Security Tools & Accounts

How to Secure a New Windows PC on Day One

A brand-new Windows PC is a clean slate — the perfect moment to set it up securely before the clutter and shortcuts creep in. This day-one checklist covers updates, accounts, backups, and the built-in protections most people never turn on.

· Aug 23, 2026 · updated Aug 21, 2026
How to Secure a New Windows PC on Day One
Illustration generated by AI
Table of contents
  1. 1. Install every update first
  2. 2. Set up the right kind of account
  3. 3. Turn on disk encryption
  4. 4. Confirm the built-in defenses are on
  5. 5. Set up backups before you need them
  6. 6. Clean out what you don't need
  7. 7. Harden your browser and email habits
  8. 8. Adjust privacy settings
  9. 9. Set up "find my device" and a lock screen
  10. Your day-one checklist

A new Windows PC is at its most secure the moment before you start using it — and its safety mostly depends on a handful of choices you make in the first hour. Set it up right on day one and you'll avoid the messy retrofits later. Here's a calm, beginner-friendly checklist, in the order that matters.

1. Install every update first

Before you do anything else, connect to a network you trust and run Windows Update fully, more than once if needed. A fresh device has often been sitting in a box for months, so it can be many security patches behind. Keep going until it reports no more updates, then turn on automatic updates so it stays current on its own. This single step closes the most exploited kind of weakness: known bugs that already have fixes.

2. Set up the right kind of account

How you sign in matters:

  • Create your main account with a strong, unique password — let a password manager generate and store it.
  • Consider using a standard (non-administrator) account for everyday use, with a separate admin account you only use when installing software. If everyday malware runs under a standard account, it can do far less damage.
  • Turn on multi-factor authentication for the online account tied to your PC. If you're unsure which type to pick, here's a primer on multi-factor authentication and which type is safest.

Enable a quick, secure sign-in like a PIN or fingerprint so a strong password doesn't tempt you into a weak one.

3. Turn on disk encryption

If your laptop is lost or stolen, disk encryption means the thief gets an expensive paperweight, not your files. Windows offers built-in device encryption (or BitLocker on some editions). Turn it on and save the recovery key somewhere safe — in your password manager or your online account, not on the machine itself. Without encryption, someone can often read your drive simply by removing it, no password required.

4. Confirm the built-in defenses are on

Modern Windows ships with solid protection already included — you mostly need to confirm it's active:

  • Antivirus / real-time protection (Microsoft Defender) should be on unless you deliberately install another trusted product. You don't need several antivirus tools at once.
  • The firewall should be enabled for all network types.
  • SmartScreen and reputation-based protection help block malicious downloads and sites — leave them on.

For a wider picture of what each tool actually does, see VPN vs antivirus vs password manager: what you need first.

5. Set up backups before you need them

Backups are your safety net against hardware failure, theft, and ransomware. The classic approach: keep copies in more than one place, including one that's offline or in the cloud. This matters because ransomware often starts quietly and a good backup is what lets you recover without paying anyone. Set it up now, while the machine is empty and it's easy, and test that you can actually restore a file.

6. Clean out what you don't need

New PCs often arrive with pre-installed trial software and extras ("bloatware"). Each one is more code that can have bugs and more background activity. Remove anything you won't use. Then be deliberate about what you add:

  • Install apps from official sources — the Microsoft Store or the vendor's real website — not random download portals.
  • Avoid "free" cracked software; it's a classic malware delivery method.
  • Say no to unnecessary browser extensions and toolbars.

7. Harden your browser and email habits

You'll spend most of your time in a browser, so it's worth a minute:

  • Keep the browser set to update automatically.
  • Add only a few reputable extensions and review their permissions.
  • Let the browser and your password manager handle logins so you're not typing passwords into lookalike sites.
  • Stay skeptical of urgent emails and pop-ups; knowing how to spot a scam message or link protects you more than any single setting.

8. Adjust privacy settings

During setup, Windows asks about diagnostics, advertising ID, location, and activity sharing. There are no universally "correct" answers, but reviewing them — rather than clicking through — lets you share only what you're comfortable with. You can revisit these any time under Privacy settings.

9. Set up "find my device" and a lock screen

Turn on the feature that lets you locate or remotely lock your PC if it's lost. Set the screen to lock automatically after a short idle time and require sign-in to wake. A machine that locks itself is protected even when you forget to.

Your day-one checklist

  • Run all Windows Updates; enable automatic updates
  • Strong unique password + MFA; consider a standard daily account
  • Turn on disk encryption and save the recovery key safely
  • Confirm antivirus and firewall are on
  • Set up and test backups
  • Remove bloatware; install only trusted apps
  • Tidy browser extensions and review privacy settings
  • Enable find-my-device and automatic lock

Spend one focused hour on this and your new PC starts life about as safe as a Windows machine can be — and staying that way becomes mostly automatic.