Find storage accounts and buckets with anonymous public access, lock them down, and enforce deny-by-default policies to prevent data leaks.
Hardening items
41 recommendations. Filter by category, criticality, maturity tier, or system.
Block Office macro abuse, script-based attacks, and credential stealing from LSASS with Defender's built-in ASR rules — free with Windows.
Block unauthorized executables, scripts, and installers by allowlisting trusted applications with AppLocker or Windows Defender Application Control.
Separate servers, clients, management interfaces, and IoT/OT devices into VLANs with inter-VLAN firewall rules to contain lateral movement.
Audit your firewall for overly permissive rules and replace them with explicit source, destination, and port definitions.
Enable time-of-click URL scanning and sandbox-based attachment detonation to stop phishing links and malicious files before they reach users.