Windows Hardening for Small Business: A Practical Guide That Actually Works
A practical Windows hardening guide for small businesses. Secure local administrators, Defender, BitLocker, RDP, firewall, LAPS, ASR rules, Office macros, updates and backups without building an enterprise security department.
Scope
A practical Windows hardening guide for small businesses. Secure local administrators, Defender, BitLocker, RDP, firewall, LAPS, ASR rules, Office macros, updates and backups without building an enterprise security department.
Small businesses often have an unusual security problem.
They are large enough to be interesting to attackers...
but too small to have:
SOC team
Security engineer
24/7 monitoring
Dedicated IAM team
Dedicated endpoint team
Dedicated incident response team
Instead, there is usually:
One IT administrator
or:
One MSP
responsible for everything.
The firewall.
Microsoft 365.
Wi-Fi.
Printers.
Servers.
Backups.
Laptops.
VPN.
And somehow also cybersecurity.
The good news is that you do not need a Fortune 500 security architecture to make Windows significantly harder to compromise.
A relatively small number of configuration changes eliminate a surprisingly large amount of risk.
This guide focuses on exactly that.
Not theoretical maximum security.
Not a 400-page compliance framework.
But:
What should a small business actually change on its Windows computers?
Hardening is not installing antivirus
One of the biggest misunderstandings about endpoint security is this:
We have antivirus.
Therefore Windows is secure.
Antivirus is only one layer.
A typical ransomware incident might look like:
Phishing email
↓
User downloads file
↓
Script runs
↓
Credentials stolen
↓
Attacker obtains administrator rights
↓
Moves to another computer
↓
Disables security
↓
Encrypts files
Antivirus might stop one step.
Hardening attempts to break the attack chain at several different points.
For example:
No local admin rights
+
Attack Surface Reduction
+
Defender
+
Firewall
+
LAPS
+
BitLocker
+
Patching
+
Macro restrictions
+
RDP restrictions
Now the attacker has to defeat multiple controls.
That is the goal.
Start with a security baseline
Do not invent your Windows security configuration from scratch.
Microsoft publishes Windows security baselines containing recommended settings for managed environments.
For small organizations, the baseline should be considered:
STARTING POINT
not:
CLICK EVERYTHING AND DEPLOY TO PRODUCTION
The sensible approach is:
Microsoft baseline
↓
Test devices
↓
Identify compatibility problems
↓
Adjust where justified
↓
Production
Security baselines can be managed through environments such as:
Group Policy
Microsoft Intune
Local policy
For a small company using Microsoft 365 Business Premium and Intune, cloud-based management is often significantly easier than maintaining a large traditional Group Policy environment.
Priority 1: Users should not be local administrators
If you only implement one recommendation from this entire article, start here.
A normal employee should not perform everyday work using an account with local administrator privileges.
Bad:
John
Member of:
Administrators
Better:
John
Member of:
Users
with a separate administrative mechanism available when IT actually needs elevated privileges.
Why?
Because malware running as:
standard user
has fewer opportunities than malware running as:
local administrator
The difference is enormous.
Check who is a local administrator
PowerShell:
Get-LocalGroupMember -Group Administrators
Example:
ObjectClass Name
----------- ----
User PC001\Administrator
User PC001\john
Group AzureAD\IT Administrators
Ask:
Why is john an administrator?
If the answer is:
He sometimes installs software.
that is usually not a good enough reason.
Use separate administrator accounts
A common small-business mistake is having one account:
john@example.com
used for:
Email
Teams
Browsing
Microsoft 365 administration
Endpoint administration
Server administration
That dramatically increases risk.
A better model:
john@example.com
Normal daily account.
And:
adm-john@example.com
Administrative account.
The administrator account should not be used for:
email
web browsing
daily Teams communication
random downloads
The more powerful the account, the less frequently it should be used.
Priority 2: Use Windows LAPS
One of the most dangerous configurations in a small Windows environment is this:
PC001
localadmin / SamePassword123!
PC002
localadmin / SamePassword123!
PC003
localadmin / SamePassword123!
PC004
localadmin / SamePassword123!
Compromise one machine and the attacker now potentially has credentials that work everywhere.
This is exactly the problem Windows LAPS solves.
LAPS stands for:
Local Administrator Password Solution
It automatically manages unique local administrator passwords.
