Module 8: Endpoint Hardening
This directory defines the technical security baselines for standard client workstations (Tier 2 endpoints) operating in isolated, air-gapped domains.
To prevent initial access and lateral movement, the following unitary technical hardening controls must be implemented:
Technical Hardening Controls
REQ-END-001 - Harden Network Parameters and Disable Legacy Name Resolution Disables Link-Local Multicast Name Resolution (LLMNR), NetBIOS over TCP/IP, and mDNS, and secures TCP/IP parameters to prevent local credential harvesting and protocol exploits.
REQ-END-002 - Configure User Account Control Policies Enforces maximum UAC security behavior, requiring credential entry on the secure desktop for administrators and automatically denying elevation prompts for standard users.
REQ-END-003 - Disable AutoPlay and AutoRun Turns off AutoPlay and AutoRun features across all drive types to prevent automatic execution of files and payloads from external media.
REQ-END-004 - Block Removable Storage Blocks read and write access to USB drives and other removable media classes to mitigate data leakage and malware propagation.
REQ-END-005 - Restrict Remote Desktop Access Blocks incoming RDP connections to standard workstations by default, or restricts allowed connection sources to authorized administrative subnets with Network Level Authentication (NLA) enabled.
REQ-END-006 - Restrict Local Administrators Group Locks down local workstation administrative privileges, removing standard domain users and enforcing administrative segregation utilizing LAPS.
REQ-END-007 - Windows Defender Antivirus Baseline and Exploit Guard Configures Windows Defender Antivirus, enabling real-time scanning, behavioral monitoring, preventing local exclusion modifications, enforcing Attack Surface Reduction (ASR) rules, activating Tamper Protection, and enabling AppContainer sandbox isolation.
- REQ-END-057 - Disable Real-Time Monitoring and Behavior Monitoring Override
- REQ-END-058 - Configure Potentially Unwanted Applications (PUA) Protection
- REQ-END-059 - Prevent Local List Merging and Exclusions Configuration
- REQ-END-060 - Configure Auto Exclusions Configuration
- REQ-END-061 - Prevent MAPS Local Setting Override
- REQ-END-062 - Enable EDR in Block Mode
- REQ-END-063 - Allow Network Protection on Windows Server
- REQ-END-064 - Enable File Hash Computation
- REQ-END-065 - Configure Network Inspection System (NIS) settings
- REQ-END-066 - Configure OOBE Real-Time Protection and Security Intelligence
- REQ-END-067 - Enable Dynamic Signature Dropped Event Reporting
- REQ-END-068 - Configure Quick Scan and Scanning Exclusions
- REQ-END-069 - Configure Scheduled Scan Parameters
- REQ-END-070 - Configure Security Intelligence Update Schedule
- REQ-END-071 - Configure Attack Surface Reduction Rules
- REQ-END-080 - ASR: Block abuse of exploited vulnerable signed drivers
- REQ-END-081 - ASR: Block Adobe Reader from creating child processes
- REQ-END-082 - ASR: Block all Office applications from creating child processes
- REQ-END-083 - ASR: Block credential stealing from the Windows local security authority subsystem
- REQ-END-084 - ASR: Block executable content from email client and webmail
- REQ-END-085 - ASR: Block executable files from running unless they meet a prevalence, age, or trusted list criterion
- REQ-END-086 - ASR: Block execution of potentially obfuscated scripts
- REQ-END-087 - ASR: Block JavaScript or VBScript from launching downloaded executable content
- REQ-END-088 - ASR: Block Office applications from creating executable content
- REQ-END-089 - ASR: Block Office applications from injecting code into other processes
- REQ-END-090 - ASR: Block Office communication application from creating child processes
- REQ-END-091 - ASR: Block persistence through WMI event subscription
- REQ-END-092 - ASR: Block process creations originating from PSExec and WMI commands
- REQ-END-093 - ASR: Block untrusted and unsigned processes that run from USB
- REQ-END-094 - ASR: Block Win32 API calls from Office macros
- REQ-END-095 - ASR: Use advanced protection against ransomware
- REQ-END-072 - Configure Threat Severity Default Quarantine Actions
- REQ-END-073 - Configure Family Options UI Lockdown
- REQ-END-074 - Configure Tamper Protection
- REQ-END-075 - Configure Sandbox Execution Environment
- REQ-END-076 - Configure AMSI Authenticode Signature Verification
- REQ-END-077 - Configure File Explorer SmartScreen
- REQ-END-078 - Disable OneDrive File Sync
- REQ-END-079 - Enforce Antivirus Scan on Opening Attachments
- REQ-END-203 - Configure Remote Encryption Protection Mode
REQ-END-008 - WSUS Client Configuration Enforces update client registry baselines to ensure workstations pull OS patches and security signatures exclusively from the local, offline WSUS server.
