Module 7: Privileged Access Workstations (PAWs) Hardening
This directory contains the physical isolation policies and operating system security configurations required to protect Tier 0 administrative workstations.
Technical Hardening Controls
REQ-PAW-001 - Configure AppLocker Policies for PAWs Enforces strict AppLocker application control policies, restricting execution of unauthorized binaries to approved administrative groups.
REQ-PAW-002 - Enable LSA Protection for PAWs Configures LSASS to run as a protected process (PPL) to block credential dumping tools from harvesting secrets from LSA memory.
REQ-PAW-003 - Restrict Local Administrators Group for PAWs Restricts and audits membership in the local Administrators group on PAWs to prevent unauthorized local administrative access.
REQ-PAW-004 - Enforce BitLocker with TPM and Startup PIN for PAWs Configures highly stringent BitLocker policies specifically for PAWs, requiring TPM + pre-boot Startup PIN (no Network Unlock allowed), disabling sleep/standby states (S1-S3) to prevent DMA attacks, enabling Kernel DMA Protection, and enforcing enhanced PIN rules and automatic AD recovery password rotation.
REQ-PAW-005 - UEFI Firmware Security Hardening Enforces UEFI firmware locking, setting a strong BIOS administrator password, disabling CSM/Legacy boot, locking the boot order, and protecting against BIOS rollbacks.
REQ-PAW-006 - Enable Hardware Virtualization and DMA Protection Enables hardware CPU virtualization, IOMMU/DMA protection at the firmware level, and TPM 2.0 to provide the necessary platform integrity foundation for Virtualization-Based Security (VBS).
REQ-PAW-007 - Disable Windows Platform Binary Table (WPBT) Disables execution of binaries supplied by the Windows Platform Binary Table (WPBT) ACPI firmware table to mitigate boot-level security bypasses.
REQ-PAW-008 - Windows Defender Antivirus PAW Baseline and Exploit Guard Configures Windows Defender Antivirus on PAWs, enabling real-time scanning, behavioral monitoring, preventing local exclusion modifications, enforcing all ASR rules in strict Block mode, activating Tamper Protection, and enabling AppContainer sandbox isolation.
- REQ-PAW-057 - Disable Real-Time Monitoring and Behavior Monitoring Override for PAWs
- REQ-PAW-058 - Configure Potentially Unwanted Applications (PUA) Protection for PAWs
- REQ-PAW-059 - Prevent Local List Merging and Exclusions Configuration for PAWs
- REQ-PAW-060 - Configure Auto Exclusions Configuration for PAWs
- REQ-PAW-061 - Enable EDR in Block Mode for PAWs
- REQ-PAW-062 - Allow Network Protection on Windows Server for PAWs
- REQ-PAW-063 - Enable File Hash Computation for PAWs
- REQ-PAW-064 - Configure Network Inspection System (NIS) settings for PAWs
- REQ-PAW-065 - Configure OOBE Real-Time Protection and Security Intelligence for PAWs
- REQ-PAW-066 - Enable Dynamic Signature Dropped Event Reporting for PAWs
- REQ-PAW-067 - Configure Quick Scan and Scanning Exclusions for PAWs
- REQ-PAW-068 - Configure Scheduled Scan Parameters for PAWs
- REQ-PAW-069 - Configure Security Intelligence Update Schedule for PAWs
- REQ-PAW-070 - Configure Attack Surface Reduction Rules for PAWs
- REQ-PAW-076 - ASR: Block abuse of exploited vulnerable signed drivers for PAWs
- REQ-PAW-077 - ASR: Block Adobe Reader from creating child processes for PAWs
- REQ-PAW-078 - ASR: Block all Office applications from creating child processes for PAWs
- REQ-PAW-079 - ASR: Block credential stealing from the Windows local security authority subsystem for PAWs
- REQ-PAW-080 - ASR: Block executable content from email client and webmail for PAWs
- REQ-PAW-081 - ASR: Block executable files from running unless they meet a prevalence, age, or trusted list criterion for PAWs