Conceptually:
PC001 → Random password A
PC002 → Random password B
PC003 → Random password C
PC004 → Random password D
Passwords are rotated automatically and stored securely in:
Microsoft Entra ID
or:
Active Directory
depending on your environment.
Why LAPS matters
Without LAPS:
Compromise PC001
↓
Steal local admin password
↓
Try same password on PC002
↓
Works
↓
Lateral movement
With LAPS:
Compromise PC001
↓
Steal PC001 local admin password
↓
Try on PC002
↓
FAIL
That one change can make lateral movement significantly harder.
Priority 3: Enable BitLocker
Every business laptop should be considered stealable.
Because it is.
Employees use laptops:
at home
in cars
at hotels
at airports
at customer sites
in cafés
Eventually one disappears.
Without disk encryption, an attacker can potentially remove the drive or boot another operating system and access data offline.
BitLocker encrypts the volume.
Conceptually:
Laptop stolen
↓
SSD removed
↓
Attacker connects SSD elsewhere
↓
Encrypted data
↓
Unreadable without recovery material
Check BitLocker:
Get-BitLockerVolume
You want to see something like:
VolumeStatus FullyEncrypted
ProtectionStatus On
For managed devices, recovery keys should be centrally escrowed.
Possible locations include:
Microsoft Entra ID
Active Directory
Do not build your recovery strategy around:
The employee probably wrote the BitLocker key somewhere.
Priority 4: Keep Microsoft Defender enabled
For many small organizations, Microsoft Defender Antivirus is perfectly capable when configured correctly.
But:
Defender installed
and:
Defender configured properly
are not the same thing.
Check status:
Get-MpComputerStatus
Important fields include:
AntivirusEnabled
RealTimeProtectionEnabled
BehaviorMonitorEnabled
IoavProtectionEnabled
AntispywareEnabled
You generally want protection enabled.
Enable cloud-delivered protection
Modern endpoint protection benefits from Microsoft's cloud intelligence.
Check:
Get-MpPreference |
Select-Object MAPSReporting
Cloud-delivered protection can help Defender react to newly observed threats faster than relying only on static local signatures.
In centrally managed environments, configure this through your management platform rather than manually on every PC.
Enable tamper protection
Imagine malware obtains administrative privileges.
One of the first things it may try is:
Disable antivirus
Tamper Protection is designed to make unauthorized changes to critical Defender settings harder.
This matters because an endpoint security product that malware can simply turn off is not a particularly useful endpoint security product.
For managed businesses, enable and monitor Tamper Protection centrally.
Priority 5: Use Attack Surface Reduction rules
Attack Surface Reduction rules — usually called ASR rules — are some of the most useful Windows hardening controls available.
They do not merely ask:
Is this file malware?
They can prevent behaviors commonly used during attacks.
Examples include blocking or restricting behaviors involving:
Office creating child processes
Office creating executable content
credential theft from LSASS
scripts launching downloaded executables
Adobe Reader spawning child processes
process injection
ransomware behavior
This is extremely powerful.
Example: Office attack chain
Without ASR:
Invoice.docx
↓
Word
↓
PowerShell
↓
Download payload
↓
Execute malware
With appropriate ASR rules:
Invoice.docx
↓
Word
↓
Attempt to launch PowerShell
↓
BLOCKED
The malicious file may exist.
But the attack chain is broken.
Do not immediately set every ASR rule to Block
This is an important operational lesson.
ASR has modes such as:
Audit
Warn
Block
A good deployment process is:
Audit
↓
Monitor legitimate applications
↓
Fix exclusions if genuinely necessary
↓
Block
Do not deploy twenty security controls at 16:55 on Friday and then discover Monday morning that the accounting system depends on behavior you just blocked.
Security needs change management too.
Priority 6: Windows Firewall stays ON
Another surprisingly common configuration:
Windows Firewall disabled
Why?
Usually:
Something didn't work once.
So somebody solved it using:
Turn firewall off.
That is troubleshooting by surrender.
Windows Firewall should normally remain enabled for:
Domain
Private
Public
Check:
Get-NetFirewallProfile |
Select-Object Name, Enabled
Expected:
Name Enabled
---- -------
Domain True
Private True
Public True
Default inbound policy should be restrictive
Most workstations do not need arbitrary inbound connectivity.
Think:
OUTBOUND
Generally allowed
INBOUND
Blocked unless required
If an application requires a port, create a specific rule.
