Require multi-factor authentication for all users and block legacy protocols (IMAP, POP, SMTP AUTH) that bypass MFA entirely.
Hardening items
41 recommendations. Filter by category, criticality, maturity tier, or system.
Enforce MFA and Block Legacy Authentication with Conditional Access
TrackUpdated Jul 9, 2026Microsoft 365 · Microsoft Entra ID · Microsoft Exchange Online
Deploy Privileged Access Workstations (PAW) for Tier 0 Administration
TrackGive Domain Admins and other Tier 0 operators a dedicated, locked-down workstation that never touches email, browsing, or productivity apps.
Updated Jul 9, 2026Microsoft Windows 10/11 · Microsoft Active Directory · Microsoft Entra ID
Implement the Active Directory Tiered Administration Model (Tier 0/1/2)
TrackSeparate Domain Admin, server admin, and workstation admin credentials into isolated tiers to block lateral movement and privilege escalation.
Updated Jul 9, 2026Microsoft Active Directory · Microsoft Windows Server
Disable SMBv1 and Enforce SMB Signing via Group Policy
TrackRemove the legacy SMBv1 protocol and require SMB signing to stop relay attacks and exploits like EternalBlue.
Updated Jul 9, 2026Microsoft Windows Server · Microsoft Windows 10/11 · GPO
Enable LSA Protection and Credential Guard to Prevent Credential Theft
TrackProtect LSASS from memory dumping and credential theft attacks like Mimikatz by enforcing LSA Protection (RunAsPPL) and Credential Guard.
Updated Jul 9, 2026Microsoft Windows Server · Microsoft Windows 10/11