Headlines refreshed Sun Oct 11, 11:45 AM ET (1 h ago) · content checked against vendor docs
▣ Windows Server security
Windows Server, locked down.
Windows Server runs the keys to the kingdom: Active Directory, file shares, certificates, and remote access. This guide covers the hardening that matters most on Server 2022 and 2025, from baselines to protocol lockdown to logging. Server 2025 has safer defaults than 2022, so we call out where the two differ. Test every change on one server first, then roll it out.
Pick one security baseline and treat it as the standard
admin
Hundreds of settings affect security. A published baseline gives you a tested starting point, so you don't have to set each one by hand.
Choose one master baseline: Microsoft's (from the Security Compliance Toolkit), CIS, or DISA STIG. Import it as GPOs into a test OU, fix what breaks, then link it to production. Write down every deviation and why. Don't stack two baselines blindly, because they conflict.
On Server 2025, apply the OSConfig baseline that matches the server's role
admin
OSConfig applies 300+ settings in one command, and drift control puts them back if something changes them. Server 2022 and earlier are not supported.
In an elevated PowerShell, install the Microsoft.OSConfig module. Apply the scenario for the role: SecurityBaseline/WindowsServer/2025/DomainController, MemberServer, or WorkgroupMember. Restart. On member servers and workgroup members you must change the local admin password (14+ characters). Expect TLS 1.2 minimum, SMB 3.0 minimum, and file copy from RDP sessions turned off. If GPO also sets the same values differently, the two will fight, so remove one source.
Check — read-only
Get-OSConfigDesiredConfiguration -Scenario SecurityBaseline/WindowsServer/2025/MemberServer | ft Name, @{ Name = "Status"; Expression={$_.Compliance.Status} }, @{ Name = "Reason"; Expression={$_.Compliance.Reason} } -AutoSize -Wrap
Baselines ship inside the OSConfig module. A newer module brings a newer baseline, which replaces the old one in full. The current version covers 344 settings on member servers, 347 on domain controllers, and 319 on workgroup members.
Check the installed module version. Update the module, then reapply the same scenario. If an earlier baseline is applied, you'll be asked to remove it first; confirm. Restart when done.
Compare GPOs against the baseline with Policy Analyzer before you deploy
power user
Policy Analyzer shows conflicts, duplicates, and differences between GPOs, the baseline, and a server's current local policy. You see what will change before it changes.
Download Policy Analyzer from the Security Compliance Toolkit. Load the Microsoft baseline and your existing GPO backups. Review the differences and settle each conflict on purpose.
Use CIS Benchmarks or DISA STIGs when an auditor or contract requires them
admin
Many audits and government contracts name CIS or STIG directly. Using the named standard saves arguing over equivalence later.
Download the Windows Server benchmark for your version from CIS (Server 2022 and 2025 are both published), or the Windows Server STIG from DISA. Apply it through GPO in a test OU first. Keep a record of exceptions with a business reason for each.
STIGs are the DoD's required configurations. They're free and detailed, and each one has a check and a fix.
Get the Windows Server 2022 or 2025 STIG and the matching GPO package from DISA's STIG library. Use STIG Viewer to track each finding. Apply through GPO in test first.
Server Core has no desktop shell, so there's less code to attack and less to patch. Microsoft rates its attack surface as greatly reduced compared with Desktop Experience.
Pick Server Core at install time for DCs, DNS, DHCP, file, and Hyper-V hosts. Manage the server remotely with Windows Admin Center, PowerShell remoting, or RSAT. You can't convert between Server Core and Desktop Experience after install, so decide up front.
Patch every month and fast-track known-exploited bugs
everyone
Attackers go after flaws that are already public. CISA's Known Exploited Vulnerabilities list shows which ones are being used right now.
Install the monthly cumulative update within days, not weeks. Check the CISA KEV catalog and patch anything on it first. Confirm each server actually installed the update.