For example:
Application:
Management Agent
Port:
TCP 12345
Source:
10.1.10.0/24
is better than:
Allow all inbound traffic.
Do not create "Any → Any" firewall rules
Bad:
Source:
Any
Destination:
Any
Protocol:
Any
Action:
Allow
Better:
Source:
Management VLAN
Destination:
Workstations
Protocol:
Required management service only
Firewall rules should answer:
Who needs access?
To what?
On which port?
Why?
If nobody can answer those questions, the rule probably should not exist.
Priority 7: Do not expose RDP directly to the Internet
This deserves capital letters.
Do not do this:
INTERNET
↓
TCP 3389
↓
Windows PC
Changing:
3389
to:
43892
does not meaningfully fix the problem.
It merely moves the door.
Use something such as:
VPN
Zero Trust access
RD Gateway
secured remote management platform
instead.
If you use RDP, keep NLA enabled
Network Level Authentication requires authentication before the full remote desktop session is established.
Check RDP configuration through policy rather than manually wherever possible.
Conceptually:
Without NLA:
Connection
↓
RDP session resources
↓
Authentication
With NLA:
Connection
↓
Authentication
↓
RDP session
Also restrict which users are actually allowed to use Remote Desktop.
Not everyone needs RDP.
Check whether RDP is needed at all
On many employee computers the correct configuration is simply:
Remote Desktop:
Disabled
If IT administration uses another remote support tool, there may be no reason to leave RDP enabled.
Reduce unnecessary attack surface.
A service you do not run cannot be exploited remotely.
Priority 8: Remove SMBv1
SMBv1 belongs in history.
If a device still requires SMBv1, ask:
Why?
Usually the answer is:
Old scanner
Old NAS
Old software
Old industrial device
That does not automatically mean SMBv1 should be enabled throughout the company.
Check SMB1 server configuration:
Get-SmbServerConfiguration |
Select-Object EnableSMB1Protocol
Check optional feature status:
Get-WindowsOptionalFeature `
-Online `
-FeatureName SMB1Protocol
For modern Windows environments, SMBv1 should normally be disabled.
If one legacy system absolutely requires it, isolate the problem rather than weakening every computer.
Priority 9: Patch Windows automatically
Hardening an unpatched computer is like installing a high-security door while leaving the window open.
For workstations, establish predictable update deployment.
A sensible model might be:
Microsoft releases updates
↓
Small pilot group
↓
Short validation period
↓
General deployment
Not:
Disable Windows Update
because users dislike restarts.
Windows 10 needs special attention
A small business should inventory old Windows 10 devices.
By 2026, ordinary Windows 10 editions are no longer on normal standard support unless the organization is using an applicable Extended Security Updates arrangement.
The preferred long-term direction is:
Windows 11
on supported hardware.
Do not let:
It still turns on.
become your lifecycle policy.
Old unsupported operating systems accumulate security risk.
Check OS versions
PowerShell:
Get-ComputerInfo |
Select-Object WindowsProductName,
WindowsVersion,
OsBuildNumber
For inventory across many machines, collect this centrally.
You need to know:
What do we have?
Which builds?
Which machines are unsupported?
Which machines have missed updates?
You cannot secure devices you do not know exist.
Priority 10: Harden Microsoft Office
Office documents remain an attractive attack vector.
The classic attack:
Invoice.xlsm
↓
User opens file
↓
Macro runs
↓
Script executes
↓
Payload downloaded
Modern Office versions already provide substantial protections against macros originating from the Internet.
Do not weaken them because one employee wants to run a random spreadsheet from email.
Macro policy
For users who do not need macros:
Macros disabled
is a perfectly reasonable policy.
For environments that genuinely require macros:
Signed macros
+
Trusted publishers
+
Controlled trusted locations
is preferable to:
Enable all macros
Never create a giant writable network share and mark the entire thing trusted.
That simply creates a new attack path.
Beware the "Unblock" workaround
Windows uses Mark of the Web to identify files originating from untrusted locations.
If someone says:
Right-click the file
Properties
Unblock
understand what you are doing.
You are removing information Windows uses to treat the file as originating from the Internet.
Sometimes that is justified for a verified business file.
It should not become:
Standard instructions for every attachment that doesn't work.
