RedPatch
Headlines refreshed Sun Oct 11, 11:45 AM ET (1 h ago) · content checked against vendor docs

▣ Windows Server security

Windows Server, locked down.

Windows Server runs the keys to the kingdom: Active Directory, file shares, certificates, and remote access. This guide covers the hardening that matters most on Server 2022 and 2025, from baselines to protocol lockdown to logging. Server 2025 has safer defaults than 2022, so we call out where the two differ. Test every change on one server first, then roll it out.

44 tips · 17 tools · every one sourced

Latest Windows Server advisories

  1. Microsoft 365 incident readiness for Microsoft Engage CenterWindows Release Health · Oct 9
  2. Windows 11, version 26H1 known issues and notificationsWindows Release Health · Oct 9
  3. RHSA-2026:79786: Important: kernel security updateRed Hat Security Advisories (RHSA) · Oct 9
  4. CVE-2026-62744 Microsoft Windows Media Foundation Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9
  5. CVE-2026-68875 Windows NTFS Remote Code Execution VulnerabilityMicrosoft Security Update Guide · Oct 9
  6. RHSA-2026:79784: Important: kernel security updateRed Hat Security Advisories (RHSA) · Oct 9

All Windows Server headlines →

1. Start from a known-good baseline

Pick one security baseline and treat it as the standard

admin

Hundreds of settings affect security. A published baseline gives you a tested starting point, so you don't have to set each one by hand.

Choose one master baseline: Microsoft's (from the Security Compliance Toolkit), CIS, or DISA STIG. Import it as GPOs into a test OU, fix what breaks, then link it to production. Write down every deviation and why. Don't stack two baselines blindly, because they conflict.

Check — read-only
gpresult /r /scope computer

Source: Microsoft Learn: Windows security baselines

On Server 2025, apply the OSConfig baseline that matches the server's role

admin

OSConfig applies 300+ settings in one command, and drift control puts them back if something changes them. Server 2022 and earlier are not supported.

In an elevated PowerShell, install the Microsoft.OSConfig module. Apply the scenario for the role: SecurityBaseline/WindowsServer/2025/DomainController, MemberServer, or WorkgroupMember. Restart. On member servers and workgroup members you must change the local admin password (14+ characters). Expect TLS 1.2 minimum, SMB 3.0 minimum, and file copy from RDP sessions turned off. If GPO also sets the same values differently, the two will fight, so remove one source.

Check — read-only
Get-OSConfigDesiredConfiguration -Scenario SecurityBaseline/WindowsServer/2025/MemberServer | ft Name, @{ Name = "Status"; Expression={$_.Compliance.Status} }, @{ Name = "Reason"; Expression={$_.Compliance.Reason} } -AutoSize -Wrap
Changes your system
Install-Module -Name Microsoft.OSConfig -Scope AllUsers -Force; Set-OSConfigDesiredConfiguration -Scenario SecurityBaseline/WindowsServer/2025/MemberServer -Default

Source: Microsoft Learn: Configure security baselines for Windows Server 2025

Keep the OSConfig baseline current

admin

Baselines ship inside the OSConfig module. A newer module brings a newer baseline, which replaces the old one in full. The current version covers 344 settings on member servers, 347 on domain controllers, and 319 on workgroup members.

Check the installed module version. Update the module, then reapply the same scenario. If an earlier baseline is applied, you'll be asked to remove it first; confirm. Restart when done.

Check — read-only
Get-Module -ListAvailable -Name Microsoft.OSConfig
Changes your system
Update-Module -Name Microsoft.OSConfig; Set-OSConfigDesiredConfiguration -Scenario SecurityBaseline/WindowsServer/2025/MemberServer -Default

Source: Microsoft Learn: Configure security baselines for Windows Server 2025 (baseline versioning)

Compare GPOs against the baseline with Policy Analyzer before you deploy

power user

Policy Analyzer shows conflicts, duplicates, and differences between GPOs, the baseline, and a server's current local policy. You see what will change before it changes.

Download Policy Analyzer from the Security Compliance Toolkit. Load the Microsoft baseline and your existing GPO backups. Review the differences and settle each conflict on purpose.

Source: Microsoft Learn: Microsoft Security Compliance Toolkit

Use CIS Benchmarks or DISA STIGs when an auditor or contract requires them

admin

Many audits and government contracts name CIS or STIG directly. Using the named standard saves arguing over equivalence later.

