Software King of the World Microsoft wants Windows 11 to start behaving more like your phone, complete with pop-ups asking if apps can poke around your files and camera.
The plan centres on Windows Baseline Security Mode and a broader push called User Transparency and Consent, aimed at tightening control across more than one billion Windows devices.
Microsoft, Windows Platform engineer, Logan Iyer said the shift comes after apps increasingly override settings, install unwanted software or tweak core Windows experiences without asking first.
Under the new model, Windows will prompt users when applications attempt to access sensitive resources, such as the file system, camera, or microphone, or when they attempt to install additional software.
Iyer said: “Just like they do today on their mobile phones, users will be able to clearly see which apps have access to sensitive resources, including file system, devices like camera and microphone, and others. If they see an app that they don’t recognise, they will be able to revoke access.”
“Users will have transparency and consent control over how apps access their personal data and device features. They will receive clear prompts to grant or deny apps permission to access protected data and hardware. Users will also be able to revoke permissions they have previously granted.”
Windows Baseline Security Mode will switch on runtime integrity safeguards by default, meaning only properly signed apps, services and drivers can run.
Users and IT administrators will still be able to override those safeguards for specific applications, which suggests Microsoft knows full well someone will complain.
The rollout will be phased and developed “in close partnership” with developers, enterprises and ecosystem partners, with Microsoft promising to tweak controls based on feedback.
The changes are part of Microsoft’s Secure Future Initiative, launched in November 2023 after the US Department of Homeland Security’s Cyber Safety Review Board described the company’s security culture as “inadequate.”
That report followed an Exchange Online breach by Storm-0558 Chinese hackers, who stole a Microsoft consumer signing key in May 2023 and used it to access Microsoft cloud services.
Since then, Microsoft has moved to secure Entra ID sign-ins against script-injection attacks, disabled ActiveX controls in Microsoft 365 and Office 2024 Windows apps, and updated Microsoft 365 defaults to block legacy authentication for SharePoint, OneDrive and Office files.
Iyer said, “Apps and AI agents will also be expected to meet higher transparency standards, giving both users and IT administrators better visibility into their behaviours. These updates raise the bar for security and privacy on Windows, while giving you more control and confidence in how your system and data are accessed.”







