Most Windows compromises use well-known weaknesses. Reused local administrator passwords, legacy protocols that are still switched on, unpatched software, and accounts with more access than they need account for a large share of incidents. Hardening closes those gaps on purpose instead of leaving them to defaults.
The approach below works for both Group Policy and Intune. Pick a baseline, test it in audit mode, roll it out in rings, and measure drift afterward. Skipping the testing is how hardening projects earn a bad reputation.
Eight steps, in order
- Choose and test a baselineStart from a published baseline instead of writing settings from scratch.
- Microsoft security baselines are recommended settings from Microsoft, delivered through the Security Compliance Toolkit with tools to compare and apply them.
- CIS Benchmarks offer two profiles. Level 1 is a practical starting point. Level 2 is stricter and suits higher-risk systems.
- DISA STIGs are the U.S. Department of Defense baselines. They are stricter and widely used in defence work.
- Choose one primary baseline, document every deviation and the reason, and test on a pilot group before broad rollout.
- Control privileged accessStolen administrator rights turn one compromised laptop into a compromised network.
- Deploy Windows LAPS so every device has a unique, regularly rotated local administrator password.
- Remove everyday users from local Administrators groups.
- Give administrators a separate account for admin work, and keep it off email and web browsing.
- Protect domain administrators with the Protected Users group, tiering, or privileged access workstations.
- Require multi-factor authentication for administrators and for remote access, and limit who can use Remote Desktop.
- Protect credentialsAttackers steal credentials from memory and from the network, so reduce both.
- Turn on Credential Guard on supported hardware, and enable LSA protection.
- Audit NTLM use first, then restrict it as far as your applications allow.
- Require SMB signing, and require LDAP signing and channel binding on domain controllers.
- Confirm WDigest credential caching is off. It is off by default on current Windows, but older settings sometimes override that.
- Find and remove passwords stored in scripts, shares, and configuration files.
- Shrink the attack surfaceEvery service that is on but unused is something an attacker can use.
- Disable SMBv1 everywhere.
- Turn off LLMNR and NetBIOS name resolution where nothing depends on them, because they enable credential capture on local networks.
- Remove PowerShell 2.0, and stop the Print Spooler service on domain controllers and on servers that do not print.
- Never expose Remote Desktop directly to the internet. Put it behind a VPN or a gateway with multi-factor authentication.
- Keep Windows Firewall on for every profile, with inbound connections blocked by default and logging enabled.
- Remove unused roles, features, and software, and review services, scheduled tasks, and startup entries.
- Turn on the built-in endpoint protectionsWindows ships with strong controls that many organizations never enable.
- Run Microsoft Defender Antivirus with cloud-delivered protection and tamper protection on.
- Enable Attack Surface Reduction rules in audit mode first, review the results, then switch the safe ones to block.
- Encrypt laptops with BitLocker, using a TPM and a PIN or an equivalent protector, and require Secure Boot.
- Use App Control for Business, or AppLocker, to allow only approved software. Start in audit mode.
- Keep PowerShell in a constrained mode where administrators do not need full language access.
- Log what mattersYou cannot investigate what you did not record.
- Configure Advanced Audit Policy for logon events, account management, and process creation with command-line auditing.
- Enable PowerShell script block logging and transcription.
- Increase event log sizes from the small defaults.
- Forward events to a central collector or a SIEM, and keep clocks in sync.
- Patch and retireHardening settings do not help an unpatched or unsupported system.
- Test monthly updates in rings, and move through them on a fixed schedule.
- Patch third-party software and firmware, not only Windows.
- Retire unsupported systems. Windows 10 reached end of support on October 14, 2025, so every remaining Windows 10 machine needs a plan.
- Keep an accurate inventory, because you cannot harden devices you do not know about.
- Measure driftSettings drift. Someone changes a policy, a server is built from an old image, a tool needs an exception.
- Re-run baseline comparisons on a schedule, and alert on policy changes.
- Use compliance reporting in your management platform, or an assessment tool such as the Defender secure configuration assessment or CIS-CAT.
- Review every approved exception each quarter and remove the ones you no longer need.
- Record what you chose and why. That record is your evidence for auditors and for the next administrator.
General information, not legal or professional advice. Official documents change, so confirm details with the linked sources before you act.
// firms
Canadian firms that work on this
Firms whose own websites name CIS Controls, NIST 800-171, CCCS baseline or list closely related services. A listing is not an endorsement.
3Tenets Consulting
Penetration testing, AI and LLM security, threat and risk assessment, incident resilience, privacy impact assessment and governance/vCISO services.
- Pen testing
- AppSec
- GRC advisory
- IR and forensics
- Privacy
- NIST CSF
- CIS Controls
- ISO 27001
- MITRE ATT&CK
- OWASP
Canadian Cyber
Toronto firm offering ISO 27001 and SOC 2 consulting, internal audits, audit simulation workshops, virtual CISO services and CIS framework implementation.
- GRC advisory
- Audit and certification
- ISO 27001
- SOC 2
- CIS Controls
CyberHunter Solutions
Penetration testing (web, network, cloud, mobile), threat hunting, protection and monitoring, vulnerability scanning and framework-based security assessments.
- Pen testing
- Vulnerability mgmt
- GRC advisory
- Cloud security
- NIST CSF
- CIS Controls
IRM Consulting & Advisory
Toronto consultancy offering virtual CISO, GRC, AI governance, security architecture, DevSecOps, privacy, penetration testing and awareness training for Canadian and US organizations.
- GRC advisory
- Audit and certification
- Privacy
- Pen testing
- AppSec
- +3
- SOC 2
- ISO 27001
- CMMC
- CIS Controls
- GDPR
- +3
Kobalt.io
Compliance and security firm offering gap assessments, audit readiness, vCISO, penetration testing and incident response, with a fixed-fee CPCSC programme for defence supply-chain vendors.
- GRC advisory
- Audit and certification
- Pen testing
- IR and forensics
- MDR and SOC
- +1
- CPCSC
- CMMC
- NIST 800-171
- SOC 2
- ISO 27001
- +6
Plurilock
Cybersecurity services firm covering adversary simulation, cloud and data protection, identity and compliance readiness, including CPCSC and CMMC readiness for defence suppliers.
- Pen testing
- Red team
- Cloud security
- IAM
- GRC advisory
- +2
- CPCSC
- CMMC
- NIST 800-171
- MITRE ATT&CK
- OWASP
// faq
Common questions
Should I use Group Policy or Intune?
Use whichever manages your devices today. Microsoft publishes baselines for both. The mistake to avoid is applying the same setting from both places and getting conflicts.
Will hardening break our applications?
Sometimes. Legacy protocols such as SMBv1 and NTLM are the usual culprits. That is why we recommend audit mode, a pilot group, and a tracked list of exceptions with an owner and a review date.
Do I need a CIS membership?
The CIS Benchmark documents are available to download after registration. Some assessment tools and build kits are part of a paid membership, so check what you need before you plan around them.
Where do I start if I have no time?
Windows LAPS, multi-factor authentication for administrators, disabling SMBv1, and patching give the most protection for the least effort.
// more hubs
Keep going
CPCSC: Canadian Program for Cyber Security Certification
What the program is, how its three levels work, the 13 Level 1 controls, and how to prepare, drawn from the official government pages.
Small business security baseline
A 90-day plan built on the Canadian Centre for Cyber Security baseline controls for small and medium organizations.
Privacy breach response in Canada
A practical sequence for handling a breach involving personal information, covering PIPEDA and Quebec Law 25 duties.