- REQ-PAW-082 - ASR: Block execution of potentially obfuscated scripts for PAWs
- REQ-PAW-083 - ASR: Block JavaScript or VBScript from launching downloaded executable content for PAWs
- REQ-PAW-084 - ASR: Block Office applications from creating executable content for PAWs
- REQ-PAW-085 - ASR: Block Office applications from injecting code into other processes for PAWs
- REQ-PAW-086 - ASR: Block Office communication application from creating child processes for PAWs
- REQ-PAW-087 - ASR: Block persistence through WMI event subscription for PAWs
- REQ-PAW-088 - ASR: Block process creations originating from PSExec and WMI commands for PAWs
- REQ-PAW-089 - ASR: Block untrusted and unsigned processes that run from USB for PAWs
- REQ-PAW-090 - ASR: Block Win32 API calls from Office macros for PAWs
- REQ-PAW-091 - ASR: Use advanced protection against ransomware for PAWs
- REQ-PAW-071 - Configure Threat Severity Default Quarantine Actions for PAWs
- REQ-PAW-072 - Configure Family Options UI Lockdown for PAWs
- REQ-PAW-073 - Configure Tamper Protection for PAWs
- REQ-PAW-074 - Configure Sandbox Execution Environment for PAWs
- REQ-PAW-075 - Configure AMSI Authenticode Signature Verification for PAWs
- REQ-PAW-192 - Configure Remote Encryption Protection Mode for PAWs
REQ-PAW-009 - Configure User Rights Assignments for PAWs Restricts critical user rights assignments (URAs) such as debugging programs, token impersonation, and denying network/interactive logon permissions for standard accounts on PAWs.
- REQ-PAW-092 - Configure User Rights: Access Credential Manager as a trusted caller for PAWs
- REQ-PAW-093 - Configure User Rights: Access this computer from the network for PAWs
- REQ-PAW-094 - Configure User Rights: Act as part of the operating system for PAWs
- REQ-PAW-095 - Configure User Rights: Allow log on locally for PAWs
- REQ-PAW-096 - Configure User Rights: Back up files and directories for PAWs
- REQ-PAW-097 - Configure User Rights: Create a pagefile for PAWs
- REQ-PAW-098 - Configure User Rights: Create a token object for PAWs
- REQ-PAW-099 - Configure User Rights: Create global objects for PAWs
- REQ-PAW-100 - Configure User Rights: Create permanent shared objects for PAWs
- REQ-PAW-101 - Configure User Rights: Debug programs for PAWs
- REQ-PAW-102 - Configure User Rights: Enable computer and user accounts to be trusted for delegation for PAWs
- REQ-PAW-103 - Configure User Rights: Force shutdown from a remote system for PAWs
- REQ-PAW-104 - Configure User Rights: Impersonate a client after authentication for PAWs
- REQ-PAW-105 - Configure User Rights: Load and unload device drivers for PAWs
- REQ-PAW-106 - Configure User Rights: Lock pages in memory for PAWs
- REQ-PAW-107 - Configure User Rights: Manage auditing and security log for PAWs
- REQ-PAW-108 - Configure User Rights: Modify firmware environment values for PAWs
- REQ-PAW-109 - Configure User Rights: Perform volume maintenance tasks for PAWs
- REQ-PAW-110 - Configure User Rights: Profile single process for PAWs
- REQ-PAW-111 - Configure User Rights: Restore files and directories for PAWs
- REQ-PAW-112 - Configure User Rights: Take ownership of files or other objects for PAWs
- REQ-PAW-113 - Configure User Rights: Deny access to this computer from the network for PAWs
- REQ-PAW-114 - Configure User Rights: Deny log on through Remote Desktop Services for PAWs
REQ-PAW-010 - Enable VBS and Credential Guard for PAWs Configures Virtualization-Based Security (VBS), Credential Guard (with UEFI Lock), System Guard Secure Launch, and memory protections to shield LSASS from credential dumping attacks on PAWs.
