Windows Security Hardening
Windows security hardening reduces the ways a Windows device can be compromised. It starts from a tested configuration baseline, then layers identity, application, network, data, and monitoring controls while preserving the device's required work.
itWindows and Microsoft infrastructure | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
Windows Security Hardening
Windows security hardening is the controlled reduction of a Windows device's attack surface. You start with a supported operating system and a tested security baseline. You then add controls for privileges, credentials, applications, network traffic, data, and telemetry. Each control removes an attacker path or limits what a successful compromise can reach.
Hardening is not a one-time registry edit. It is a lifecycle that connects desired configuration to measured device state:
Requirements → baseline → pilot → enforcement → observation → remediation → review
A baseline is a group of recommended settings with documented security implications. Microsoft publishes Windows security baselines because Windows exposes thousands of policy settings, while only a subset should be enforced broadly. A useful baseline is opinionated enough to reduce risk and restrained enough to avoid operational damage.
The layered architecture
Windows hardening works as overlapping control planes. No single plane replaces the others.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/windows-security-configuration-framework/windows-security-baselines
Supports
- Baseline definition, principles, supported Windows editions, and Group Policy or MDM deployment paths
- Use of known, tested configuration instead of independently selecting thousands of settings
- https://learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/windows-security-configuration-framework/security-compliance-toolkit-10
Supports
- Security Compliance Toolkit contents and baseline workflow
- Policy Analyzer comparisons and LGPO import and export capabilities
- https://www.microsoft.com/en-us/download/details.aspx?id=55319
Supports
- Security Compliance Toolkit product role, free download, baseline packages, Policy Analyzer, and LGPO
- https://learn.microsoft.com/en-us/windows/security/
Supports
- Official Windows security documentation map across hardware, identity, application, data, network, and cloud controls
- https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/windows-firewall/
Supports
- Host firewall role, default inbound and outbound behavior, profiles, rule conditions, IPsec, and service guidance
- https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/planning-guide
Supports
- TPM behavior, protector choices, recovery planning, offline protection, and deployment tradeoffs
- https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/
Supports
- VBS isolation, protected domain secrets, requirements, default enablement, limitations, and authentication compatibility
- https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-concepts-overview
Supports
- Local password generation, directory backup, retrieval permissions, encryption, expiry, and rotation after authentication
- https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-overview
Supports
- ASR capabilities, control boundaries, audit mode, management tools, and relationship to endpoint detection
- https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-deployment
Supports
- Plan, audit, enable, monitor, and ring-based ASR deployment path
- https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-deployment-test
Supports
- Representative audit testing, event review, impact assessment, and narrow exclusions before enforcement
- https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/
Supports
- App Control policy design, rule behavior, audit and enforcement modes, deployment, and event troubleshooting
- https://learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/design/appcontrol-and-applocker-overview
Supports
- App Control and AppLocker decision boundaries, rule types, and writable-path risk
- https://github.com/sindresorhus/awesome
Supports
- Required starting point for awesome-list discovery
- https://github.com/fabacab/awesome-cybersecurity-blueteam
Supports
- Discovery of HardenTools, Sandboxie, Sigcheck, and the Windows-defense ecosystem
- https://github.com/hardentools/hardentools
Supports
- Windows and document-application attack-surface reductions, desktop focus, compatibility warnings, and project limits
- https://learn.microsoft.com/en-us/sysinternals/downloads/sigcheck
Supports
- Signature, certificate-chain, hash, unsigned-file, and optional malware-reputation inspection
- https://fibratus.io/docs
Supports
- Windows kernel telemetry, rule language, architecture, capture, and investigation capabilities
- https://sandboxie-plus.github.io/sandboxie-docs/
Supports
- Windows application isolation and redirected file and registry changes
- https://news.microsoft.com/source/2004/08/06/microsoft-releases-windows-xp-service-pack-2-with-advanced-security-technologies-to-computer-manufacturers/
Supports
- August 2004 XP Service Pack 2 milestone, stronger defaults, Security Center, and data execution prevention
- https://news.microsoft.com/source/2007/01/16/top-security-companies-align-to-support-consumer-launch-of-windows-vista/
Supports
- January 2007 Vista availability and built-in UAC, Defender, and firewall layers
- https://news.microsoft.com/speeches/steve-ballmer-new-york-business-launch-of-windows-vista-2007-microsoft-office-system-and-microsoft-exchange-server-2007/
Supports
- BitLocker as a Windows Vista Enterprise volume-encryption feature
- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/ee424367%28v%3Dws.11%29
Supports
- AppLocker introduction in Windows 7 and Windows Server 2008 R2 and its rule scope
- https://learn.microsoft.com/en-us/windows/win32/w8cookbook/secured-boot
Supports
- Windows 8 introduction of Secure Boot and early launch antimalware
- https://www.microsoft.com/en-us/industry/blog/government/2015/07/29/windows-10-a-new-operating-system-for-government-it/
Supports
- July 2015 Windows 10 release context and Device Guard code-trust role
- https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/overview-of-threat-mitigations-in-windows-10
Supports
- Windows 10 Credential Guard and VBS introduction and protected-secret purpose
- https://www.microsoft.com/en-us/security/blog/2017/10/23/introducing-windows-defender-application-control/
Supports
- October 2017 WDAC naming and separation from the broader Device Guard state
- https://www.microsoft.com/en-us/security/blog/2018/04/19/introducing-windows-defender-system-guard-runtime-attestation/
Supports
- April 2018 runtime attestation milestone and platform-integrity evidence
- https://techcommunity.microsoft.com/blog/microsoft-security-baselines/security-baseline-final-for-windows-10-v1903-and-windows-server-v1903/701084
Supports
- May 2019 baseline removal of forced periodic password expiration
- https://blogs.windows.com/windows-insider/2021/08/27/update-on-windows-11-minimum-system-requirements-and-the-pc-health-check-app/
Supports
- Windows 11 TPM 2.0 and Secure Boot rationale and hardware-backed security floor
- https://blogs.windows.com/windowsexperience/2021/10/04/windows-11-a-new-era-for-the-pc-begins-today/
Supports
- October 2021 Windows 11 general availability
- https://techcommunity.microsoft.com/blog/windows-itpro-blog/by-popular-demand-windows-laps-available-now/3788747
Supports
- April 2023 integrated Windows LAPS release and supported cloud and on-premises paths
- https://learn.microsoft.com/en-us/intune/device-security/security-baselines/overview
Supports
- Intune Windows and Defender baseline profiles, customization, group deployment, and per-setting state
- https://www.microsoft.com/en-us/evalcenter/download-microsoft-endpoint-configuration-manager
Supports
- Proprietary Configuration Manager product, endpoint deployment and management role, and evaluation packaging
- https://www.cisecurity.org/cybersecurity-tools/cis-cat-pro
Supports
- CIS Benchmark assessment, reporting, membership access, and paid Pro positioning
- https://www.tenable.com/products/nessus
Supports
- Proprietary paid Nessus product, configuration, compliance, security audit, and vulnerability assessment roles
- https://docs.tenable.com/nessus/compliance-checks-reference/Content/WindowsConfigurationAuditComplianceFileReference.htm
Supports
- Windows registry and local security policy checks through Nessus audit files
- https://www.qualys.com/apps/policy-audit
Supports
- Proprietary paid Policy Audit product and recurring configuration assessment role
- https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-endpoint
Supports
- Proprietary paid Defender for Endpoint product and endpoint security role
