Windows Central has published a practical, no-nonsense security checklist that finally answers the question every family tech supporter dreads: "Is my PC safe?" The guide, written by a veteran Windows user tired of emergency calls from relatives, consolidates the most impactful Windows 11 settings—from multi-factor authentication to device encryption—into a manageable list that any home user can follow. More than a dry list of toggles, it ties technical steps to real-world threats like tech-support scams and password reuse, making it the sort of document you want to bookmark and send to your parents before they click the next suspicious link.

What’s in the checklist—and why it exists

The Windows Central piece is not about breaking news from Microsoft. Rather, it’s a response to a familiar reality: millions of Windows machines sit in homes where the user knows just enough to get online but not enough to resist a convincing pop-up or a caller claiming to be from “Microsoft support.” The author, after one too many frantic texts, decided to build a baseline security document his family could reference before calling for help.

The result is a focused set of protections that lean heavily on built-in Windows 11 features. The core items include:

  • Windows Hello for passwordless sign-in via PIN, fingerprint, or facial recognition.
  • Windows Update kept active to receive security patches.
  • Windows Security (Defender) real-time protection confirmed and active.
  • Find My Device enabled to locate or lock a lost PC remotely.
  • A Microsoft account with two-factor authentication for account recovery and syncing.
  • Device encryption (or BitLocker) to protect data if the computer is stolen.
  • Switching to a Standard user account for day-to-day use, reserving admin rights for installations.
  • Adopting a password manager to eliminate password reuse.
  • Learning to recognize phishing and scams, and never acting under pressure.

None of these steps require third-party software or a paid subscription, and most can be completed by a motivated relative in under an hour. The checklist is also notable for what it omits: no registry hacks, no Group Policy tweaks, no enterprise-grade intrusion detection. It targets the biggest gaps that real families encounter.

What this means for you

If you’re the designated “computer person” in your extended family, this guide is a godsend. It transforms an endless stream of one-off fixes into a repeatable, copy-pasteable set of instructions. Instead of walking your mother through a complex malware removal procedure after the fact, you can hand her a checklist that prevents the problem in the first place.

For home users who manage their own PCs, the checklist is a self-audit. Many people never touch the security settings that Microsoft ships, either because they don’t know they exist or because they assume Windows takes care of everything. The truth is messier: Windows Defender is excellent, but if a third-party antivirus trial expires and disables it, you’re left unprotected. Device encryption may be off by default on older hardware. And Windows Hello, while convenient, is useless if you keep signing in with a simple password that’s been reused across a dozen breached websites.

The practical impact of following the list is immediate risk reduction. A PC with Windows Hello and a strong PIN is mostly immune to physical password theft. Encryption means that a stolen laptop yields nothing but scrambled data. A password manager prevents the domino effect of credential stuffing. And Find My Device can turn a lost laptop from a catastrophe into a minor inconvenience.

How we got here: a threat landscape that preys on trust

To understand why this checklist is necessary, look no further than the scams it tries to counter. Microsoft itself warns that tech-support fraud is rampant: criminals cold-call victims, spoof caller ID to display “Microsoft,” and convince them to install remote-access tools like AnyDesk or TeamViewer. Once connected, they show fake error messages and charge for nonexistent fixes. According to Microsoft’s advisory, legitimate error messages never include a phone number to call.

Phishing has grown equally sophisticated. Fake browser windows mimic login pages, deceptive emails bypass spam filters, and SMS messages impersonate banks and parcel services. Meanwhile, the password habits of ordinary users remain dire—studies cited by Microsoft Edge’s password check feature suggest roughly 60% of people reuse credentials. When one site is breached, attackers try those same credentials against email, shopping, and bank accounts, a technique known as credential stuffing.

Windows 10’s approaching end-of-life adds another layer of risk. Microsoft ended free security updates for most Windows 10 editions on October 14, 2025. Machines still running Windows 10 are now permanently vulnerable to new exploits unless users pay for Extended Security Updates. For families, this isn’t just a theoretical concern: an unpatched machine doing online banking or storing tax documents is a disaster waiting to happen. Upgrading to Windows 11 and following the checklist is the practical upgrade path.

The Windows Central article didn’t emerge in a vacuum. It’s part of a growing awareness that personal cybersecurity cannot be outsourced entirely to software. Behavioral habits—like pausing when a pop-up screams “call now” or recognizing that Microsoft will never call you first—are just as critical as enabling SmartScreen.