REQ-PAW-011 - Harden DMA and Physical Security for PAWs Mitigates physical access threat vectors by disabling sleep standby states (S1-S3), disabling external DMA device enumeration under lock, enforcing a strict block-all device enumeration policy, and blocking legacy SBP-2 device classes.
REQ-PAW-012 - Enable WDAC Driver Blocklist Enforces the Microsoft Vulnerable Driver Blocklist using Windows Defender Application Control (WDAC) to protect the kernel from Bring Your Own Vulnerable Driver (BYOVD) attacks.
REQ-PAW-013 - Configure Account and Password Policies for PAWs Configures robust local account lockout, local password complexity, and 20-character minimum length policies, and references Active Directory Fine-Grained Password Policies (FGPP) for Tier 0 Administrators.
- REQ-PAW-152 - Account Policy: Password Policy for PAWs
- REQ-PAW-153 - Account Policy: Account Lockout Policy for PAWs
- REQ-PAW-154 - Account Policy: Kerberos Policy for PAWs
- REQ-PAW-155 - Account Policy: Smart Card Removal Behavior for PAWs
- REQ-PAW-156 - Account Policy: Cached Logons and PBKDF2 Iteration Count for PAWs
- REQ-PAW-157 - Account Policy: Local Accounts and Blank Password Restrictions for PAWs
- REQ-PAW-158 - Account Policy: NTLM and LAN Manager Authentication Security for PAWs
- REQ-PAW-159 - Account Policy: Disable WDigest Credential Caching for PAWs
- REQ-PAW-160 - Account Policy: Windows Hello for Business and PIN Complexity for PAWs
- REQ-PAW-161 - Account Policy: Consumer Microsoft Account Restrictions for PAWs
- REQ-PAW-162 - Account Policy: Domain Member Secure Channel Security for PAWs
- REQ-PAW-163 - Account Policy: SMB Client and Server Security Options for PAWs
- REQ-PAW-164 - Account Policy: Anonymous Access and Enumeration Restrictions for PAWs
- REQ-PAW-165 - Account Policy: Interactive Logon Security Options for PAWs
REQ-PAW-014 - Configure Early Launch Antimalware (ELAM) Policy for PAWs Configures the Early Launch Antimalware (ELAM) driver initialization policy to ensure only signed, trusted boot drivers execute.
REQ-PAW-015 - Configure Secure Printing and Print Spooler Policies for PAWs Enforces disabling the Print Spooler service and configuring Point and Print restrictions to prevent print-related exploits.
REQ-PAW-016 - Configure Untrusted Font Blocking for PAWs Configures the Untrusted Font Blocking mitigation on PAWs to prevent font parsing exploits.
REQ-PAW-017 - Configure svchost.exe Mitigation Options for PAWs Configures svchost.exe mitigation options on PAWs to restrict binary loading to Microsoft-signed code and block dynamic code execution.
REQ-PAW-018 - Enable Kernel-Mode Hardware-Enforced Stack Protection for PAWs Configures Kernel-mode Hardware-enforced Stack Protection to enforce hardware-backed control-flow integrity and mitigate kernel Return-Oriented Programming (ROP) execution hijacks.
REQ-PAW-019 - Harden Network Parameters and Disable Legacy Name Resolution Disables Link-Local Multicast Name Resolution (LLMNR), NetBIOS over TCP/IP, and mDNS, and secures TCP/IP parameters on PAWs to prevent credential harvesting and protocol exploits.
REQ-PAW-020 - Configure User Account Control Policies for PAWs Enforces maximum UAC security behavior, requiring credential entry on the secure desktop for administrators and automatically denying elevation prompts.
REQ-PAW-021 - Disable AutoPlay and AutoRun for PAWs Turns off AutoPlay and AutoRun features across all drive types to prevent automatic execution of files and payloads from external media.
REQ-PAW-022 - Disable Incoming Remote Desktop Access for PAWs Strictly denies incoming RDP and Remote Assistance connections to administrative workstations to block lateral movement.
REQ-PAW-023 - WSUS Client Configuration for PAWs Enforces update client registry baselines to ensure workstations pull OS patches and security signatures exclusively from the local, offline WSUS server.
