Disable NetBIOS name resolution to reduce legacy attack surfaces, prevent name spoofing attacks, and encourage secure DNS-based name resolution.
Endpoint Security
Protect Windows endpoints with Microsoft Defender, Intune, BitLocker, and endpoint security best practices.
Get notified when new items are published
Centrally enforce a secure Chrome baseline across your fleet by deploying Google's ADMX templates through Group Policy — lock down extensions, password saving, and risky flags instead of relying on user discretion.
Prevent users from copying data to or from removable USB storage devices by enforcing a Group Policy that blocks USB storage drivers.
Enforce full disk encryption across the fleet with Group Policy — TPM-backed protection, XTS-AES ciphers, and recovery keys safely escrowed to Active Directory.
Automatically randomize and rotate the local administrator password on every machine, ending the single-shared-password problem that enables domain-wide lateral movement.
Block Office macro abuse, script-based attacks, and credential stealing from LSASS with Defender's built-in ASR rules — free with Windows.