——
GuideHARDENING

Windows Hardening for Small Business: A Practical Guide That Actually Works

A practical Windows hardening guide for small businesses. Secure local administrators, Defender, BitLocker, RDP, firewall, LAPS, ASR rules, Office macros, updates and backups without building an enterprise security department.

A practical Windows hardening guide for small businesses. Secure local administrators, Defender, BitLocker, RDP, firewall, LAPS, ASR rules, Office macros, updates and backups without building an enterprise security department.

WindowsWindows 11hardeningcybersecuritysmall businessMicrosoft DefenderLAPSBitLockerASRsysadminransomware

Small businesses often have an unusual security problem.

They are large enough to be interesting to attackers...

but too small to have:

SOC team
Security engineer
24/7 monitoring
Dedicated IAM team
Dedicated endpoint team
Dedicated incident response team

Instead, there is usually:

One IT administrator

or:

One MSP

responsible for everything.

The firewall.

Microsoft 365.

Wi-Fi.

Printers.

Servers.

Backups.

Laptops.

VPN.

And somehow also cybersecurity.

The good news is that you do not need a Fortune 500 security architecture to make Windows significantly harder to compromise.

A relatively small number of configuration changes eliminate a surprisingly large amount of risk.

This guide focuses on exactly that.

Not theoretical maximum security.

Not a 400-page compliance framework.

But:

What should a small business actually change on its Windows computers?


Hardening is not installing antivirus

One of the biggest misunderstandings about endpoint security is this:

We have antivirus.

Therefore Windows is secure.

Antivirus is only one layer.

A typical ransomware incident might look like:

Phishing email
     ↓
User downloads file
     ↓
Script runs
     ↓
Credentials stolen
     ↓
Attacker obtains administrator rights
     ↓
Moves to another computer
     ↓
Disables security
     ↓
Encrypts files

Antivirus might stop one step.

Hardening attempts to break the attack chain at several different points.

For example:

No local admin rights
        +
Attack Surface Reduction
        +
Defender
        +
Firewall
        +
LAPS
        +
BitLocker
        +
Patching
        +
Macro restrictions
        +
RDP restrictions

Now the attacker has to defeat multiple controls.

That is the goal.


Start with a security baseline

Do not invent your Windows security configuration from scratch.

Microsoft publishes Windows security baselines containing recommended settings for managed environments.

For small organizations, the baseline should be considered:

STARTING POINT

not:

CLICK EVERYTHING AND DEPLOY TO PRODUCTION

The sensible approach is:

Microsoft baseline
       ↓
Test devices
       ↓
Identify compatibility problems
       ↓
Adjust where justified
       ↓
Production

Security baselines can be managed through environments such as:

Group Policy
Microsoft Intune
Local policy

For a small company using Microsoft 365 Business Premium and Intune, cloud-based management is often significantly easier than maintaining a large traditional Group Policy environment.


Priority 1: Users should not be local administrators

If you only implement one recommendation from this entire article, start here.

A normal employee should not perform everyday work using an account with local administrator privileges.

Bad:

John
Member of:
Administrators

Better:

John
Member of:
Users

with a separate administrative mechanism available when IT actually needs elevated privileges.

Why?

Because malware running as:

standard user

has fewer opportunities than malware running as:

local administrator

The difference is enormous.


Check who is a local administrator

PowerShell:

Get-LocalGroupMember -Group Administrators

Example:

ObjectClass Name
----------- ----
User        PC001\Administrator
User        PC001\john
Group       AzureAD\IT Administrators

Ask:

Why is john an administrator?

If the answer is:

He sometimes installs software.

that is usually not a good enough reason.


Use separate administrator accounts

A common small-business mistake is having one account:

john@example.com

used for:

Email
Teams
Browsing
Microsoft 365 administration
Endpoint administration
Server administration

That dramatically increases risk.

A better model:

john@example.com

Normal daily account.

And:

adm-john@example.com

Administrative account.

The administrator account should not be used for:

email
web browsing
daily Teams communication
random downloads

The more powerful the account, the less frequently it should be used.


Priority 2: Use Windows LAPS

One of the most dangerous configurations in a small Windows environment is this:

PC001
localadmin / SamePassword123!

PC002
localadmin / SamePassword123!