REQ-PAW-024 - Configure User Profile and System Restrictions for PAWs Locks down user profile registry settings and key system security policies including inactivity timeouts, secondary logon, and ASLR force.
- REQ-PAW-115 - User Profile: Toast Notifications Lock Screen Restrictions for PAWs
- REQ-PAW-116 - User Profile: Spotlight and Consumer Features Restrictions for PAWs
- REQ-PAW-117 - User Profile: Windows Copilot Restrictions for PAWs
- REQ-PAW-118 - User Profile: In-Place Sharing Restrictions for PAWs
- REQ-PAW-119 - User Profile: Shell RunAs User Suppression for PAWs
- REQ-PAW-120 - User Profile: Personalization and Privacy Restrictions for PAWs
- REQ-PAW-121 - User Profile: Group Policy Processing Behaviors for PAWs
- REQ-PAW-122 - User Profile: Telemetry and Inventory Collection Restrictions for PAWs
- REQ-PAW-123 - User Profile: Explorer Security and Memory Protections for PAWs
- REQ-PAW-124 - User Profile: Internet Explorer Options and Feeds Restrictions for PAWs
- REQ-PAW-125 - User Profile: Interactive Logon Warning Banners for PAWs
- REQ-PAW-126 - User Profile: Interactive Logon Inactivity Timeout for PAWs
- REQ-PAW-127 - User Profile: Windows Installer Hardening for PAWs
- REQ-PAW-128 - User Profile: Secondary Logon Service Lockdown for PAWs
- REQ-PAW-140 - User Profile: Structured Exception Handling Overwrite Protection (SEOP) for PAWs
- REQ-PAW-141 - User Profile: Directory Protection Mode for PAWs
- REQ-PAW-142 - User Profile: Address Space Layout Randomization (ASLR) Image Relocation for PAWs
- REQ-PAW-143 - User Profile: Speculative Execution Mitigations (Spectre/Meltdown) for PAWs
- REQ-PAW-144 - User Profile: Authenticode Certificate Padding Check for PAWs
- REQ-PAW-145 - User Profile: Command Processor Batch File Locking for PAWs
- REQ-PAW-146 - User Profile: Time-Travel Debugging (TTD) Recording Policy for PAWs
- REQ-PAW-147 - User Profile: Trusted Root Store Protected Roots Certificate Restriction for PAWs
- REQ-PAW-148 - User Profile: Disabling Injection of AppInit DLLs for PAWs
- REQ-PAW-149 - User Profile: Preservation of Attachment Zone Information for PAWs
- REQ-PAW-150 - User Profile: Disable Windows Game DVR for PAWs
- REQ-PAW-151 - User Profile: Restrict Windows Ink Workspace on Lock Screen for PAWs
REQ-PAW-025 - Configure Exploit Protection Profile for PAWs Configures and enforces a system-wide Microsoft Defender Exploit Protection profile to apply advanced memory mitigations (DEP, ASLR, CFG, SEHOP, Heap Integrity) on all PAWs.
REQ-PAW-026 - Restrict Safe Mode Access to Administrators on PAWs Prevents standard (non-administrative) users from logging into the system while in Safe Mode by setting SafeModeBlockNonAdmins to 1.
REQ-PAW-027 - Configure Windows Defender Firewall and Block LOLBins for PAWs Configures host firewall profiles and outbound rules to block known Living Off the Land Binaries (LOLBins) from initiating outgoing network connections.
REQ-PAW-028 - Disable Unnecessary System Services for PAWs Disables unnecessary and high-risk system services to minimize the attack surface of administrative endpoints.
