Enforce full disk encryption across the fleet with Group Policy — TPM-backed protection, XTS-AES ciphers, and recovery keys safely escrowed to Active Directory.
Hardening items
41 recommendations. Filter by category, criticality, maturity tier, or system.
Build practical, low-noise detection rules for password attacks and lateral movement — thresholds, correlation logic, and tuning against false positives.
The shortlist of Windows security events that actually indicate attacks — logons, privilege use, account changes, and log tampering — and how to collect them.
Default Windows auditing misses the events that matter — deploy Microsoft's recommended Advanced Audit Policy via GPO so logons, privilege use, and account changes are actually recorded.
Directly exposed RDP is the top ransomware entry vector — find every instance, close it now, and move remote access behind VPN/ZTNA, a gateway, or Bastion.
Automatically randomize and rotate the local administrator password on every machine, ending the single-shared-password problem that enables domain-wide lateral movement.