What to do now: a step-by-step plan

1. Lock down the sign-in

Open Settings > Accounts > Sign-in options and set up Windows Hello. Choose whatever method the user will actually stick with: a PIN for almost any PC, a fingerprint if the laptop has a good reader, facial recognition if a compatible infrared camera is present. Reiterate that the PIN is tied to the device, not the Microsoft account, so it’s worthless if stolen elsewhere.

2. Confirm the essentials are running

Go to Settings > Windows Update and click Check for updates. If updates are paused, resume them. A permanently paused update queue is a flashing “welcome” sign for known exploits. Then open Windows Security from the Start menu, select Virus & threat protection, and verify that no warnings appear and real-time protection is on. If a third-party antivirus has expired or interfered, remove it and rely on Defender.

3. Make the lost-device scenario less terrifying

Navigate to Settings > Privacy & security > Find my device and turn it on. This requires a Microsoft account and location services. Remind the user that if the PC is lost, they can go to the Microsoft account dashboard to see its last known location and lock it remotely. Do this now—it’s useless after the fact.

4. Harden the account and enable MFA

If the PC still uses a local account, switch to a Microsoft account via Settings > Accounts > Your info. The Microsoft account enables password reset, sync, and digital license recovery. More importantly, it allows you to activate two-step verification. Visit the Microsoft account security settings online, enable MFA, and add multiple recovery methods: an authenticator app, a backup email, and a phone number. Write down the recovery code and store it in a safe place. Crucially, teach the user that a code from the authenticator app should never be read to anyone over the phone—scammers can use a password reset and a stolen code to lock the owner out completely.

5. Encrypt everything

Go to Settings > Privacy & security > Device encryption and turn it on if available. If your PC runs Windows 11 Pro, you may see BitLocker Drive Encryption; the principle is the same. If the option is missing, open System Information and check Device Encryption Support to see why. On incompatible hardware, consider an upgrade, but don’t panic. The key peril is the recovery key: save it to the Microsoft account, print a copy for the owner, and explain that without it, the drive is inaccessible if the TPM or boot sequence fails.

6. Create a standard daily-use account

Add a new account in Settings > Accounts > Family & other users and set it as Standard user. Then use the original administrator account only for legitimate software installs. This single step prevents malware and unwanted software from gaining admin privileges without an explicit UAC prompt. The elevation prompt becomes a deliberate checkpoint, not a habit to blindly click through.

7. Deploy a password manager

Pick one reputable password manager—NordPass, 1Password, Bitwarden, Proton Pass, or even Microsoft Edge’s built-in manager are all reasonable starting points. Install it on the user’s devices, create a strong master password (and store it in a safe place), and begin replacing the most critical passwords: email, Microsoft account, bank, shopping, mobile carrier. Edge’s password-health check can flag reused or breached credentials. Make it clear that the password manager, not the user’s brain, should be the sole source of truth for passwords going forward.

8. Establish the “Stop. Inspect. Verify.” rule

Technical controls can’t defeat social engineering. Pair the checklist with a behavioral script: If something feels urgent or unexpected, stop. Inspect the sender, the URL, the request. Verify by contacting the entity through a known, independent channel—not the number or link in the suspicious message. The moment someone asks you to install remote-access software because of an unsolicited call or pop-up, end the interaction. Microsoft will never call you. A genuine Windows error message will never include a phone number.

9. Plan for maintenance

Security isn’t a one-off project. Schedule a monthly check of Windows Update and Security dashboard, and a quarterly review of account recovery options and password-manager health. After any scam scare, run a Windows Security scan, look for recently installed remote-access tools, and change passwords for affected services.

Outlook: it’s a habit, not a checklist

The Windows Central guide’s real genius is its recognition that security fails when it’s complicated or preachy. By leaning on built-in tools and clear, jargon-free language, it becomes a document you can actually share with your dad without triggering eye-rolls. The threat landscape will keep shifting—more passkeys, more AI-generated phishing, smarter malware—but the fundamentals remain constant: protected accounts, encrypted devices, updated software, and skeptical users. Microsoft continues to integrate passkeys and refine SmartScreen; attackers will adapt. The families who stay safe will be those who turn this checklist from a project into a habit.

Reference: The original checklist and guidance can be found at Windows Central. For official details on tech-support scams, see Microsoft’s advisory. For more on User Account Control, visit the Microsoft documentation.