- REQ-PAW-037 - Disable Computer Browser Service for PAWs (Browser)
- REQ-PAW-038 - Disable Infrared Monitor Service for PAWs (irmon)
- REQ-PAW-039 - Disable Internet Connection Sharing (ICS) Service for PAWs (SharedAccess)
- REQ-PAW-040 - Disable LxssManager Service for PAWs (LxssManager)
- REQ-PAW-041 - Disable Microsoft FTP Service for PAWs (FTPSVC)
- REQ-PAW-042 - Disable OpenSSH SSH Server Service for PAWs (sshd)
- REQ-PAW-043 - Disable Remote Procedure Call (RPC) Locator Service for PAWs (RpcLocator)
- REQ-PAW-044 - Disable Routing and Remote Access Service for PAWs (RemoteAccess)
- REQ-PAW-045 - Disable Simple TCP/IP Services for PAWs (simptcp)
- REQ-PAW-046 - Disable Special Administration Console Helper Service for PAWs (sacsvr)
- REQ-PAW-047 - Disable SSDP Discovery Service for PAWs (SSDPSRV)
- REQ-PAW-048 - Disable UPnP Device Host Service for PAWs (upnphost)
- REQ-PAW-049 - Disable Web Management Service for PAWs (WMSvc)
- REQ-PAW-050 - Disable Windows Media Player Network Sharing Service for PAWs (WMPNetworkSvc)
- REQ-PAW-051 - Disable Windows Mobile Hotspot Service for PAWs (icssvc)
- REQ-PAW-052 - Disable World Wide Web Publishing Service for PAWs (W3SVC)
- REQ-PAW-053 - Disable Xbox Accessory Management Service for PAWs (XboxGipSvc)
- REQ-PAW-054 - Disable Xbox Live Auth Manager Service for PAWs (XblAuthManager)
- REQ-PAW-055 - Disable Xbox Live Game Save Service for PAWs (XblGameSave)
- REQ-PAW-056 - Disable Xbox Live Networking Service for PAWs (XboxNetApiSvc)
- REQ-PAW-166 - Disable WebClient Service for PAWs (WebClient)
REQ-PAW-029 - Configure System Administrative Templates for PAWs Coordinates system-wide administrative template policies across network protocols, session security, diagnostic data collection, application deployment, event log capacities, and update schedules for Tier 0 PAWs.
- REQ-PAW-168 - Administrative Templates: Disable SMBv1 Protocol Components for PAWs
- REQ-PAW-169 - Administrative Templates: Configure NetBT Node Type and Name Release for PAWs
- REQ-PAW-170 - Administrative Templates: MSS IP Source Routing and ICMP Redirects for PAWs
- REQ-PAW-171 - Administrative Templates: MSS System and Session Security Protections for PAWs
- REQ-PAW-172 - Administrative Templates: Prevent Device Metadata Retrieval from Network for PAWs
- REQ-PAW-173 - Administrative Templates: Enforce Group Policy Background Processing for PAWs
- REQ-PAW-174 - Administrative Templates: Disable Cross-Device Experiences for PAWs
- REQ-PAW-175 - Administrative Templates: Restrict Internet Communication and Web Downloads for PAWs
- REQ-PAW-176 - Administrative Templates: Block Custom SSPs and APs from Loading into LSASS for PAWs
- REQ-PAW-177 - Administrative Templates: Logon Display and Credential Restrictions for PAWs
- REQ-PAW-178 - Administrative Templates: Disable Connected Standby Network Connectivity for PAWs
- REQ-PAW-179 - Administrative Templates: Disable Remote Assistance for PAWs
- REQ-PAW-180 - Administrative Templates: Enable RPC Endpoint Mapper Client Authentication for PAWs
- REQ-PAW-181 - Administrative Templates: Configure Windows Time Service NTP Client and Server for PAWs
- REQ-PAW-182 - Administrative Templates: App Package Deployment Restrictions for PAWs
- REQ-PAW-183 - Administrative Templates: Configure Biometrics Enhanced Anti-Spoofing for PAWs
- REQ-PAW-184 - Administrative Templates: Disable Cloud Consumer Account State Content for PAWs
- REQ-PAW-185 - Administrative Templates: Require PIN for Connect Wireless Pairing for PAWs
- REQ-PAW-186 - Administrative Templates: Credential User Interface Security Protections for PAWs
- REQ-PAW-187 - Administrative Templates: Diagnostic Data Collection and Preview Builds Restrictions for PAWs