Hotpatch installs security fixes into running memory, so most months need no reboot. Servers are no longer left unpatched while waiting for a maintenance window.
Connect Server 2025 Standard or Datacenter to Azure Arc and turn on Hotpatch. Microsoft now offers Arc-enabled Hotpatch for Server 2025 at no extra cost. A baseline cumulative update still needs a reboot every three months. Non-security updates, .NET, and drivers or firmware still go through normal patching.
Keep Windows Firewall on for every profile and block inbound by default
power user
A default-deny firewall means only ports you meant to open are reachable. The Server 2025 baseline does exactly this.
Turn on the Domain, Private, and Public profiles. Set the default inbound action to Block. Add allow rules only for what the server's role needs, scoped to the source subnets that need it.
These old broadcast protocols let anyone on the network answer name lookups and collect credential hashes, which is what tools like Responder do. DNS is all you need.
In GPO, enable Computer Configuration > Administrative Templates > Network > DNS Client > Turn off multicast name resolution. Turn off NetBIOS over TCP/IP on each network adapter, or use DHCP options. The Server 2025 OSConfig baseline does both.
If a Domain Admin signs in to a workstation that's already compromised, the whole domain falls. Tiering keeps top-level credentials off lower-trust machines.
Treat DCs, AD FS, AD CS, and Microsoft Entra Connect servers as Tier 0. Give each admin separate accounts per tier, and never use one for email or browsing. Use GPO 'Deny log on' user rights to block Tier 0 accounts from lower-tier servers and workstations. Keep Domain Admins as small as possible.
Run Tier 0 administration from privileged access workstations (PAWs)
admin
An admin's own machine is the easiest way in. A dedicated, locked-down workstation with no email or web browsing removes that path.
Build PAWs from a clean, hardened image with TPM 2.0, Secure Boot, BitLocker, and app control. Block general web browsing and email on them. Allow Tier 0 servers to accept admin connections only from PAWs, using firewall rules and logon rights.
Members can't use NTLM, or DES or RC4 in Kerberos pre-authentication, their credentials aren't cached, and their Kerberos tickets can't be renewed past four hours. This blunts pass-the-hash and offline cracking.
Add individual admin user accounts, one or two at a time. Never add service or computer accounts, because their authentication will fail. Check that RDP, tools, and scripts still work before adding the next. The domain functional level must be Windows Server 2012 R2 or higher.
Mark admin accounts 'sensitive and cannot be delegated'
admin
By default, any AD account can be delegated. This flag stops a compromised server with delegation rights from impersonating your admins elsewhere.
Set 'Account is sensitive and cannot be delegated' on every privileged user account. Check service accounts separately before you flag them, since some apps need delegation.
Use Windows LAPS for every server's local admin password
admin
When every server shares one local admin password, an attacker who steals it can reach all of them. Windows LAPS gives each server its own rotating password, and it's built in.
Extend the schema once per forest with Update-LapsADSchema. Give servers rights to write their own passwords on their OU. Turn on LAPS through GPO, or on Server 2025 member servers through the OSConfig LAPS scenario. Turn on password encryption, and limit who can read the passwords.
Use Just Enough Administration (JEA) for routine tasks
admin
Help desk and app owners often get full admin rights just to restart a service. JEA gives them only the commands they need, runs them under a temporary virtual account, and keeps transcripts of what they ran.
Write a role capability file listing the allowed cmdlets. Write a session configuration that maps AD groups to that role and runs as a virtual account. Register it, then have users connect with Enter-PSSession -ConfigurationName.
Use Credential Guard on member servers, but not on domain controllers
admin
Credential Guard isolates NTLM hashes and Kerberos tickets inside virtualization-based security (VBS), out of reach of admin-level malware. Microsoft says it adds nothing on DCs and can break apps there.