REQ-END-009 - Enable UEFI Secure Boot Mandates hardware-rooted platform integrity checks, verifying that UEFI Secure Boot is active on the operating system.
REQ-END-010 - Enable VBS and Credential Guard Activates Virtualization-Based Security (VBS) and Credential Guard to protect password hashes and Kerberos tickets in an isolated virtual container, mitigating LSASS dumping.
REQ-END-011 - Configure Windows Defender Application Control Deploys application control baselines and the Microsoft Vulnerable Driver Blocklist to enforce code integrity policies, restricting the system to run only signed, authorized binaries, scripts, and secure drivers.
REQ-END-012 - Enable BitLocker and Network Unlock Enforces full disk encryption with TPM and enables secure Network Unlock capabilities for standard client workstations.
REQ-END-013 - UEFI Firmware Security Hardening Enforces password protection, disables Compatibility Support Module (CSM)/Legacy Boot, locks boot order, and configures secure firmware update policies.
REQ-END-014 - Enable Hardware Virtualization and DMA Protection Enables CPU virtualization (VT-x/AMD-V) and IOMMU (VT-d/AMD-Vi) to provide the hardware-rooted platform integrity required for VBS and Kernel DMA protection.
REQ-END-015 - Disable Windows Platform Binary Table (WPBT) Disables execution of binaries supplied by the Windows Platform Binary Table (WPBT) ACPI firmware table to mitigate boot-level security bypasses.
REQ-END-016 - Configure User Rights Assignments Restricts critical user rights assignments (URAs) such as debugging programs, token impersonation, and local logon permissions on standard client endpoints.
- REQ-END-096 - Configure User Rights: Access Credential Manager as a trusted caller
- REQ-END-097 - Configure User Rights: Access this computer from the network
- REQ-END-098 - Configure User Rights: Act as part of the operating system
- REQ-END-099 - Configure User Rights: Allow log on locally
- REQ-END-100 - Configure User Rights: Back up files and directories
- REQ-END-101 - Configure User Rights: Change the system time
- REQ-END-102 - Configure User Rights: Change the time zone
- REQ-END-103 - Configure User Rights: Create a pagefile
- REQ-END-104 - Configure User Rights: Create a token object
- REQ-END-105 - Configure User Rights: Create global objects
- REQ-END-106 - Configure User Rights: Create permanent shared objects
- REQ-END-107 - Configure User Rights: Create symbolic links
- REQ-END-108 - Configure User Rights: Debug programs
- REQ-END-109 - Configure User Rights: Enable computer and user accounts to be trusted for delegation
- REQ-END-110 - Configure User Rights: Force shutdown from a remote system
- REQ-END-111 - Configure User Rights: Impersonate a client after authentication
- REQ-END-112 - Configure User Rights: Increase scheduling priority
- REQ-END-113 - Configure User Rights: Load and unload device drivers
- REQ-END-114 - Configure User Rights: Lock pages in memory
- REQ-END-115 - Configure User Rights: Manage auditing and security log
- REQ-END-116 - Configure User Rights: Modify firmware environment values
- REQ-END-117 - Configure User Rights: Perform volume maintenance tasks
- REQ-END-118 - Configure User Rights: Profile single process
- REQ-END-119 - Configure User Rights: Profile system performance
- REQ-END-120 - Configure User Rights: Replace a process level token
- REQ-END-121 - Configure User Rights: Restore files and directories
- REQ-END-122 - Configure User Rights: Take ownership of files or other objects
- REQ-END-123 - Configure User Rights: Modify an object label
- REQ-END-124 - Configure User Rights: Deny access to this computer from the network
- REQ-END-125 - Configure User Rights: Deny log on through Remote Desktop Services
REQ-END-017 - Harden DMA and Physical Security Mitigates physical access threat vectors by disabling standby sleep states (S1-S3), disabling external DMA device enumeration under lock, blocking legacy SBP-2 device classes, and denying write access to removable drives without BitLocker protection.
