Deploy Microsoft Defender for Identity sensors on every domain controller to detect reconnaissance, lateral movement, and identity-based attacks in real time.
Hardening items
17 recommendations. Filter by category, criticality, maturity tier, or system.
Move beyond password-only logins by building a phased credential strategy that reduces phishing risk and prepares the organization for passwordless
Reduce the attack surface by disabling Internet Explorer and enforcing Microsoft Edge with Internet Explorer mode only for legacy applications when absolutely required.
Centrally enforce a secure Chrome baseline across your fleet by deploying Google's ADMX templates through Group Policy — lock down extensions, password saving, and risky flags instead of relying on user discretion.
Reduce security risks by assigning permissions to roles instead of individual users, ensuring consistent least-privilege access across your environment.
Prevent users from copying data to or from removable USB storage devices by enforcing a Group Policy that blocks USB storage drivers.