Enable SMB signing to verify the integrity of SMB traffic and reduce the risk of man-in-the-middle attacks against Windows file sharing.
Hardening items
17 recommendations. Filter by category, criticality, maturity tier, or system.
Block legacy authentication protocols that bypass modern security controls such as MFA and Conditional Access to reduce the risk of credential attacks.
Reduce the risk of the PrintNightmare vulnerability by securing the Windows Print Spooler service, applying security updates, and restricting printer driver installation to trusted administrators.
Synchronize AD password hashes to Microsoft Entra ID to unlock leaked-credential detection, keep cloud sign-in working when on-premises infrastructure fails, and remove your dependency on always-available federation servers.
Enable NTLM auditing to identify legacy applications and systems still relying on NTLM before enforcing restrictions or a move to Kerberos-only authentication.
Mitigate PrintNightmare-class vulnerabilities by disabling the Print Spooler service on domain controllers, since DCs rarely need direct printing functionality.