Prevent users from downloading email attachments to unmanaged or untrusted devices to reduce the risk of data leakage and unauthorized file distribution.
Hardening items
41 recommendations. Filter by category, criticality, maturity tier, or system.
Synchronize AD password hashes to Microsoft Entra ID to unlock leaked-credential detection, keep cloud sign-in working when on-premises infrastructure fails, and remove your dependency on always-available federation servers.
Enable NTLM auditing to identify legacy applications and systems still relying on NTLM before enforcing restrictions or a move to Kerberos-only authentication.
Mitigate PrintNightmare-class vulnerabilities by disabling the Print Spooler service on domain controllers, since DCs rarely need direct printing functionality.
Deploy Microsoft Defender for Identity sensors on every domain controller to detect reconnaissance, lateral movement, and identity-based attacks in real time.
Move beyond password-only logins by building a phased credential strategy that reduces phishing risk and prepares the organization for passwordless