Download the Windows Server benchmark for your version from CIS (Server 2022 and 2025 are both published), or the Windows Server STIG from DISA. Apply it through GPO in a test OU first. Keep a record of exceptions with a business reason for each.

Source: CIS Benchmarks: Microsoft Windows Server

Use DISA STIGs for government and defense work

admin

STIGs are the DoD's required configurations. They're free and detailed, and each one has a check and a fix.

Get the Windows Server 2022 or 2025 STIG and the matching GPO package from DISA's STIG library. Use STIG Viewer to track each finding. Apply through GPO in test first.

Source: DoD Cyber Exchange: STIGs

2. Shrink the attack surface and patch fast

Use Server Core for infrastructure roles

admin

Server Core has no desktop shell, so there's less code to attack and less to patch. Microsoft rates its attack surface as greatly reduced compared with Desktop Experience.

Pick Server Core at install time for DCs, DNS, DHCP, file, and Hyper-V hosts. Manage the server remotely with Windows Admin Center, PowerShell remoting, or RSAT. You can't convert between Server Core and Desktop Experience after install, so decide up front.

Check — read-only
(Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion').InstallationType

Source: Microsoft Learn: Windows Server installation options (Server Core vs Desktop Experience)

Patch every month and fast-track known-exploited bugs

everyone

Attackers go after flaws that are already public. CISA's Known Exploited Vulnerabilities list shows which ones are being used right now.

Install the monthly cumulative update within days, not weeks. Check the CISA KEV catalog and patch anything on it first. Confirm each server actually installed the update.

Check — read-only
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5

Source: CISA: Known Exploited Vulnerabilities Catalog

Use Hotpatch on Server 2025 to cut reboot delays

admin

Hotpatch installs security fixes into running memory, so most months need no reboot. Servers are no longer left unpatched while waiting for a maintenance window.

Connect Server 2025 Standard or Datacenter to Azure Arc and turn on Hotpatch. Microsoft now offers Arc-enabled Hotpatch for Server 2025 at no extra cost. A baseline cumulative update still needs a reboot every three months. Non-security updates, .NET, and drivers or firmware still go through normal patching.

Check — read-only
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 5

Source: Microsoft Learn: Hotpatch for Windows Server

Keep Windows Firewall on for every profile and block inbound by default

power user

A default-deny firewall means only ports you meant to open are reachable. The Server 2025 baseline does exactly this.

Turn on the Domain, Private, and Public profiles. Set the default inbound action to Block. Add allow rules only for what the server's role needs, scoped to the source subnets that need it.

Check — read-only
Get-NetFirewallProfile | Select-Object Name, Enabled, DefaultInboundAction
Changes your system
Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True -DefaultInboundAction Block

Source: Microsoft Learn: Configure security baselines for Windows Server 2025 (network exposure reduction)

Turn off LLMNR and NetBIOS name resolution

admin

These old broadcast protocols let anyone on the network answer name lookups and collect credential hashes, which is what tools like Responder do. DNS is all you need.

In GPO, enable Computer Configuration > Administrative Templates > Network > DNS Client > Turn off multicast name resolution. Turn off NetBIOS over TCP/IP on each network adapter, or use DHCP options. The Server 2025 OSConfig baseline does both.

Check — read-only
Get-ItemProperty 'HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient' -Name EnableMulticast -ErrorAction SilentlyContinue

Source: Microsoft Learn: Configure security baselines for Windows Server 2025 (network exposure reduction)

3. Control privileged access

Separate admin accounts into tiers

admin

If a Domain Admin signs in to a workstation that's already compromised, the whole domain falls. Tiering keeps top-level credentials off lower-trust machines.

Treat DCs, AD FS, AD CS, and Microsoft Entra Connect servers as Tier 0. Give each admin separate accounts per tier, and never use one for email or browsing. Use GPO 'Deny log on' user rights to block Tier 0 accounts from lower-tier servers and workstations. Keep Domain Admins as small as possible.

Check — read-only
Get-ADGroupMember -Identity 'Domain Admins' -Recursive | Select-Object Name, objectClass

Source: Microsoft Learn: Active Directory tier model

Run Tier 0 administration from privileged access workstations (PAWs)

admin

An admin's own machine is the easiest way in. A dedicated, locked-down workstation with no email or web browsing removes that path.