- REQ-PAW-188 - Administrative Templates: App Installer Protocol and Execution Controls for PAWs
- REQ-PAW-189 - Administrative Templates: Event Log Maximum File Sizes and Retention Policies for PAWs
- REQ-PAW-190 - Administrative Templates: File Explorer Mark of the Web and Shell Protocol Security for PAWs
- REQ-PAW-191 - Administrative Templates: Internet Explorer 11 and Web Feeds Retirement Controls for PAWs
- REQ-PAW-193 - Administrative Templates: Windows Search and Cortana Privacy Restrictions for PAWs
- REQ-PAW-194 - Administrative Templates: Windows Store Updates and OS Upgrade Restrictions for PAWs
- REQ-PAW-195 - Administrative Templates: Disable Windows Widgets and News Feed for PAWs
- REQ-PAW-196 - Administrative Templates: Disable Windows Automatic Restart Sign-On for PAWs
- REQ-PAW-197 - Administrative Templates: Windows Sandbox Clipboard and Network Isolation for PAWs
- REQ-PAW-198 - Administrative Templates: Windows Update Deferral and Automatic Installation Policies for PAWs
REQ-PAW-030 - Enable UEFI Secure Boot for PAWs Mandates hardware-rooted platform integrity checks, verifying that UEFI Secure Boot is active on the operating system for PAWs.
REQ-PAW-031 - Enforce Smart Card Logon for PAWs Enforces the 'Interactive logon: Require smart card' GPO policy locally to suppress username/password fields and force hardware-bound authentication.
REQ-PAW-032 - Disable Unused Windows Features and PowerShell 2.0 Engine Disables legacy, unused Windows optional features, including PowerShell 2.0, .NET Framework 3.5, and SMBv1 to minimize the workstation attack surface.
REQ-PAW-033 - Configure Microsoft Office Security and Block OLE Packages Blocks VBA macros from running in Office files downloaded from the Internet, enforces macro digital signing warnings, and disables OLE Package execution in Outlook to prevent initial access exploits.
REQ-PAW-034 - Disable Windows Script Host and Remap Scripting Extensions Disables Windows Script Host execution globally and remaps standard scripting extensions (.vbs, .js, etc.) to open in Notepad by default to prevent execution by double-click.
REQ-PAW-035 - Configure Secure Boot Revocations and Bootloader Updates for PAWs Configures and enforces BlackLotus revocation updates and bootloader integrity verification policy variables in system firmware for PAWs.
REQ-PAW-036 - Configure Windows Defender Application Control Deploys Windows Defender Application Control (WDAC) on PAWs in Audit Mode to block unauthorized system-level binaries and scripts.
REQ-PAW-129 - Configure Advanced Security Audit Policies for PAWs Enforces granular Windows security audit policies (including logons, group memberships, registry access, and system events) to log critical threat telemetry on privileged access workstations.
- REQ-PAW-130 - Audit Policy: Advanced Audit Policy Overrides for PAWs
- REQ-PAW-131 - Audit Policy: Account Logon Auditing for PAWs
- REQ-PAW-132 - Audit Policy: Account Management Auditing for PAWs
- REQ-PAW-133 - Audit Policy: Detailed Tracking Auditing for PAWs
- REQ-PAW-134 - Audit Policy: Logon and Logoff Auditing for PAWs
- REQ-PAW-135 - Audit Policy: Object Access Auditing for PAWs
- REQ-PAW-136 - Audit Policy: Policy Change Auditing for PAWs
- REQ-PAW-137 - Audit Policy: Privilege Use Auditing for PAWs
- REQ-PAW-138 - Audit Policy: System Events Auditing for PAWs
REQ-PAW-167 - Enable Kerberos Armoring for PAWs Enforces Kerberos Armoring (FAST) with strict enforcement (
RequireFast = 1) and certificate device authentication on Privileged Access Workstations to protect administrative authentication exchanges from offline cracking and protocol downgrade attacks.