Priority 11: Keep SmartScreen enabled
Microsoft Defender SmartScreen helps protect against:
malicious websites
phishing sites
untrusted applications
dangerous downloads
This is particularly valuable for small businesses because phishing remains one of the easiest ways to obtain initial access.
Do not train users to think:
Windows warned me.
Click Run anyway.
Security controls are useless when the company culture teaches users to bypass them automatically.
Priority 12: Protect credentials
Passwords are not just used at login.
Windows processes, applications and authentication systems handle credentials throughout the session.
Attacker goals often include extracting credentials from:
LSASS
browser stores
cached credentials
tokens
memory
Modern Windows security technologies such as virtualization-based security and Credential Guard can make credential theft harder on supported systems.
For new Windows 11 hardware, evaluate these features rather than automatically disabling them for compatibility with ancient software.
Use Windows Hello for Business where possible
A PIN sounds weaker than a 20-character password until you understand how Windows Hello works.
The important distinction is that a Windows Hello credential is tied to the device and protected using hardware-backed mechanisms such as TPM.
A stolen password can potentially be used elsewhere.
A Windows Hello credential is designed differently.
For managed modern Windows environments:
Windows Hello for Business
+
MFA
is worth considering as part of the identity strategy.
Priority 13: Disable unnecessary services and software
Attack surface is not only Windows configuration.
Look at installed software.
A typical workstation may contain:
Old Java
Old VPN client
Three PDF readers
Remote access software
Vendor update utility
Old printer tools
Abandoned browser extensions
Legacy middleware
Every additional application is:
another thing to patch
another potential vulnerability
another persistence mechanism
Remove software nobody uses.
This is one of the cheapest security improvements available.
Do not install five remote access tools
It is surprisingly common to find:
AnyDesk
TeamViewer
RustDesk
Quick Assist
vendor remote agent
old MSP agent
on the same workstation.
That creates unnecessary attack surface.
Decide which remote administration tools the organization actually allows.
Remove the rest.
Priority 14: Control browser extensions
Browser extensions are software.
They can potentially access:
webpage contents
cookies
form data
browser sessions
A business browser policy should ideally restrict unnecessary extensions.
At minimum:
Remove abandoned extensions
Remove extensions from unknown publishers
Avoid random PDF/download/coupon/search extensions
For centrally managed Edge or Chrome deployments, consider extension allowlists where practical.
Priority 15: Configure screen locking
This is boring.
It is also necessary.
If an employee walks away from a logged-in computer for an hour, an attacker does not need an exploit.
They need a chair.
Require automatic locking after a reasonable period of inactivity.
Also train users to use:
Win + L
when leaving the desk.
Physical access is still access.
Priority 16: Disable unnecessary autorun behavior
USB devices and removable media remain relevant.
Organizations with higher exposure may want additional controls around:
USB storage
removable media
unknown devices
You do not necessarily need to disable USB storage across a ten-person architecture company.
But you should at least know whether employees regularly move sensitive files onto random USB drives.
Hardening should reflect real business risk.
Priority 17: Backups are part of endpoint hardening
This might sound unrelated.
It is not.
Ransomware defense has two objectives:
Prevent compromise
and:
Survive compromise
Backups solve the second problem.
A company should have:
multiple backup copies
+
offsite or isolated copy
+
retention
+
restore testing
A backup continuously mounted with administrative write access from every workstation may simply become:
more data for ransomware to encrypt.
Test restores
A backup job saying:
SUCCESS
means:
The backup software believes it wrote something.
It does not prove:
You can restore the company.
Periodically restore:
a file
a folder
a VM
a database
depending on your environment.
A backup without restore testing is an assumption.
Priority 18: Logging matters
Small companies often investigate incidents with:
We don't know.
The logs are already gone.
At minimum, retain enough information to answer:
Who logged in?
From where?
Which account became administrator?
Was Defender disabled?
Did a process get blocked?
When was software installed?
When did the incident start?
If you have centralized monitoring:
Microsoft Defender for Business
Wazuh
Sentinel
SIEM
send useful endpoint events there.
You do not need to ingest every Windows event ever created.
Start with events that help investigate real incidents.
Priority 19: Do not share administrator passwords
Another classic small-business design:
Administrator password:
Company2026!
known by:
IT
accountant
manager
external technician
printer technician
the guy who installed the ERP in 2018
Do not do this.
Administrative access should be attributable.
You should know:
Who logged in?
