In order to access the BIOS and Boot Device selection screen, you need to turn your Tablet OFF by holding the power button while in windows to fake a bad system crash. To meet that you either go with Windows 8, and deal with the whole set of issues that surround it, or you can just go with Windows 1. But not everyone agrees that upgrading will be a priority for businesses. Richard Edwards, principal research analyst for enterprise productivity and mobility at Ovum, said Clearly, theres knowledge of Windows 1. IT departments. But weve not heard from any of our enterprise customers just yet that they have plans to roll out Windows 1. Here is a rundown of the key Windows 1. Enterprise edition features that Microsoft is hoping will persuade businesses to make the switch. Windows 1. 0s new enterprise features Enterprise Data Protection Windows 1. Enterprise Data Protection features, which are to be added to Windows 1. Enterprise at a later date, are designed to help prevent the accidental disclosure of sensitive information. The system will use containerisation file techniques to keep personal and enterprise data separate with minimal impact on the way employees work, according to Microsoft. Additional safeguards will protect sensitive data when it is shared. Its encrypting data as it moves around your organisation. If you send an email to the wrong person, with the wrong file attached and it escapes your organisation, its not going to be readable, its going to be encrypted. But someone inside your organisation would have no problem reading it, Gartners Kleynhans said. Microsoft has also highlighted Windows 1. It will also be able to be used with a mobile device management MDM system to protect corporate data inside Office universal apps. Device Guard. This feature allows devices to be restricted to running only trusted software whether its traditional desktop, Windows store or in house apps. It also makes it much less likely, according to Microsoft, that an attacker who seizes control of the Windows kernel will be able to run malicious code. Device Guard uses the new virtualization based security in Windows 1. Enterprise to isolate the Code Integrity service that controls the process from the Microsoft Windows kernel itself, letting the service use signatures defined by enterprise controlled policy to determine what is trustworthy. You can lock the operating system to that piece of hardware, and nothing else could ever boot on that piece of hardware, Gartners Kleynhans said. You can make it so that it would be very hard, if not impossible, to wipe and reload a machine with something else. Microsoft says this whitelisting approach will be effective in stopping malware from being run on machines, particularly software that alters its code to prevent detection by anti virus software. Using technology embedded in the hardware and virtualization to sandbox the Code Integrity service will also help foil exploits that compromise Windows at the kernel level, and which can tamper with traditional virus and malware countermeasures. Device Guard requires various hardware features and software settings UEFI 2. Virtualization Extensions such as Intel VT x, AMD V, and SLAT must be enabled x. Windows IOMMU, such as Intel VT d, AMD Vi TPM 2. Acer Bios Key Windows 10' title='Acer Bios Key Windows 10' />BIOS lockdown. HP, Acer, Lenovo, Toshiba, Fujitsu and others will manufacture systems designed for the new Microsoft security controls. Provisioning packages This feature allows Window 1. OS. IT admins can configure provisioning package rules that determine the look of the OS, what apps and certificates should be installed, that enroll devices with an MDM suite, set out user rights and more. The same provisioning package rules can be used to configure multiple machines and can be applied to either a Windows image or running Windows machine via SD card, USB drive or network share. Packages are created using the Imaging and Configuration Designer, part of the new Windows 1. Assessment and Deployment Kit. Microsoft Passport Microsoft Passport provides a system for allowing users to log into Windows 1. PIN. This same scan or PIN can then be used to log into Microsoft, Active Directory or Azure Active Directory accounts, as well as many non Microsoft services that support Fast ID Online authentication including Office. Exchange Online, Salesforce, Citrix, Box and Concur. Microsoft says Passport provides both convenience, in that the user has to remember fewer credentials, and security, because no passwords are used. Credential Guard Credential Guard will offer additional security for login details by storing derived credentials NTLM hashes and Kerberos tickets and the process that manages them in a secured isolated container that uses Hyper V and virtualization based security. It will require UEFI 2. Virtualization Extensions such as Intel VT x, AMD V, and SLAT must be enabled x. Windows IOMMU, such as Intel VT d, AMD Vi TPM 2. BIOS. Deployment features. Sideloading apps Sideloading allows certain Windows Store apps, which firms dont want to publish and make publicly available, to be installed on Windows machines. This practice of sideloading is useful when a firm wants to deploy line of business apps internally. Sideloading is a built in capability with Windows 1. Home, Pro and Enterprise users. If an organisation is developing its own set of corporate apps that it wishes to push out to employees, clearly there is some inherent business value in Windows 1. Ovums Edwards. Mobile Device Management Phones, tablets and other devices running Windows 1. IT. Windows 1. 0 machines can connect to a Mobile Device Management MDM server that will enroll and configure the devices, as well as applying updates and enforcing the latest in house policies governing usage. An MDM package can be used both to manage Windows 1.