Reduce the Exchange Online attack surface by blocking Exchange Web Services (EWS) when it is not required and migrate legitimate application dependencies to Microsoft Graph.
Windows Hardening, GPO & Security Baselines
Apply proven Windows security baselines, Group Policy recommendations, firewall checklists, and Microsoft 365 hardening guides. Track your implementation progress with a personalized security checklist.
Free to browse · No credit card · Your assessment stays private
Choose where to start
Pick the path that best matches your current priority.
Prefer a ready-made checklist? Explore starter packs
Browse by technology
Explore the areas you manage.
Recently added
The newest hardening recommendations across all categories.
Protect privileged administrator accounts from credential phishing and MFA bypass attacks by requiring phishing-resistant authentication methods such as FIDO2 security keys, passkeys, Windows Hello for Business, or certificate-based authentication.
Enable SMB signing to verify the integrity of SMB traffic and reduce the risk of man-in-the-middle attacks against Windows file sharing.
Block legacy authentication protocols that bypass modern security controls such as MFA and Conditional Access to reduce the risk of credential attacks.
Basic, essential — do this before anything else.
Browse first items ThenStrongly recommended once the basics are done.
Browse then items NextAdvanced, future-proof security for mature environments.
Browse next itemsProgress
Track your hardening score
Every completed item counts toward your private assessment dashboard. See how hardened your environment really is — only you and admins can see it.
Roadmap
Build your Zero Trust roadmap
The Board organizes every checklist item into seven Zero Trust pillars, prioritized as First, Then, and Next — work through them in order and watch your coverage grow.
Knowledge
Understand before you apply
The blog explains the concepts behind the checklist — what GPO, ADMX, or LAPS actually are and how to set them up, in plain language.