Not:
Someone using Administrator.
Use individual accounts where possible.
Use LAPS for local recovery accounts.
Priority 20: Protect management systems even more strongly
Your IT administrator's workstation is more valuable than a normal user workstation.
Because it may access:
Microsoft 365 Admin Center
Intune
Entra ID
firewalls
hypervisors
backup systems
servers
DNS
domain controllers
Consider separating administrative activity from ordinary browsing and email.
For example:
Normal workstation/session
↓
Email
Teams
Web
Administrative workstation/session
↓
Management portals
Servers
Infrastructure
Even a small company can implement some version of this concept.
A realistic small-business baseline
If I had to secure a 30-person Windows environment without creating an enterprise security bureaucracy, my minimum would look something like this:
Windows 11 Pro
+
Users are standard users
+
Separate IT admin accounts
+
Windows LAPS
+
BitLocker
+
Microsoft Defender
+
Tamper Protection
+
Cloud protection
+
ASR rules
+
Windows Firewall
+
No Internet-facing RDP
+
NLA for required RDP
+
SMBv1 disabled
+
Automatic patching
+
Office macro protection
+
SmartScreen
+
MFA
+
Central device inventory
+
Tested backups
That architecture is not exotic.
Most of the technology is already included in Windows or Microsoft 365 environments.
The difficult part is configuration and discipline.
A 15-minute workstation audit
Open PowerShell as Administrator.
1. Check local administrators
Get-LocalGroupMember Administrators
Investigate unexpected users.
2. Check Defender
Get-MpComputerStatus |
Select-Object AntivirusEnabled,
RealTimeProtectionEnabled,
BehaviorMonitorEnabled
Expected:
True
True
True
3. Check firewall
Get-NetFirewallProfile |
Select-Object Name,Enabled
Expected:
Domain True
Private True
Public True
4. Check BitLocker
Get-BitLockerVolume |
Select-Object MountPoint,
VolumeStatus,
ProtectionStatus
Look for:
FullyEncrypted
Protection On
5. Check SMBv1
Get-SmbServerConfiguration |
Select-Object EnableSMB1Protocol
Prefer:
False
where legacy compatibility is not required.
6. Check RDP
Get-Service TermService
Ask whether Remote Desktop is actually required.
If not:
disable unnecessary remote access
7. Check Windows version
Get-ComputerInfo |
Select-Object WindowsProductName,
WindowsVersion,
OsBuildNumber
Confirm the OS is supported.
8. Check recent patches
Get-HotFix |
Sort-Object InstalledOn -Descending |
Select-Object -First 10
Look for machines that stopped receiving updates months ago.
A useful PowerShell inventory command
You can combine several checks:
Write-Host "=== COMPUTER ==="
hostname
Write-Host "`n=== WINDOWS ==="
Get-ComputerInfo |
Select WindowsProductName, WindowsVersion, OsBuildNumber
Write-Host "`n=== LOCAL ADMINS ==="
Get-LocalGroupMember Administrators
Write-Host "`n=== DEFENDER ==="
Get-MpComputerStatus |
Select AntivirusEnabled,
RealTimeProtectionEnabled,
BehaviorMonitorEnabled
Write-Host "`n=== FIREWALL ==="
Get-NetFirewallProfile |
Select Name, Enabled
Write-Host "`n=== BITLOCKER ==="
Get-BitLockerVolume |
Select MountPoint,
VolumeStatus,
ProtectionStatus
Write-Host "`n=== SMB1 ==="
Get-SmbServerConfiguration |
Select EnableSMB1Protocol
Write-Host "`n=== RDP ==="
Get-Service TermService
This is not a vulnerability scanner.
But it gives you a very fast picture of whether a workstation is obviously poorly configured.
What not to do
Hardening can also go wrong.
Do not simply copy 600 registry settings from a random GitHub repository.
Do not deploy every CIS Level 2 recommendation to the entire company without understanding it.
Do not disable services just because someone on a forum called them unnecessary.
Do not turn off IPv6 because:
We don't use IPv6.
Do not disable Windows Defender because another tool once generated a false positive.
Do not disable the firewall because an application failed.
Do not permanently use one shared local administrator password.
Do not expose RDP because configuring VPN takes longer.
Do not exempt:
C:\
from antivirus scanning because one application is slow.
Security configuration needs engineering.
Not superstition.
