Find storage accounts and buckets with anonymous public access, lock them down, and enforce deny-by-default policies to prevent data leaks.
Hardening items
25 recommendations. Filter by category, criticality, maturity tier, or system.
Block Office macro abuse, script-based attacks, and credential stealing from LSASS with Defender's built-in ASR rules — free with Windows.
Audit your firewall for overly permissive rules and replace them with explicit source, destination, and port definitions.
Enable time-of-click URL scanning and sandbox-based attachment detonation to stop phishing links and malicious files before they reach users.
Require multi-factor authentication for all users and block legacy protocols (IMAP, POP, SMTP AUTH) that bypass MFA entirely.
Remove the legacy SMBv1 protocol and require SMB signing to stop relay attacks and exploits like EternalBlue.