Build PAWs from a clean, hardened image with TPM 2.0, Secure Boot, BitLocker, and app control. Block general web browsing and email on them. Allow Tier 0 servers to accept admin connections only from PAWs, using firewall rules and logon rights.

Source: Microsoft Learn: Privileged access devices

Add human admin accounts to Protected Users

admin

Members can't use NTLM, or DES or RC4 in Kerberos pre-authentication, their credentials aren't cached, and their Kerberos tickets can't be renewed past four hours. This blunts pass-the-hash and offline cracking.

Add individual admin user accounts, one or two at a time. Never add service or computer accounts, because their authentication will fail. Check that RDP, tools, and scripts still work before adding the next. The domain functional level must be Windows Server 2012 R2 or higher.

Check — read-only
Get-ADGroupMember -Identity 'Protected Users' | Select-Object Name, objectClass
Changes your system
Add-ADGroupMember -Identity 'Protected Users' -Members <admin-account>

Source: Microsoft Learn: Protected Users security group

Mark admin accounts 'sensitive and cannot be delegated'

admin

By default, any AD account can be delegated. This flag stops a compromised server with delegation rights from impersonating your admins elsewhere.

Set 'Account is sensitive and cannot be delegated' on every privileged user account. Check service accounts separately before you flag them, since some apps need delegation.

Check — read-only
Get-ADUser -Filter 'AdminCount -eq 1' -Properties AccountNotDelegated | Select-Object Name, AccountNotDelegated
Changes your system
Set-ADAccountControl -Identity <admin-account> -AccountNotDelegated $true

Source: Microsoft Learn: Implementing least-privilege administrative models

Use Windows LAPS for every server's local admin password

admin

When every server shares one local admin password, an attacker who steals it can reach all of them. Windows LAPS gives each server its own rotating password, and it's built in.

Extend the schema once per forest with Update-LapsADSchema. Give servers rights to write their own passwords on their OU. Turn on LAPS through GPO, or on Server 2025 member servers through the OSConfig LAPS scenario. Turn on password encryption, and limit who can read the passwords.

Check — read-only
Get-LapsADPassword -Identity <server-name>
Changes your system
Update-LapsADSchema; Set-LapsADComputerSelfPermission -Identity 'OU=Servers,DC=contoso,DC=com'

Source: Microsoft Learn: Get started with Windows LAPS and Windows Server Active Directory

Use Just Enough Administration (JEA) for routine tasks

admin

Help desk and app owners often get full admin rights just to restart a service. JEA gives them only the commands they need, runs them under a temporary virtual account, and keeps transcripts of what they ran.

Write a role capability file listing the allowed cmdlets. Write a session configuration that maps AD groups to that role and runs as a virtual account. Register it, then have users connect with Enter-PSSession -ConfigurationName.

Check — read-only
Get-PSSessionConfiguration | Select-Object Name, Permission
Changes your system
Register-PSSessionConfiguration -Name <JEAEndpoint> -Path .\<endpoint>.pssc

Source: Microsoft Learn: Just Enough Administration

4. Protect credentials and authentication

Use Credential Guard on member servers, but not on domain controllers

admin

Credential Guard isolates NTLM hashes and Kerberos tickets inside virtualization-based security (VBS), out of reach of admin-level malware. Microsoft says it adds nothing on DCs and can break apps there.

On Server 2025 it's on by default for domain-joined non-DC servers that meet the requirements. On 2022, turn it on through GPO: Computer Configuration > Administrative Templates > System > Device Guard > Turn On Virtualization Based Security, then set Credential Guard Configuration. Hyper-V VMs must be Generation 2. Check that apps don't need NTLMv1, Kerberos DES, or unconstrained delegation. Don't turn it on for Exchange Server, which isn't supported.

Check — read-only
(Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard).SecurityServicesRunning

Source: Microsoft Learn: Credential Guard overview

Run LSASS as a protected process

admin

LSA protection blocks untrusted code from reading or injecting into LSASS memory, which is where credential-dumping tools go.

Run audit mode first, as the doc describes, to find LSA plug-ins or drivers that would be blocked. Then turn it on through GPO or the registry value below, and restart. Value 1 also sets a UEFI variable, which makes it harder to turn off later; value 2 skips the UEFI lock and is enforced only on newer builds (Windows 11 22H2 and later). Use GPO across the fleet.