REQ-END-018 - Configure Account and Password Policies Enforces local and domain-wide account settings, including account lockout thresholds, lockout observation windows, smart card removal actions, and disabling reversible password encryption.
- REQ-END-163 - Account Policy: Password Policy for Endpoints
- REQ-END-164 - Account Policy: Account Lockout Policy for Endpoints
- REQ-END-165 - Account Policy: Kerberos Policy for Endpoints
- REQ-END-166 - Account Policy: Smart Card Removal Behavior for Endpoints
- REQ-END-167 - Account Policy: Cached Logons and PBKDF2 Iteration Count for Endpoints
- REQ-END-168 - Account Policy: Local Accounts and Blank Password Restrictions for Endpoints
- REQ-END-169 - Account Policy: NTLM and LAN Manager Authentication Security for Endpoints
- REQ-END-170 - Account Policy: Disable WDigest Credential Caching for Endpoints
- REQ-END-171 - Account Policy: Windows Hello for Business and PIN Complexity for Endpoints
- REQ-END-172 - Account Policy: Consumer Microsoft Account Restrictions for Endpoints
- REQ-END-173 - Account Policy: Domain Member Secure Channel Security for Endpoints
- REQ-END-174 - Account Policy: SMB Client and Server Security Options for Endpoints
- REQ-END-175 - Account Policy: Anonymous Access and Enumeration Restrictions for Endpoints
- REQ-END-176 - Account Policy: Interactive Logon Security Options for Endpoints
REQ-END-019 - Configure User Profile Restrictions Locks down user profile registry settings (HKCU) to disable toast notifications on the lock screen and block third-party application suggestions.
- REQ-END-126 - User Profile: Toast Notifications Lock Screen Restrictions
- REQ-END-127 - User Profile: Spotlight and Consumer Features Restrictions
- REQ-END-128 - User Profile: Windows Copilot Restrictions
- REQ-END-129 - User Profile: In-Place Sharing Restrictions
- REQ-END-130 - User Profile: Shell RunAs User Suppression
- REQ-END-131 - User Profile: Personalization and Privacy Restrictions
- REQ-END-132 - User Profile: Group Policy Processing Behaviors
- REQ-END-133 - User Profile: Telemetry and Inventory Collection Restrictions
- REQ-END-134 - User Profile: Explorer Security and Memory Protections
- REQ-END-135 - User Profile: Internet Explorer Options and Feeds Restrictions
- REQ-END-136 - User Profile: Interactive Logon Warning Banners
- REQ-END-137 - User Profile: Interactive Logon Inactivity Timeout
- REQ-END-138 - User Profile: Windows Installer Hardening
- REQ-END-139 - User Profile: Secondary Logon Service Lockdown
- REQ-END-151 - User Profile: Structured Exception Handling Overwrite Protection (SEOP) for Endpoints
- REQ-END-152 - User Profile: Directory Protection Mode for Endpoints
- REQ-END-153 - User Profile: Address Space Layout Randomization (ASLR) Image Relocation for Endpoints
- REQ-END-154 - User Profile: Speculative Execution Mitigations (Spectre/Meltdown) for Endpoints
- REQ-END-155 - User Profile: Authenticode Certificate Padding Check for Endpoints
- REQ-END-156 - User Profile: Command Processor Batch File Locking for Endpoints
- REQ-END-157 - User Profile: Time-Travel Debugging (TTD) Recording Policy for Endpoints
- REQ-END-158 - User Profile: Trusted Root Store Protected Roots Certificate Restriction for Endpoints
- REQ-END-159 - User Profile: Disabling Injection of AppInit DLLs for Endpoints
- REQ-END-160 - User Profile: Preservation of Attachment Zone Information for Endpoints
- REQ-END-161 - User Profile: Disable Windows Game DVR for Endpoints
- REQ-END-162 - User Profile: Restrict Windows Ink Workspace on Lock Screen for Endpoints
REQ-END-020 - Configure Exploit Protection Profile Configures and enforces a system-wide Microsoft Defender Exploit Protection profile to apply advanced memory mitigations (DEP, ASLR, CFG, SEHOP, Heap Integrity) on all endpoints.
REQ-END-021 - Restrict Safe Mode Access to Administrators Prevents standard (non-administrative) users from logging into the system while in Safe Mode by setting SafeModeBlockNonAdmins to 1.
