Enable SMB signing to verify the integrity of SMB traffic and reduce the risk of man-in-the-middle attacks against Windows file sharing.
Hardening items
16 recommendations. Filter by category, criticality, maturity tier, or system.
Reduce the risk of the PrintNightmare vulnerability by securing the Windows Print Spooler service, applying security updates, and restricting printer driver installation to trusted administrators.
Disable NetBIOS name resolution to reduce legacy attack surfaces, prevent name spoofing attacks, and encourage secure DNS-based name resolution.
Reduce the attack surface by disabling Internet Explorer and enforcing Microsoft Edge with Internet Explorer mode only for legacy applications when absolutely required.
Centrally enforce a secure Chrome baseline across your fleet by deploying Google's ADMX templates through Group Policy — lock down extensions, password saving, and risky flags instead of relying on user discretion.
Prevent users from copying data to or from removable USB storage devices by enforcing a Group Policy that blocks USB storage drivers.