Check — read-only
Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa' -Name RunAsPPL -ErrorAction SilentlyContinue
Changes your system
reg add HKLM\SYSTEM\CurrentControlSet\Control\Lsa /v RunAsPPL /t REG_DWORD /d 1 /f

Source: Microsoft Learn: Configure added LSA protection

Move Kerberos off RC4 and onto AES

admin

RC4-encrypted Kerberos tickets are much easier to crack offline. Accounts explicitly set to allow only DES or RC4 stay weak even after Microsoft's updates.

Find accounts that allow DES or RC4 but not AES, and fix them. Watch the System log on DCs for KDC event 42 (account lacks strong keys) and event 27 (no common encryption type). Once clean, set DefaultDomainSupportedEncTypes on DCs to 0x38, which Microsoft recommends where RC4 isn't used. Test first, because old non-Windows devices may fail.

Check — read-only
Get-ADObject -Filter "msDS-supportedEncryptionTypes -bor 0x7 -and -not msDS-supportedEncryptionTypes -bor 0x18"
Changes your system
reg add HKLM\SYSTEM\CurrentControlSet\services\KDC /v DefaultDomainSupportedEncTypes /t REG_DWORD /d 0x38 /f

Source: Microsoft Support: KB5021131 Kerberos protocol changes (CVE-2022-37966)

Audit NTLM, then restrict it

admin

NTLM enables relay and pass-the-hash attacks. Server 2025 has removed NTLMv1, and Microsoft is phasing out NTLM altogether.

Turn on these GPO audit settings first: 'Network security: Restrict NTLM: Audit Incoming NTLM Traffic' on all servers, 'Network security: Restrict NTLM: Audit NTLM authentication in this domain' on DCs, and 'Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers' set to Audit all. Read the Microsoft-Windows-NTLM/Operational log to find what still uses NTLM. Move those apps to Kerberos, then deny NTLM server by server. On 2022, set 'Network security: LAN Manager authentication level' to 'Send NTLMv2 response only. Refuse LM & NTLM' (LmCompatibilityLevel 5).

Check — read-only
Get-WinEvent -LogName 'Microsoft-Windows-NTLM/Operational' -MaxEvents 50; Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Control\Lsa' -Name LmCompatibilityLevel -ErrorAction SilentlyContinue

Source: Microsoft Learn: Network security: Restrict NTLM: Audit incoming NTLM traffic

5. Lock down network protocols (SMB and LDAP)

Keep SMBv1 off and uninstalled

power user

SMBv1 has no modern protections and was the route WannaCry used. It also lets attackers downgrade encrypted SMB sessions to unencrypted access.

SMBv1 isn't installed by default on Server 2019 and later, so on 2022 and 2025 confirm it stayed that way. If it's present (for example on an upgraded server), remove it. Before you do, find and replace old devices that need it, such as old copiers and NAS boxes, instead of reinstalling SMBv1.

Check — read-only
Get-SmbServerConfiguration | Select-Object EnableSMB1Protocol; Get-WindowsOptionalFeature -Online -FeatureName SMB1Protocol
Changes your system
Disable-WindowsOptionalFeature -Online -FeatureName SMB1Protocol

Source: Microsoft Learn: Detect, enable, and disable SMBv1, SMBv2, and SMBv3

Require SMB signing for both inbound and outbound connections

power user

Signing stops relay and spoofing attacks on file traffic. Server 2025 requires it for outbound connections only, so you must set inbound yourself, and on Server 2022 set both.

Set RequireSecuritySignature to True on the server and client side, through GPO ('Microsoft network server: Digitally sign communications (always)' and the matching client setting) or PowerShell. Signing also stops guest access to third-party devices. Fix any third-party NAS so it allows signing instead of turning signing off.

Check — read-only
Get-SmbServerConfiguration | Select-Object RequireSecuritySignature; Get-SmbClientConfiguration | Select-Object RequireSecuritySignature
Changes your system
Set-SmbServerConfiguration -RequireSecuritySignature $true; Set-SmbClientConfiguration -RequireSecuritySignature $true

Source: Microsoft Learn: Control SMB signing behavior

Encrypt sensitive file shares

admin

SMB encryption protects data in transit end to end, even across networks you don't control. You don't need IPsec for it.