REQ-END-022 - Configure Windows Defender Firewall and Block LOLBins Configures Domain, Private, and Public firewall profile states, logging, and notifications, and enforces outbound rules to block known Living Off the Land Binaries (LOLBins) from initiating outgoing network connections.
REQ-END-023 - Enable LSA Protection with UEFI Lock Configures the LSA Protection setting to run the LSASS process as a Protected Process Light (PPL) with UEFI Lock, preventing credential harvesting from LSASS memory.
REQ-END-024 - Disable Unnecessary System Services Disables unnecessary and high-risk system services to minimize the attack surface of standard client endpoints and member servers.
- REQ-END-037 - Disable Computer Browser Service (Browser)
- REQ-END-038 - Disable Infrared Monitor Service (irmon)
- REQ-END-039 - Disable Internet Connection Sharing (ICS) Service (SharedAccess)
- REQ-END-040 - Disable LxssManager Service (LxssManager)
- REQ-END-041 - Disable Microsoft FTP Service (FTPSVC)
- REQ-END-042 - Disable OpenSSH SSH Server Service (sshd)
- REQ-END-043 - Disable Remote Procedure Call (RPC) Locator Service (RpcLocator)
- REQ-END-044 - Disable Routing and Remote Access Service (RemoteAccess)
- REQ-END-045 - Disable Simple TCP/IP Services (simptcp)
- REQ-END-046 - Disable Special Administration Console Helper Service (sacsvr)
- REQ-END-047 - Disable SSDP Discovery Service (SSDPSRV)
- REQ-END-048 - Disable UPnP Device Host Service (upnphost)
- REQ-END-049 - Disable Web Management Service (WMSvc)
- REQ-END-050 - Disable Windows Media Player Network Sharing Service (WMPNetworkSvc)
- REQ-END-051 - Disable Windows Mobile Hotspot Service (icssvc)
- REQ-END-052 - Disable World Wide Web Publishing Service (W3SVC)
- REQ-END-053 - Disable Xbox Accessory Management Service (XboxGipSvc)
- REQ-END-054 - Disable Xbox Live Auth Manager Service (XblAuthManager)
- REQ-END-055 - Disable Xbox Live Game Save Service (XblGameSave)
- REQ-END-056 - Disable Xbox Live Networking Service (XboxNetApiSvc)
- REQ-END-177 - Disable WebClient Service (WebClient)
REQ-END-025 - Configure Secure Printing and Print Spooler Policies Configures printing security, RPC over TCP communication, Point and Print restrictions, and Redirection Guard, and disables incoming print spooler connections.
REQ-END-026 - Configure System Administrative Templates Coordinates system-wide administrative template policies across network protocols, session security, diagnostic data collection, application deployment, event log capacities, and update schedules.
- REQ-END-179 - Administrative Templates: Disable SMBv1 Protocol Components
- REQ-END-180 - Administrative Templates: Configure NetBT Node Type and Name Release
- REQ-END-181 - Administrative Templates: MSS IP Source Routing and ICMP Redirects
- REQ-END-182 - Administrative Templates: MSS System and Session Security Protections
- REQ-END-183 - Administrative Templates: Prevent Device Metadata Retrieval from Network
- REQ-END-184 - Administrative Templates: Enforce Group Policy Background Processing
- REQ-END-185 - Administrative Templates: Disable Cross-Device Experiences
- REQ-END-186 - Administrative Templates: Restrict Internet Communication and Web Downloads
- REQ-END-187 - Administrative Templates: Block Custom SSPs and APs from Loading into LSASS
- REQ-END-188 - Administrative Templates: Logon Display and Credential Restrictions
- REQ-END-189 - Administrative Templates: Disable Connected Standby Network Connectivity
- REQ-END-190 - Administrative Templates: Disable Remote Assistance
- REQ-END-191 - Administrative Templates: Enable RPC Endpoint Mapper Client Authentication
- REQ-END-192 - Administrative Templates: Configure Windows Time Service NTP Client and Server
- REQ-END-193 - Administrative Templates: App Package Deployment Restrictions
- REQ-END-194 - Administrative Templates: Configure Biometrics Enhanced Anti-Spoofing
- REQ-END-195 - Administrative Templates: Disable Cloud Consumer Account State Content
- REQ-END-196 - Administrative Templates: Require PIN for Connect Wireless Pairing
- REQ-END-197 - Administrative Templates: Credential User Interface Security Protections
- REQ-END-198 - Administrative Templates: Diagnostic Data Collection and Preview Builds Restrictions
- REQ-END-199 - Administrative Templates: App Installer Protocol and Execution Controls
- REQ-END-200 - Administrative Templates: Event Log Maximum File Sizes and Retention Policies
- REQ-END-201 - Administrative Templates: File Explorer Mark of the Web and Shell Protocol Security
- REQ-END-202 - Administrative Templates: Internet Explorer 11 and Web Feeds Retirement Controls
- REQ-END-204 - Administrative Templates: Windows Search and Cortana Privacy Restrictions
- REQ-END-205 - Administrative Templates: Windows Store Updates and OS Upgrade Restrictions
- REQ-END-206 - Administrative Templates: Disable Windows Widgets and News Feed
- REQ-END-207 - Administrative Templates: Disable Windows Automatic Restart Sign-On (ARSO)
- REQ-END-208 - Administrative Templates: Windows Sandbox Clipboard and Network Isolation
- REQ-END-209 - Administrative Templates: Windows Update Deferral and Automatic Installation Policies
REQ-END-027 - Configure AppLocker Policies Deploys AppLocker application control policies to restrict unauthorized software and script execution, and prevents default AppLocker bypasses.
