Rob, are you suggesting it'd be better security-wise to entrust our systems to Microsoft's offerings? IE has been the greatest security threat to Windows since 9x. Since IE is literally part of the OS, this makes the entire system vulnerable. MS finally had the decency to strip it from Windows, with 10, albeit a few OS's later than it should have.
Anyway, I disagree with you on that. On the contrary, we need a browser like Firefox to protect us from IE's vulnerabilities. ;-) Mozilla now puts out small, incremental updates and quite often sometimes. A recent wk. I had two updates. They're non-intrusive, and you can continue with your browsing. Plus, they don't just start updating, they give you a choice.. ask later or update now.
There are better free, 3rd party apps to take place of some of MS's products, esp when it comes to security. I can see how it would make your job easier, if your clients stick with M$ though. As for Adobe, Flash is still a great security risk and needs replaced. Nothing about that has improved. Then there's that bloated Reader. There's an open source PDF reader, which I use, called Sumatra. All there is to it is the 6 MB executable. Simply brilliant. Well-known doesn't necessarily equal better. Norton's AV is another example of bloated.
Edit: Who needs MS Office, when there are a couple good alts. like LibreOffice and Open Office?
CarolLJ,
In the US it's always better to use any applications built into the Windows operating system, since there's little you can do to remove most of them anyway and adding any 3rd-party apps simply adds to the vulnerabilities as I stated earlier, so there's never a more secure operating system possible than the original installation.
Internet Explorer hasn't been part of the operating system itself since roughly Windows 7, though it was still bundled with the operating system install by default in the US, so unless you took the time to learn how to disable it completely it would remain operating. This meant that adding a 3rd-party browser did nothing itself to improve security, only adding the vulnerabilities it contains to those discovered in Windows and Internet Explorer as well.
Since all currently supported versions of Internet Explorer (e.g. IE11 and Edge on Win10) now contain not only SmartScreen malicious file and phishing protection, but also the hidden improvements which aren't enabled by default which I provided above, these browsers are actually far more secure than any 3rd-party's can possibly be. That's because the Microsoft security apps, especially Windows Defender with Windows 8.1 or 10, are tightly integrated into these browsers as well.
On top of this all of the updating required for not only the operating system, but also the browser and Microsoft provided security are included without any additional effort or knowledge required by the PC owner. This type of integration is required for anyone supporting multiple standalone systems on a sporadic basis like Chris is doing, since he can't always be there to monitor which updates need to be performed and whether they're real or not, since users are often incapable of making these decisions. This also allows him to tell the users not to install anything without his permission, since Microsoft only typically asks when major upgrades take place.
There may be better options for Flash and Reader than Adobe if those are required, but we don't know the policy for these with the system's Chris manages. Personally, if I need these apps I'll use those built-in with Windows 8.1 or 10, only dealing with these for Windows 7, which few people I know have had since the free upgrade to Win10.
I haven't used anything other than the Microsoft free security apps on any system since Microsoft Security Essentials became available, since with the additional settings I've provided, I simply don't need to pay for the 1 or 2 commercial versions that are truly as good as these.
I always avoided the 3rd-party office replacements, since in the past they required Java which is a security nightmare, but I see these now only require that when using the database app. I still prefer to use Office myself, since it's cheap for the small packages or free with OneDrive or Outlook.com anyway and I don't need to worry about any compatibility, update or other maintenance issues. However, I have relatives that simply use the Microsoft freebees now since all they typically do is view things others send them anyway, so no need for another 3rd-party app to maintain.
Anyone like Chris needing to maintain multiple systems needs to keep the situation as simple and limited as possible, since every added program is another support burden and security risk. Individual home users are entirely different than a multiuser situation, since they tend to care about their personal systems more.
That's where my system's administrator and security consultant background comes into play, since I know how business systems are actually treated by users in every environment including businesses such as financial, healthcare, general corporate, government and all levels of education from 4k/elementary to colleges.
In my experience, the strong, self-maintaining security systems I've put in place have meant I rarely if ever deal with actual malware infections, since these are typically blocked with nothing more than a rare notification from the antimalware at worst. My last true infection on a personal system was in 2001, when I was forced to upgrade from Win95 to 2000 due to the side effects. No Windows 7 or later personal system I've installed for friends or relatives has ever had anything worse than the recent modal dialog browser hijacks (e.g. technical support scams).
So if anyone had something that simply running the free MBAM wouldn't easily remove, I'd probably just choose to rebuild the system from scratch, since there's likely something deeper wrong with a system in such a case and I'd rather be certain I removed it permanently.
Rob