On Server 2025 it's on by default for domain-joined non-DC servers that meet the requirements. On 2022, turn it on through GPO: Computer Configuration > Administrative Templates > System > Device Guard > Turn On Virtualization Based Security, then set Credential Guard Configuration. Hyper-V VMs must be Generation 2. Check that apps don't need NTLMv1, Kerberos DES, or unconstrained delegation. Don't turn it on for Exchange Server, which isn't supported.
LSA protection blocks untrusted code from reading or injecting into LSASS memory, which is where credential-dumping tools go.
Run audit mode first, as the doc describes, to find LSA plug-ins or drivers that would be blocked. Then turn it on through GPO or the registry value below, and restart. Value 1 also sets a UEFI variable, which makes it harder to turn off later; value 2 skips the UEFI lock and is enforced only on newer builds (Windows 11 22H2 and later). Use GPO across the fleet.
RC4-encrypted Kerberos tickets are much easier to crack offline. Accounts explicitly set to allow only DES or RC4 stay weak even after Microsoft's updates.
Find accounts that allow DES or RC4 but not AES, and fix them. Watch the System log on DCs for KDC event 42 (account lacks strong keys) and event 27 (no common encryption type). Once clean, set DefaultDomainSupportedEncTypes on DCs to 0x38, which Microsoft recommends where RC4 isn't used. Test first, because old non-Windows devices may fail.
NTLM enables relay and pass-the-hash attacks. Server 2025 has removed NTLMv1, and Microsoft is phasing out NTLM altogether.
Turn on these GPO audit settings first: 'Network security: Restrict NTLM: Audit Incoming NTLM Traffic' on all servers, 'Network security: Restrict NTLM: Audit NTLM authentication in this domain' on DCs, and 'Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers' set to Audit all. Read the Microsoft-Windows-NTLM/Operational log to find what still uses NTLM. Move those apps to Kerberos, then deny NTLM server by server. On 2022, set 'Network security: LAN Manager authentication level' to 'Send NTLMv2 response only. Refuse LM & NTLM' (LmCompatibilityLevel 5).
SMBv1 has no modern protections and was the route WannaCry used. It also lets attackers downgrade encrypted SMB sessions to unencrypted access.
SMBv1 isn't installed by default on Server 2019 and later, so on 2022 and 2025 confirm it stayed that way. If it's present (for example on an upgraded server), remove it. Before you do, find and replace old devices that need it, such as old copiers and NAS boxes, instead of reinstalling SMBv1.
Require SMB signing for both inbound and outbound connections
power user
Signing stops relay and spoofing attacks on file traffic. Server 2025 requires it for outbound connections only, so you must set inbound yourself, and on Server 2022 set both.
Set RequireSecuritySignature to True on the server and client side, through GPO ('Microsoft network server: Digitally sign communications (always)' and the matching client setting) or PowerShell. Signing also stops guest access to third-party devices. Fix any third-party NAS so it allows signing instead of turning signing off.
SMB encryption protects data in transit end to end, even across networks you don't control. You don't need IPsec for it.
Turn on encryption for each sensitive share, or for the whole server. Leave RejectUnencryptedAccess at its default of True so only encryption-capable SMB 3.x clients get in. Disable SMBv1 too, because RejectUnencryptedAccess doesn't stop a downgrade to SMB 1.0. Expect a small performance cost.
Unsigned LDAP binds can be tampered with or relayed. New Server 2025 deployments require signing by default. Server 2022 and earlier don't.
Watch Directory Service events 2886-2889 to find clients making unsigned or clear-text binds. Set the '16 LDAP Interface Events' diagnostic level to 2 to get per-client event 2889, and turn it back down afterward. Fix those clients, then set 'Domain controller: LDAP server signing requirements' to Require signing. Upgraded environments can keep their old policy, so check them.
Channel binding ties a login to its TLS session, which shuts off NTLM relay over LDAPS. New Server 2025 deployments default to 'When supported'. Server 2022 and earlier default to 'Never'.
