defender is not the primary engine.
NoID cannot verify vendor-specific attack-surface-reduction controls. Consult the vendor's documentation or
management console to confirm equivalent protections are enabled.
This is NOT an error - ASR will be skipped.
The other modules are not skipped solely because of the endpoint product; their own edition, feature, firewall-controller and user-choice applicability rules still apply.
- PSScriptAnalyzer:
Invoke-ScriptAnalyzer -Path . -Recurse -Settings ./PSScriptAnalyzerSettings.psd1runs in CI on every push and pull request and rejects any Error, Warning or ParseError under the canonicalPSScriptAnalyzerSettings.psd1. The dated 0-finding pass from this release cycle (PSScriptAnalyzer 1.25.0, Windows PowerShell 5.1) is recorded in Release Notes 2.2.5. - Pester Tests:
Tests/UnitandTests/Integrationrun under Pester 5.9.0 in CI on every push and pull request and fail the build on any failure or on an empty run;Tests\Run-AllTests.ps1runs the same suites locally and emits a timestamped NUnit artifact. The dated 479/479 pass from this release cycle (Windows 11 Pro 25H2 build 26200.8737 — 0 failed, 0 skipped, 0 not run) is recorded in Release Notes 2.2.5. - Verification: the complete active target set is checked by
Tools\Verify-Complete-Hardening.ps1 - Structured error reporting and logging on the declared execution paths
- Advanced functions,
CmdletBinding, validated parameters andSupportsShouldProcesswhere exposed mutation helpers use PowerShell confirmation semantics
- Applies the documented 425-target profile derived from the recorded Windows 11 v25H2 baseline package plus the additional NoID modules; all source entries match except the declared
RDVDenyWriteAccess1→0 andSubmitSamplesConsent3→1 decisions - Adds supplemental legacy .lnk path rules while explicitly not claiming complete CVE mitigation or runtime SRP enforcement
- Applies the selected diagnostic-data/privacy controls with edition-aware effectiveness and exact state reporting
- Applies applicable documented AI policy state; it does not claim removal of the current Copilot MSIX app or universal runtime suppression
- Configures BitLocker policies, Credential Guard*, VBS
- Install, replace or certify antivirus/EDR software; ASR configuration runs only with positive Defender-primary evidence
- Create or manage AD/Intune policy objects
- Modify BIOS/UEFI settings
- Guarantee application, peripheral, VPN or management-tool compatibility
- Prevent re-enabling features
- Restored exactly: owned registry values and types, service/task state, firewall state, DNS state, declared AI/Edge targets, and the Tier 1 policy-based bloatware-removal prestate
- AppX safety boundary (Tier 2 only): classic per-user app removal is a best-effort action; winget reinstall cannot reproduce exact prior package/provisioning state, so restore is a separate, explicitly non-exact
Restore-BloatwareAppsstep, never automatic - Backup system: sealed, hashed, target-specific prestate captured before Apply
- Documented operations: module decisions, mutations and failures are written to local operational logs; review logs before sharing
Defaults are an explicit security/usability choice, not a universal compatibility guarantee:
- Services: Telemetry services controlled, critical services protected
- Firewall: Inbound blocked, outbound allowed
- Privacy: MSRecommended applies its least-disruptive non-relaxing target plan; Strict and Paranoid add progressively broader deny policies
- BitLocker: Policies set, user must enable manually
- AI policy targets: applicable subset uses exact typed registry BAVR; inapplicable targets remain untouched, while current Copilot AppX enforcement is explicitly outside this profile
Freeze supported user decisions in config.json; the module JSON files are canonical target inventories and are not casual preference files:
# Review the shipped decision schema, then set options.nonInteractive=true
notepad.exe .\config.jsonMaintainers who change a canonical module inventory must also update applicability, exact backup/apply/verify/restore logic, Config/SettingsCounts.json, provenance and deterministic tests. For a temporary ASR file exception, use the narrow procedure in the Troubleshooting Guide; do not add local paths to ASR-Rules.json.
Common issues and step-by-step fixes — running as Administrator, VBS/Credential Guard, BitLocker, relaxing the ASR rule / SmartScreen that can block software installs, Windows Insider compatibility, and where to find logs — live in the dedicated guide:
Quick pointers:
- "Access Denied" → run PowerShell as Administrator.
- Can't install downloaded software after hardening? → narrow ASR exception and audited compatibility steps. The cleanest reset is the interactive
[R]Restore from Backup menu. - Logs:
Logs/NoIDPrivacy_YYYYMMDD_HHMMSS_fff_<nonce>.log
- Features - Declared settings and decision reference
- Changelog - Version history
- Quick Start - Installation guide (see above)
- Troubleshooting - Common issues & step-by-step fixes
- 💬 Discussions - Questions and ideas
- 🐛 Issues - Bug reports only
- 📚 Documentation - Declared feature reference
- Microsoft Security Baseline Team for Windows 11 25H2 guidance
- PowerShell Community for best practices and patterns
- Open Source Contributors for testing and feedback
| Platform | Link |
|---|---|
| 🌐 Website | NoID-Privacy.com — all platforms, pricing, and docs |
| 🪟 Windows | You're here! |
| 🐧 Linux | NoID Privacy for Linux — read-only Bash posture audit |
| 🏰 Workstation | NoID Privacy Workstation 44 — hardened Fedora 44 / GNOME 50 privacy OS |
| 📱 Android | NoID Privacy for Android — device + Google-account privacy audit |
NoID Privacy is available under a dual-licensing model:
For individuals, researchers, and open-source projects:
This project is licensed under the GNU General Public License v3.0 (GPL-3.0).
✅ You CAN:
- ✔️ Use the software freely for personal and commercial purposes
- ✔️ Modify the source code
- ✔️ Distribute the software
- ✔️ Distribute your modifications
- 📝 Disclose your source code when distributing
- 🔓 License your modifications under GPL v3.0
- 📄 Include the original copyright notice
- 📋 State significant changes made to the software
Read the full GPL v3.0 License
For companies and organizations that want to:
- Integrate this software into closed-source/proprietary products
- Distribute this software without disclosing source code
- Receive dedicated commercial support and warranties
- Avoid GPL v3.0 copyleft requirements
Contact:
- GitHub: 💬 Discussions
This software implements security configurations based on:
- Microsoft Security Baselines - Public documentation
- Microsoft Defender ASR Rules - Official documentation
- DNS Providers - Cloudflare, Quad9, AdGuard (public services)
Microsoft, Windows, and Edge are trademarks of Microsoft Corporation. This project is not affiliated with Microsoft.
This script modifies critical system settings. Use at your own risk. Always:
- Create a system backup before running
- Test in a VM first
- Review the code to understand changes
- Verify compatibility with your environment
The authors are not responsible for any damage or data loss.
Current release: 2.2.5 (Windows 11 Pro 25H2 validated). See the Changelog for the release notes.
Made with 🛡️ for the Windows Security Community
Report Bug · Request Feature · Discussions · Website
⭐ Star this repo if you find it useful!