GPO Security Settings Checklist for Windows Active Directory

Jul 27, 2026

Group Policy Objects (GPOs) are one of the most effective ways to enforce consistent security settings across Windows environments. Use this checklist to review and strengthen your Active Directory Group Policy configuration.

Group Policy Objects (GPOs) allow administrators to centrally manage security configurations across Windows devices joined to Active Directory. Properly configured GPO security settings reduce attack surface, enforce organizational policies, and help maintain compliance with security frameworks. This checklist provides a quick reference for reviewing common GPO security settings.

Why GPO Security Settings Matter

Misconfigured Group Policies can expose systems to credential theft, privilege escalation, weak authentication, and unnecessary administrative access. Regularly reviewing security-related GPOs helps maintain a consistent and secure Windows environment.

If you are building a complete Windows hardening baseline, also review our related hardening checklists where applicable.

GPO Security Settings Checklist

Account Policies

  • Configure a strong password policy.
  • Configure password history.
  • Set minimum password length.
  • Set maximum password age.
  • Configure account lockout threshold.
  • Configure account lockout duration.
  • Configure reset account lockout counter.

User Rights Assignment

  • Restrict "Log on locally".
  • Restrict "Log on through Remote Desktop Services".
  • Configure "Deny log on locally".
  • Configure "Deny log on through Remote Desktop Services".
  • Restrict "Access this computer from the network".
  • Configure "Deny access to this computer from the network".
  • Limit "Debug programs" privilege.
  • Restrict "Load and unload device drivers".
  • Limit "Back up files and directories".
  • Limit "Restore files and directories".

Security Options

  • Rename the built-in Administrator account.
  • Disable the Guest account.
  • Disable anonymous SID/Name translation.
  • Disable anonymous enumeration.
  • Enable User Account Control (UAC).
  • Configure LAN Manager authentication level.
  • Require NTLMv2 authentication.
  • Restrict NTLM usage where possible.
  • Enable SMB signing.
  • Disable insecure guest logons.

Audit Policy

  • Enable logon auditing.
  • Enable account management auditing.
  • Enable privilege use auditing.
  • Enable object access auditing.
  • Enable policy change auditing.
  • Enable process creation auditing.
  • Enable account lockout auditing.

Windows Defender Settings

  • Enable Microsoft Defender Antivirus.
  • Enable real-time protection.
  • Enable cloud-delivered protection.
  • Enable tamper protection.
  • Enable attack surface reduction rules.
  • Configure scheduled scans.

Firewall Settings

  • Enable Windows Defender Firewall for all profiles.
  • Configure inbound firewall rules.
  • Configure outbound firewall rules.
  • Enable firewall logging.
  • Restrict unnecessary ports.

Remote Access

  • Disable Remote Assistance if unused.
  • Restrict Remote Desktop access.
  • Require Network Level Authentication (NLA).
  • Disable unnecessary remote management services.

Administrative Templates

  • Disable AutoRun and AutoPlay.
  • Disable consumer experiences.
  • Disable unnecessary telemetry where appropriate.
  • Restrict PowerShell where required.
  • Configure Windows Update policies.
  • Restrict removable storage access.
  • Disable legacy protocols.

Best Practices

  • Create separate GPOs for security baselines.
  • Test GPO changes before production deployment.
  • Use security filtering where appropriate.
  • Use WMI filtering only when necessary.
  • Review GPO inheritance regularly.
  • Document all security-related GPOs.
  • Audit GPO changes periodically.
  • Back up Group Policy Objects regularly.

You may also find these security checklists useful:

Implementing secure GPO security settings helps standardize security controls across your Windows environment while reducing administrative effort. Regular reviews, testing, and ongoing maintenance ensure that Group Policy remains an effective component of your organization's security hardening strategy.

« Back to blog

Optional analytics cookies help us improve Hardenly. They stay off unless you accept. Cookie policy