REQ-END-028 - Configure Early Launch Antimalware (ELAM) Policy Configures the Early Launch Antimalware (ELAM) driver initialization policy to ensure only signed, trusted boot drivers execute.
REQ-END-029 - Configure Untrusted Font Blocking Configures the Untrusted Font Blocking mitigation to prevent loading of fonts outside the system fonts directory.
REQ-END-030 - Configure svchost.exe Mitigation Options Configures svchost.exe mitigation options on Tier 2 client workstations to restrict binary loading to Microsoft-signed code and block dynamic code execution.
REQ-END-031 - Enable Kernel-Mode Hardware-Enforced Stack Protection Configures Kernel-mode Hardware-enforced Stack Protection to enforce hardware-backed control-flow integrity and mitigate kernel Return-Oriented Programming (ROP) execution hijacks.
REQ-END-032 - Disable Unused Windows Features and PowerShell 2.0 Engine Disables legacy, unused Windows optional features, including PowerShell 2.0, .NET Framework 3.5, and SMBv1 to minimize the client attack surface.
REQ-END-033 - Configure Microsoft Office Security and Block OLE Packages Blocks VBA macros from running in Office files downloaded from the Internet, enforces macro digital signing warnings, and disables OLE Package execution in Outlook to prevent initial access exploits.
REQ-END-034 - Disable Windows Script Host and Remap Scripting Extensions Disables Windows Script Host execution globally and remaps standard scripting extensions (.vbs, .js, etc.) to open in Notepad by default to prevent execution by double-click.
REQ-END-035 - Configure Secure Boot Revocations and Bootloader Updates Configures and enforces BlackLotus revocation updates and bootloader integrity verification policy variables in system firmware.
REQ-END-036 - Enable WDAC Driver Blocklist Enforces the Microsoft Vulnerable Driver Blocklist via Windows Defender Application Control (WDAC) to prevent known vulnerable or malicious drivers from loading in kernel space, mitigating Bring Your Own Vulnerable Driver (BYOVD) attacks.
REQ-END-140 - Configure Advanced Security Audit Policies for Endpoints Enforces granular Windows security audit policies (including logons, group memberships, registry access, and system events) to log critical threat telemetry on Tier 2 client workstations.
- REQ-END-141 - Audit Policy: Advanced Audit Policy Overrides for Endpoints
- REQ-END-142 - Audit Policy: Account Logon Auditing for Endpoints
- REQ-END-143 - Audit Policy: Account Management Auditing for Endpoints
- REQ-END-144 - Audit Policy: Detailed Tracking Auditing for Endpoints
- REQ-END-145 - Audit Policy: Logon and Logoff Auditing for Endpoints
- REQ-END-146 - Audit Policy: Object Access Auditing for Endpoints
- REQ-END-147 - Audit Policy: Policy Change Auditing for Endpoints
- REQ-END-148 - Audit Policy: Privilege Use Auditing for Endpoints
- REQ-END-149 - Audit Policy: System Events Auditing for Endpoints
REQ-END-178 - Enable Kerberos Armoring for Endpoints Enables client-side Kerberos Armoring (FAST) and certificate device authentication on Tier 2 client endpoints with opportunistic FAST negotiation to protect authentication traffic while preserving compatibility.