Yes, Chris, I was just as surprised as you to learn that Microsoft had included, but disabled these strong settings by default due to compatibility concerns. However, I'll quickly explain why here and what potential tradeoffs these may create which you
need to be aware of when supporting systems using them.
First, as I mentioned the DEP setting is typically relatively safe today when used with major name applications, while operating on 64-bit is also generally more stable than it was with the 32-bit versions including Windows XP before the more stable Windows
7 you're supporting.
It's also true that much of the vendor supported software from those like Adobe such as Flash and Reader have improved greatly in the last few years, so this reduces the chance of any issues with enabling DEP, while at the same time reducing or at least
quickly patching any newly discovered vulnerabilities within these applications. Testing all of your required apps on a single machine along with some brief browsing to major sites known to use flash or pdf downloads is usually sufficient to find any potential
issues, but I wouldn't expect any with these or any other major name software at this point.
It's easier to support a newer Windows operating system such as 8.1 that includes the Microsoft tiled Reader app and Flash operating within a sandbox in the browser itself, but I had operated both of these successfully in the past with only the relatively
obvious "update Adobe Flash" and similar social engineering app update prompts to deal with. I can't say how many of these the settings might also protect from, since I personally would never try to install any of these as I know they're all invalid.
As the short article discussing the EPM setting mentions near the end, the ability to run a necessary extension on a trusted website does exist, but this should only be enabled when both a site and the application are truly trusted. Obviously this still
provides an opening for confused users to mistakenly enable something they shouldn't, but since most major vendor's extensions such as Flash have been converted to 64-bit since this article was published, it should be possible to recommend that your users
never allow any of these without your explicit permission.
My general operating rule for my friends and relatives is if you didn't explicitly request something, just say no! It's always safer to return later to install something that's needed than clean up from a malware install, so don't ever accept something
you don't understand or didn't specifically request. This can be a bit of an issue with Windows 7 and Adobe apps like Flash or Reader, but since even valid updates for these can include bundled downloads it may be safer to maintain these yourself than expect
the typical user to do this correctly. Of course, the more you an automate these via settings in the app itself the better.
Finally, the Tracking protection has the most real potential for undesired side effects such as blocking a few websites such as Forbes, which demands that you disable all ad blockers to view it. I personally just avoid these sites, since that's not their
decision to make, but if this becomes a problem you can try and determine whether there's a workaround for the rare few requiring this. Most of the few I've seen have been lesser sites I don't care about, while I only discovered Forbes due to a friend who
likes to include links to their articles on occasion, in which case I usually just search for a similar article title elsewhere.
Note that any engineering or technical choice is always a tradeoff, with some desired result balanced by some possibly less desired side effect. That's the choices you'll need to make with these settings, since these are fundamentally the basis for the
default configurations in later versions of Windows that have included them since their release. This means that both more recent software and website design have already taken them into account, so I'd expect you to have few if any problems with most of
them.
I do on occasion see unexplained lags with some websites which I assume is either related to the ad blocking or possibly my choice of Advanced Privacy Settings to Always block Third-party Cookies, Always prompt First-party, with Always allow session cookies
checked. I didn't mention this last set of settings due to this potential as well as the fact these are really only related to privacy and not security. Possibly changing the First-party setting to Accept might reduce these lags as well as the noise these
prompts create, since this can often cause a delayed popup to display the prompt, but I chose to control the access these have to my browsing history.
Sorry for the length, but as a small organization's administrator I know you'll spend far more time maintaining these systems in the long run. My own history in security consulting for large, medium and small businesses as well as aiding a few friends and
relatives with their personal systems has taught me a just as broad set of relatively simple solutions that along with proper updating and maintenance, can keep most systems safe with a minimum of added work.
Good luck,
Rob