Turn on encryption for each sensitive share, or for the whole server. Leave RejectUnencryptedAccess at its default of True so only encryption-capable SMB 3.x clients get in. Disable SMBv1 too, because RejectUnencryptedAccess doesn't stop a downgrade to SMB 1.0. Expect a small performance cost.

Check — read-only
Get-SmbShare | Select-Object Name, EncryptData; Get-SmbServerConfiguration | Select-Object EncryptData, RejectUnencryptedAccess
Changes your system
Set-SmbShare -Name <share-name> -EncryptData $true

Source: Microsoft Learn: SMB security enhancements

Require LDAP signing on domain controllers

admin

Unsigned LDAP binds can be tampered with or relayed. New Server 2025 deployments require signing by default. Server 2022 and earlier don't.

Watch Directory Service events 2886-2889 to find clients making unsigned or clear-text binds. Set the '16 LDAP Interface Events' diagnostic level to 2 to get per-client event 2889, and turn it back down afterward. Fix those clients, then set 'Domain controller: LDAP server signing requirements' to Require signing. Upgraded environments can keep their old policy, so check them.

Check — read-only
Get-WinEvent -FilterHashtable @{LogName='Directory Service'; Id=2886,2887,2888,2889} -MaxEvents 20

Source: Microsoft Learn: LDAP signing overview for Active Directory

Move LDAP channel binding to 'Always'

admin

Channel binding ties a login to its TLS session, which shuts off NTLM relay over LDAPS. New Server 2025 deployments default to 'When supported'. Server 2022 and earlier default to 'Never'.

On 2022, first set 'Domain controller: LDAP server channel binding token requirements' to When supported (LdapEnforceChannelBinding = 1), because events 3039, 3074, and 3075 are only logged at 1 or 2. Set diagnostic level 2 to get 3074 and 3075. Update or replace clients those events name. Then set the policy to Always (LdapEnforceChannelBinding = 2).

Check — read-only
Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Parameters' -Name LdapEnforceChannelBinding -ErrorAction SilentlyContinue; Get-WinEvent -FilterHashtable @{LogName='Directory Service'; Id=3039,3040,3074,3075} -MaxEvents 20

Source: Microsoft Learn: LDAP channel binding in Active Directory

6. Harden Active Directory Certificate Services (AD CS)

Confirm every DC is in Full Enforcement for certificate mapping

admin

Weak certificate mapping let attackers sign in as other users with a crafted certificate. Microsoft moved DCs to Full Enforcement in February 2025, and from the September 9, 2025 update the StrongCertificateBindingEnforcement registry key is no longer supported, so there's no way back to Compatibility mode.

Make sure every DC has the September 2025 or later cumulative update. Remove any leftover StrongCertificateBindingEnforcement value so nobody assumes it still does something. Fix certificates that KDC events 39, 40, or 41 flag, which usually means reissuing them with the SID extension or adding a strong mapping.

Check — read-only
Get-WinEvent -FilterHashtable @{LogName='System'; Id=39,40,41} -MaxEvents 50 -ErrorAction SilentlyContinue | Where-Object ProviderName -match 'Kerberos-Key-Distribution-Center|Kdcsvc'

Source: Microsoft Support: KB5014754 Certificate-based authentication changes on Windows domain controllers

Fix certificate templates that let requesters choose the subject

admin

A template that allows client authentication and 'Supply in the request' lets any enrollee get a certificate for any user, including a Domain Admin (ESC1).

Review every published template. Where a template allows client authentication, clear 'Supply in the request', or require CA manager approval. Remove enrollment rights for unprivileged users. Unpublish templates nobody uses. Defender for Identity flags these templates as a posture finding.

Check — read-only
certutil -v -dstemplate

Source: Microsoft Learn: Defender for Identity: Certificate security posture assessments

Protect AD CS web enrollment from NTLM relay

admin

Attackers can relay NTLM to the CA's web enrollment pages (PetitPotam) to get a certificate for a DC. Microsoft published specific fixes for this.

The strongest fix is to disable NTLM on AD CS servers with 'Network security: Restrict NTLM: Incoming NTLM traffic'. Where Web Enrollment or the Certificate Enrollment Web Service is in use, set Extended Protection for Authentication to Required in IIS, turn on Require SSL, set Windows authentication to Negotiate:Kerberos, and restart IIS. Treat CA servers as Tier 0.