On 2022, first set 'Domain controller: LDAP server channel binding token requirements' to When supported (LdapEnforceChannelBinding = 1), because events 3039, 3074, and 3075 are only logged at 1 or 2. Set diagnostic level 2 to get 3074 and 3075. Update or replace clients those events name. Then set the policy to Always (LdapEnforceChannelBinding = 2).
6. Harden Active Directory Certificate Services (AD CS)
Confirm every DC is in Full Enforcement for certificate mapping
admin
Weak certificate mapping let attackers sign in as other users with a crafted certificate. Microsoft moved DCs to Full Enforcement in February 2025, and from the September 9, 2025 update the StrongCertificateBindingEnforcement registry key is no longer supported, so there's no way back to Compatibility mode.
Make sure every DC has the September 2025 or later cumulative update. Remove any leftover StrongCertificateBindingEnforcement value so nobody assumes it still does something. Fix certificates that KDC events 39, 40, or 41 flag, which usually means reissuing them with the SID extension or adding a strong mapping.
Fix certificate templates that let requesters choose the subject
admin
A template that allows client authentication and 'Supply in the request' lets any enrollee get a certificate for any user, including a Domain Admin (ESC1).
Review every published template. Where a template allows client authentication, clear 'Supply in the request', or require CA manager approval. Remove enrollment rights for unprivileged users. Unpublish templates nobody uses. Defender for Identity flags these templates as a posture finding.
Attackers can relay NTLM to the CA's web enrollment pages (PetitPotam) to get a certificate for a DC. Microsoft published specific fixes for this.
The strongest fix is to disable NTLM on AD CS servers with 'Network security: Restrict NTLM: Incoming NTLM traffic'. Where Web Enrollment or the Certificate Enrollment Web Service is in use, set Extended Protection for Authentication to Required in IIS, turn on Require SSL, set Windows authentication to Negotiate:Kerberos, and restart IIS. Treat CA servers as Tier 0.
On Server 2025, deploy the App Control default policy in audit mode first
admin
App Control for Business allows only trusted code to run, which stops most malware and attacker tools. Server 2025 ships a ready-made Microsoft policy you apply with OSConfig.
Install OSConfig. Apply the DefaultPolicy and AppBlockList scenarios in Audit mode. Watch CodeIntegrity/Operational event 3076 for what would have been blocked. Turn those events into supplemental policies with the App Control Wizard (Convert Event Logs to a Policy). Switch to Enforce only when 3076 events stop. The server must run a production-signed build; flight-signed binaries aren't permitted and the device won't start.
On Server 2022, build App Control policies with the App Control Wizard
admin
Server 2022 has no OSConfig, but App Control works there too. Locked-down single-role servers like DCs are a good fit.
Start from a Microsoft example base policy in the App Control Wizard. Deploy it in audit mode, collect events, add rules for legitimate software, then enforce. Roll it out one role at a time.
Keep Microsoft Defender Antivirus active and current
everyone
Real-time protection and fresh signatures catch commodity malware. Server 2025 has its own OSConfig Defender baseline.
Confirm Defender is in Normal mode with real-time protection on and signatures updated today. On Server 2025, apply the Defender/Antivirus/WindowsServer/2025 OSConfig scenario. If you run a third-party antivirus, confirm it's actually active.
Turn on attack surface reduction (ASR) rules, starting in audit mode
admin
ASR rules block common attack behaviors, such as WMI persistence, PsExec and WMI process launches, and dropping vulnerable signed drivers. They need Microsoft Defender Antivirus.
Start with 'Block persistence through WMI event subscription' in AuditMode. Review the events, then switch it to Enabled. Add more rules from the reference list the same way. Skip the LSASS credential-stealing rule where LSA protection is on, because Microsoft says it adds nothing there.
Use advanced audit policy and force subcategory settings
admin
The default audit settings miss logons, account changes, and privilege use. Without those, you can't reconstruct an incident.