Hardening should happen in stages
A practical deployment might be:
PHASE 1
Inventory
Windows updates
Defender
Firewall
BitLocker
Local administrator cleanup
Then:
PHASE 2
LAPS
ASR audit mode
Macro policies
RDP restrictions
SMB cleanup
Then:
PHASE 3
ASR block mode
Central monitoring
Browser policies
Application control
Additional credential protections
This is much easier to manage than changing everything at once.
Test before production
Create a pilot group.
For example:
IT administrator
+
one accounting computer
+
one engineering computer
+
one normal office workstation
Why different departments?
Because accounting may use:
old Excel macros
bank software
ERP plugins
while engineering may use:
CAD software
license managers
special drivers
Security policies that work perfectly on a clean IT laptop may behave very differently on a ten-year-old business application.
Document exceptions
Suppose an application genuinely requires something insecure.
Do not simply disable the security setting globally.
Document:
Control:
ASR rule X
Exception:
Accounting workstation group
Reason:
Legacy ERP component
Owner:
Finance
Review date:
2027-01-15
Replacement plan:
Upgrade ERP
Exceptions should expire.
Otherwise:
Temporary exception
becomes:
Permanent architecture.
Hardening is not a one-time project
The worst possible process is:
2026:
Windows hardening project completed.
2027:
Nobody checked again.
Your environment changes.
Microsoft changes Windows.
Applications change.
Threats change.
Users install things.
New laptops arrive.
Policies break.
Review the baseline periodically.
At minimum:
OS support status
patch compliance
Defender health
BitLocker status
local administrators
LAPS coverage
ASR events
firewall status
RDP exposure
software inventory
Small-business hardening priority list
If your environment is currently mostly default Windows installations, do these first:
1. Remove users from Local Administrators.
2. Deploy LAPS.
3. Enable BitLocker.
4. Verify Defender is fully enabled.
5. Enable Tamper Protection.
6. Enable cloud-delivered protection.
7. Deploy ASR rules in Audit mode.
8. Keep Windows Firewall enabled.
9. Remove Internet-facing RDP.
10. Disable SMBv1.
11. Patch Windows consistently.
12. Upgrade unsupported Windows versions.
13. Protect Office macros.
14. Keep SmartScreen enabled.
15. Ensure backups cannot be destroyed by normal users.
This will give a small organization far more security value than buying another dashboard nobody monitors.
What should cost money?
A lot of Windows hardening does not require another security product.
Many useful controls already exist in:
Windows
Microsoft Defender
Microsoft Entra ID
Microsoft Intune
Microsoft 365
Before buying another:
AI-powered zero-trust next-generation endpoint cyber platform
make sure the basics are actually configured.
Because an expensive EDR agent does not fix:
Everyone is local admin.
Every PC has the same admin password.
RDP is open to the Internet.
BitLocker is disabled.
Backups are writable from user PCs.
Windows Update is disabled.
Architecture beats product collection.
The 80/20 rule of Windows hardening
For a small business, a relatively small number of controls deliver most of the practical security improvement.
The big ones are:
Least privilege
Unique admin credentials
Patch management
Endpoint protection
Attack Surface Reduction
Encryption
Firewall
Remote access restrictions
Macro protection
Backups
Get those right first.
Only then worry about obscure registry values.
Final thoughts
Windows is not inherently impossible to secure.
The bigger problem is that many business environments slowly accumulate insecure decisions:
Make him administrator because the software complains.
Disable the firewall because the printer doesn't work.
Use the same password because support needs access.
Open RDP because somebody works from home.
Disable Defender because the ERP folder is slow.
Ignore BitLocker because the laptop has a password.
Each individual shortcut feels small.
Together they create an environment where one compromised computer can become a company-wide incident.
Hardening reverses that process.
Not by buying one magical security product.
But by removing unnecessary trust.
Instead of:
Every user can administer the machine.
use:
Standard user.
Instead of:
One admin password everywhere.
use:
LAPS.
Instead of:
RDP from anywhere.
use:
VPN or controlled remote access.
Instead of:
Maybe the laptop is encrypted.
use:
BitLocker compliance.
Instead of:
Hopefully Defender is running.
use:
Central monitoring.
The objective is simple:
A compromised user should not automatically become a compromised computer, and a compromised computer should not automatically become a compromised company.
That is what Windows hardening is really about.