Check — read-only
Get-WindowsFeature ADCS-Web-Enrollment, ADCS-Enroll-Web-Svc

Source: Microsoft Support: KB5005413 Mitigating NTLM relay attacks on AD CS

7. Control what runs: App Control and antimalware

On Server 2025, deploy the App Control default policy in audit mode first

admin

App Control for Business allows only trusted code to run, which stops most malware and attacker tools. Server 2025 ships a ready-made Microsoft policy you apply with OSConfig.

Install OSConfig. Apply the DefaultPolicy and AppBlockList scenarios in Audit mode. Watch CodeIntegrity/Operational event 3076 for what would have been blocked. Turn those events into supplemental policies with the App Control Wizard (Convert Event Logs to a Policy). Switch to Enforce only when 3076 events stop. The server must run a production-signed build; flight-signed binaries aren't permitted and the device won't start.

Check — read-only
citool -lp | findstr /I "WS2025"
Changes your system
Set-OSConfigDesiredConfiguration -Scenario AppControl\WS2025\DefaultPolicy\Audit -Default; Set-OSConfigDesiredConfiguration -Scenario AppControl\WS2025\AppBlockList\Audit -Default

Source: Microsoft Learn: Configure App Control policies in Windows Server

On Server 2022, build App Control policies with the App Control Wizard

admin

Server 2022 has no OSConfig, but App Control works there too. Locked-down single-role servers like DCs are a good fit.

Start from a Microsoft example base policy in the App Control Wizard. Deploy it in audit mode, collect events, add rules for legitimate software, then enforce. Roll it out one role at a time.

Check — read-only
Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard | Select-Object CodeIntegrityPolicyEnforcementStatus, UsermodeCodeIntegrityPolicyEnforcementStatus

Source: Microsoft Learn: Application Control for Windows

Keep Microsoft Defender Antivirus active and current

everyone

Real-time protection and fresh signatures catch commodity malware. Server 2025 has its own OSConfig Defender baseline.

Confirm Defender is in Normal mode with real-time protection on and signatures updated today. On Server 2025, apply the Defender/Antivirus/WindowsServer/2025 OSConfig scenario. If you run a third-party antivirus, confirm it's actually active.

Check — read-only
Get-MpComputerStatus | Select-Object AMRunningMode, RealTimeProtectionEnabled, AntivirusSignatureLastUpdated
Changes your system
Set-OSConfigDesiredConfiguration -Scenario Defender/Antivirus/WindowsServer/2025 -Default

Source: Microsoft Learn: Configure security baselines for Windows Server 2025 (companion scenarios)

Turn on attack surface reduction (ASR) rules, starting in audit mode

admin

ASR rules block common attack behaviors, such as WMI persistence, PsExec and WMI process launches, and dropping vulnerable signed drivers. They need Microsoft Defender Antivirus.

Start with 'Block persistence through WMI event subscription' in AuditMode. Review the events, then switch it to Enabled. Add more rules from the reference list the same way. Skip the LSASS credential-stealing rule where LSA protection is on, because Microsoft says it adds nothing there.

Check — read-only
Get-MpPreference | Select-Object AttackSurfaceReductionRules_Ids, AttackSurfaceReductionRules_Actions
Changes your system
Add-MpPreference -AttackSurfaceReductionRules_Ids e6db77e5-3df2-4cf1-b95a-636979351e5b -AttackSurfaceReductionRules_Actions AuditMode

Source: Microsoft Learn: Attack surface reduction rules reference

8. Log it, watch it, test it

Use advanced audit policy and force subcategory settings

admin

The default audit settings miss logons, account changes, and privilege use. Without those, you can't reconstruct an incident.

In GPO, configure Advanced Audit Policy Configuration using Microsoft's recommendations. Enable 'Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings' so old category-level settings don't override them. Cover credential validation, account management, logon, and sensitive privilege use, for both success and failure.

Check — read-only
auditpol /get /category:*

Source: Microsoft Learn: Audit policy recommendations

Log process creation with the full command line

admin

Event 4688 with the command line shows exactly what an attacker ran. The Server 2025 baseline turns it on.

Turn on 'Audit Process Creation' (Success). Then enable the GPO 'Include command line in process creation events' under Computer Configuration > Administrative Templates > System > Audit Process Creation.

