Skip to content

Windows Hardening

Reducing the attack surface of Windows hosts and servers through configuration.

Why It Matters

Default Windows installations prioritize compatibility over security. Hardening closes the gaps attackers rely on (weak authentication, legacy protocols, excessive privilege) and is the configuration side of the same coin as the detection work in a blue team.

Reference

Baselines

Start from a published baseline rather than a blank checklist:

Baseline Source
Microsoft Security Baselines Security Compliance Toolkit
CIS Benchmarks CIS Windows Benchmarks
DISA STIGs DoD STIGs

Key Areas

Area Controls
Accounts Rename and disable default accounts, enforce a strong password policy, use LAPS for local admin passwords
Authentication Disable LM/NTLMv1, require SMB signing, disable SMBv1, disable LLMNR and NetBIOS
Privilege Remove local admin rights, use separate admin accounts, apply least privilege
Attack surface Uninstall unneeded roles and features, disable unused services, host firewall on
Application control AppLocker or WDAC to allowlist executables
Patching Timely updates via WSUS, Intune, or SCCM
Logging Enable advanced audit policy, PowerShell script block logging, and forward to a SIEM
Defender Enable Defender, controlled folder access, and attack surface reduction rules

How I Use It

I apply a CIS or Microsoft baseline through Group Policy or Intune rather than hand-configuring each host, then tune exceptions. The Harden-DomainController and System-Hardening scripts in this toolkit apply a baseline set of these controls, and audit logging ties back to the detection side.

Test baselines before deploying

Security baselines can break legacy applications and protocols. Pilot them on a test group, confirm what breaks, and remediate before a wide rollout.

Resources