Enable SMB signing to verify the integrity of SMB traffic and reduce the risk of man-in-the-middle attacks against Windows file sharing.
Hardening items
16 recommendations. Filter by category, criticality, maturity tier, or system.
Reduce the risk of the PrintNightmare vulnerability by securing the Windows Print Spooler service, applying security updates, and restricting printer driver installation to trusted administrators.
Disable NetBIOS name resolution to reduce legacy attack surfaces, prevent name spoofing attacks, and encourage secure DNS-based name resolution.
Reduce the attack surface by disabling Internet Explorer and enforcing Microsoft Edge with Internet Explorer mode only for legacy applications when absolutely required.
Reduce security risks by assigning permissions to roles instead of individual users, ensuring consistent least-privilege access across your environment.
Prevent users from copying data to or from removable USB storage devices by enforcing a Group Policy that blocks USB storage drivers.