Check — read-only
Get-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Audit' -Name ProcessCreationIncludeCmdLine_Enabled -ErrorAction SilentlyContinue

Source: Microsoft Learn: Configure security baselines for Windows Server 2025 (auditing and visibility)

Turn on PowerShell script block logging

admin

Attackers lean on PowerShell. Script block logging records the scripts and commands that actually ran, as event 4104.

In GPO, enable Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell > Turn on PowerShell Script Block Logging. Forward the Microsoft-Windows-PowerShell/Operational log to your SIEM. Consider module logging and transcription as well.

Check — read-only
Get-ItemProperty -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging' -ErrorAction SilentlyContinue

Source: Microsoft Learn: about_Group_Policy_Settings (Windows PowerShell 5.1)

Size the Security log properly and send logs off the server

power user

A small log rolls over in hours, and an attacker with admin rights can clear a local log. The Server 2025 baseline sets the Security log to at least 192 MB.

Raise the Security log to at least 192 MB. Forward events with Windows Event Forwarding or a SIEM agent, so a copy lives somewhere the attacker can't reach.

Check — read-only
wevtutil gl Security
Changes your system
wevtutil sl Security /ms:201326592

Source: Microsoft Learn: Configure security baselines for Windows Server 2025 (auditing and visibility)

Deploy Sysmon with a tuned configuration

admin

Sysmon adds detail Windows doesn't log by default: process hashes, network connections, LSASS access, WMI persistence, and DNS queries.

Download Sysmon from Sysinternals. Install it with a configuration file that filters out noise, because the defaults are either too quiet or too loud. Forward Microsoft-Windows-Sysmon/Operational to your SIEM. Update the configuration with sysmon64 -c <file>.

Check — read-only
Get-Service Sysmon64 -ErrorAction SilentlyContinue; Get-WinEvent -LogName 'Microsoft-Windows-Sysmon/Operational' -MaxEvents 5
Changes your system
sysmon64 -accepteula -i C:\Sysmon\config.xml

Source: Microsoft Learn: Sysmon (Sysinternals)

Put Microsoft Defender for Identity on every Tier 0 server

admin

MDI watches DC traffic and events for things like Kerberoasting, DCSync, and lateral movement. It also flags AD and AD CS posture problems.

If you're licensed, activate the v3.x sensor. It needs Server 2019 or later with a recent cumulative update (currently July 2026 or later), and the server onboarded to Defender for Endpoint (eligible DCs can skip that). Run Test-MdiReadiness.ps1 first, and read the current deployment page, since the minimum update level changes. Cover all DCs, AD CS, AD FS, and Entra Connect servers.

Source: Microsoft Learn: Deploy Defender for Identity sensor v3.x

Score your Active Directory health every quarter

admin

Free assessment tools find stale admins, weak delegation, risky ACLs, and AD CS mistakes in minutes. They give you a ranked to-do list.

Run PingCastle (healthcheck mode) or Purple Knight from a domain-joined admin machine, with management's approval. Fix the highest-risk findings first. Re-run each quarter and track the score over time.

Source: PingCastle (official site)

Map attack paths with BloodHound CE, defensively and with written approval

admin

BloodHound shows how a normal account could chain group memberships and permissions to reach Domain Admin. Defenders can cut those paths before attackers find them.

Get written authorization first. Antivirus often flags the collectors, so tell your SOC. Install BloodHound CE with the BloodHound CLI (a wrapper around Docker Compose) following the official quickstart. Review the paths to Tier 0 and remove unneeded rights and group nesting.

Source: BloodHound docs: Community Edition quickstart

9. Remote administration done safely

Require Network Level Authentication for RDP

power user

NLA makes users sign in before a remote session is created. That reduces the exposure of the logon screen to attacks and denial of service.

Enable the GPO 'Require user authentication for remote connections by using Network Level Authentication' under Remote Desktop Session Host > Security. Or set it per server with the CIM method below.

Check — read-only
(Get-CimInstance -ClassName Win32_TSGeneralSetting -Namespace root\cimv2\terminalservices -Filter "TerminalName='RDP-tcp'").UserAuthenticationRequired
Changes your system
Get-CimInstance -ClassName Win32_TSGeneralSetting -Namespace root\cimv2\terminalservices -Filter "TerminalName='RDP-tcp'" | Invoke-CimMethod -MethodName SetUserAuthenticationRequired -Arguments @{UserAuthenticationRequired=1}

Source: Microsoft Learn: Enable Remote Desktop (Why allow connections only with NLA)

Never expose RDP directly to the internet; use RD Gateway or VPN

everyone

Open port 3389 gets constant password-spraying and exploit attempts. RD Gateway wraps RDP in encrypted HTTPS and gives you one place to apply MFA and access policy.