In GPO, configure Advanced Audit Policy Configuration using Microsoft's recommendations. Enable 'Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings' so old category-level settings don't override them. Cover credential validation, account management, logon, and sensitive privilege use, for both success and failure.
Event 4688 with the command line shows exactly what an attacker ran. The Server 2025 baseline turns it on.
Turn on 'Audit Process Creation' (Success). Then enable the GPO 'Include command line in process creation events' under Computer Configuration > Administrative Templates > System > Audit Process Creation.
Attackers lean on PowerShell. Script block logging records the scripts and commands that actually ran, as event 4104.
In GPO, enable Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell > Turn on PowerShell Script Block Logging. Forward the Microsoft-Windows-PowerShell/Operational log to your SIEM. Consider module logging and transcription as well.
Size the Security log properly and send logs off the server
power user
A small log rolls over in hours, and an attacker with admin rights can clear a local log. The Server 2025 baseline sets the Security log to at least 192 MB.
Raise the Security log to at least 192 MB. Forward events with Windows Event Forwarding or a SIEM agent, so a copy lives somewhere the attacker can't reach.
Sysmon adds detail Windows doesn't log by default: process hashes, network connections, LSASS access, WMI persistence, and DNS queries.
Download Sysmon from Sysinternals. Install it with a configuration file that filters out noise, because the defaults are either too quiet or too loud. Forward Microsoft-Windows-Sysmon/Operational to your SIEM. Update the configuration with sysmon64 -c <file>.
Put Microsoft Defender for Identity on every Tier 0 server
admin
MDI watches DC traffic and events for things like Kerberoasting, DCSync, and lateral movement. It also flags AD and AD CS posture problems.
If you're licensed, activate the v3.x sensor. It needs Server 2019 or later with a recent cumulative update (currently July 2026 or later), and the server onboarded to Defender for Endpoint (eligible DCs can skip that). Run Test-MdiReadiness.ps1 first, and read the current deployment page, since the minimum update level changes. Cover all DCs, AD CS, AD FS, and Entra Connect servers.
Free assessment tools find stale admins, weak delegation, risky ACLs, and AD CS mistakes in minutes. They give you a ranked to-do list.
Run PingCastle (healthcheck mode) or Purple Knight from a domain-joined admin machine, with management's approval. Fix the highest-risk findings first. Re-run each quarter and track the score over time.
Map attack paths with BloodHound CE, defensively and with written approval
admin
BloodHound shows how a normal account could chain group memberships and permissions to reach Domain Admin. Defenders can cut those paths before attackers find them.
Get written authorization first. Antivirus often flags the collectors, so tell your SOC. Install BloodHound CE with the BloodHound CLI (a wrapper around Docker Compose) following the official quickstart. Review the paths to Tier 0 and remove unneeded rights and group nesting.
NLA makes users sign in before a remote session is created. That reduces the exposure of the logon screen to attacks and denial of service.
Enable the GPO 'Require user authentication for remote connections by using Network Level Authentication' under Remote Desktop Session Host > Security. Or set it per server with the CIM method below.
Never expose RDP directly to the internet; use RD Gateway or VPN
everyone
Open port 3389 gets constant password-spraying and exploit attempts. RD Gateway wraps RDP in encrypted HTTPS and gives you one place to apply MFA and access policy.
Close 3389 at the perimeter. Publish RDP only through RD Gateway or a VPN. Scope the RDP firewall rules on servers to admin subnets or PAWs. Add MFA at the gateway.
Use Remote Credential Guard when admins RDP into servers
admin
Normal RDP sends reusable credentials to the target. Remote Credential Guard redirects Kerberos requests back to the admin's machine, so a compromised server can't harvest them.
Requires Kerberos and both machines in the same or a trusted domain. Connect with mstsc /remoteGuard, or push the client-side GPO Administrative Templates > System > Credentials Delegation > 'Restrict delegation of credentials to remote servers'. Follow the doc for server-side requirements.