Enforce full disk encryption across the fleet with Group Policy — TPM-backed protection, XTS-AES ciphers, and recovery keys safely escrowed to Active Directory.
Hardening items
16 recommendations. Filter by category, criticality, maturity tier, or system.
The shortlist of Windows security events that actually indicate attacks — logons, privilege use, account changes, and log tampering — and how to collect them.
Default Windows auditing misses the events that matter — deploy Microsoft's recommended Advanced Audit Policy via GPO so logons, privilege use, and account changes are actually recorded.
Directly exposed RDP is the top ransomware entry vector — find every instance, close it now, and move remote access behind VPN/ZTNA, a gateway, or Bastion.
Automatically randomize and rotate the local administrator password on every machine, ending the single-shared-password problem that enables domain-wide lateral movement.
Block Office macro abuse, script-based attacks, and credential stealing from LSASS with Defender's built-in ASR rules — free with Windows.