Close 3389 at the perimeter. Publish RDP only through RD Gateway or a VPN. Scope the RDP firewall rules on servers to admin subnets or PAWs. Add MFA at the gateway.

Check — read-only
Get-NetFirewallRule -DisplayGroup 'Remote Desktop' | Select-Object DisplayName, Enabled, Profile

Source: Microsoft Learn: Remote Desktop Gateway role

Use Remote Credential Guard when admins RDP into servers

admin

Normal RDP sends reusable credentials to the target. Remote Credential Guard redirects Kerberos requests back to the admin's machine, so a compromised server can't harvest them.

Requires Kerberos and both machines in the same or a trusted domain. Connect with mstsc /remoteGuard, or push the client-side GPO Administrative Templates > System > Credentials Delegation > 'Restrict delegation of credentials to remote servers'. Follow the doc for server-side requirements.

Source: Microsoft Learn: Remote Credential Guard

Tools worth knowing

OSConfig (Microsoft.OSConfig module)free

Applies and drift-protects Microsoft's role-based security baselines, Defender, LAPS, and App Control on Server 2025.

When: Building or hardening any Server 2025 machine.

Microsoft Security Compliance Toolkitfree

Microsoft's security baselines as GPO backups, plus companion tools.

When: Setting a baseline for Server 2022 or 2025 through Group Policy.

Policy Analyzerfree

Compares GPOs, baselines, and local policy, and highlights conflicts and differences.

When: Before deploying a baseline, or when auditing GPO sprawl.

LGPOfree

Command-line tool that imports and exports local Group Policy.

When: Applying a baseline to workgroup or standalone servers without a domain.

CIS Benchmarks for Windows Serverfree + paid

Consensus hardening guides with audit and remediation steps for each setting.

When: Compliance-driven environments and audits.

DISA STIGs and STIG Viewerfree

DoD-mandated Windows Server configurations, with checks and fixes.

When: Government, defense, or contract work that requires STIG compliance.

Windows LAPSbuilt-in

Built-in rotation and backup of local admin passwords to AD or Entra ID.

When: Every domain-joined server and workstation.

App Control Wizardfree

GUI tool for building and editing App Control for Business policies, including turning audit logs into rules.

When: Creating base or supplemental App Control policies.

CiToolbuilt-in

Built-in command-line tool that lists and manages active code integrity (App Control) policies.

When: Checking which App Control policies are active on a server.

auditpolbuilt-in

Built-in tool that shows and sets advanced audit policy subcategories.

When: Checking that auditing actually matches your GPO intent.

Sysmonfree

Sysinternals service that logs detailed process, network, registry, and file activity to the event log.

When: Endpoint telemetry for a SIEM or threat hunting.

Microsoft Defender for Identitypaid

Cloud service that detects identity attacks on DCs, AD CS, AD FS, and Entra Connect, and scores AD posture.

When: Continuous monitoring of Active Directory in Microsoft 365 E5 or MDI-licensed environments.

Microsoft Defender Antivirusbuilt-in

Built-in antimalware with real-time protection and attack surface reduction rules.

When: Every server, unless another EDR product is actually active.

PingCastlefree + paid

Active Directory health check that scores risk across privileged accounts, trusts, stale objects, and anomalies.

When: Quarterly AD posture reviews.

Purple Knightfree

Semperis AD, Entra ID, and Okta security assessment with prioritized fixes.

When: A second-opinion AD posture snapshot alongside PingCastle.

BloodHound Community Editionfree + paid

Graphs AD permissions and memberships to show attack paths to privileged groups.

When: Defensive attack-path reduction, with written authorization only.

Windows Admin Centerfree

Browser-based management for servers, including SMB signing and encryption settings.

When: Managing Server Core and remote servers without RDP.

Other platforms

Go deeper

networks.jelia.nycHow the internet actually moves your data — packets, DNS, routing, TLS. waves.jelia.nycElectromagnetism explained — Wi-Fi, 2.4 GHz, Bluetooth and why RF leaks. lib.jelia.nycThe library — security, Linux, assembly and networking books on the shelf. blog.redpatch.usRedPatch field notes.