PC003
localadmin / SamePassword123!

PC004
localadmin / SamePassword123!

Compromise one machine and the attacker now potentially has credentials that work everywhere.

This is exactly the problem Windows LAPS solves.

LAPS stands for:

Local Administrator Password Solution

It automatically manages unique local administrator passwords.

Conceptually:

PC001 → Random password A

PC002 → Random password B

PC003 → Random password C

PC004 → Random password D

Passwords are rotated automatically and stored securely in:

Microsoft Entra ID

or:

Active Directory

depending on your environment.


Why LAPS matters

Without LAPS:

Compromise PC001
      ↓
Steal local admin password
      ↓
Try same password on PC002
      ↓
Works
      ↓
Lateral movement

With LAPS:

Compromise PC001
      ↓
Steal PC001 local admin password
      ↓
Try on PC002
      ↓
FAIL

That one change can make lateral movement significantly harder.


Priority 3: Enable BitLocker

Every business laptop should be considered stealable.

Because it is.

Employees use laptops:

at home
in cars
at hotels
at airports
at customer sites
in cafés

Eventually one disappears.

Without disk encryption, an attacker can potentially remove the drive or boot another operating system and access data offline.

BitLocker encrypts the volume.

Conceptually:

Laptop stolen
      ↓
SSD removed
      ↓
Attacker connects SSD elsewhere
      ↓
Encrypted data
      ↓
Unreadable without recovery material

Check BitLocker:

Get-BitLockerVolume

You want to see something like:

VolumeStatus     FullyEncrypted
ProtectionStatus On

For managed devices, recovery keys should be centrally escrowed.

Possible locations include:

Microsoft Entra ID
Active Directory

Do not build your recovery strategy around:

The employee probably wrote the BitLocker key somewhere.

Priority 4: Keep Microsoft Defender enabled

For many small organizations, Microsoft Defender Antivirus is perfectly capable when configured correctly.

But:

Defender installed

and:

Defender configured properly

are not the same thing.

Check status:

Get-MpComputerStatus

Important fields include:

AntivirusEnabled
RealTimeProtectionEnabled
BehaviorMonitorEnabled
IoavProtectionEnabled
AntispywareEnabled

You generally want protection enabled.


Enable cloud-delivered protection

Modern endpoint protection benefits from Microsoft's cloud intelligence.

Check:

Get-MpPreference |
Select-Object MAPSReporting

Cloud-delivered protection can help Defender react to newly observed threats faster than relying only on static local signatures.

In centrally managed environments, configure this through your management platform rather than manually on every PC.


Enable tamper protection

Imagine malware obtains administrative privileges.

One of the first things it may try is:

Disable antivirus

Tamper Protection is designed to make unauthorized changes to critical Defender settings harder.

This matters because an endpoint security product that malware can simply turn off is not a particularly useful endpoint security product.

For managed businesses, enable and monitor Tamper Protection centrally.


Priority 5: Use Attack Surface Reduction rules

Attack Surface Reduction rules — usually called ASR rules — are some of the most useful Windows hardening controls available.

They do not merely ask:

Is this file malware?

They can prevent behaviors commonly used during attacks.

Examples include blocking or restricting behaviors involving:

Office creating child processes

Office creating executable content

credential theft from LSASS

scripts launching downloaded executables

Adobe Reader spawning child processes

process injection

ransomware behavior

This is extremely powerful.


Example: Office attack chain

Without ASR:

Invoice.docx
     ↓
Word
     ↓
PowerShell
     ↓
Download payload
     ↓
Execute malware

With appropriate ASR rules:

Invoice.docx
     ↓
Word
     ↓
Attempt to launch PowerShell
     ↓
BLOCKED

The malicious file may exist.

But the attack chain is broken.


Do not immediately set every ASR rule to Block

This is an important operational lesson.

ASR has modes such as:

Audit
Warn
Block

A good deployment process is:

Audit
   ↓
Monitor legitimate applications
   ↓
Fix exclusions if genuinely necessary
   ↓
Block

Do not deploy twenty security controls at 16:55 on Friday and then discover Monday morning that the accounting system depends on behavior you just blocked.

Security needs change management too.


Priority 6: Windows Firewall stays ON

Another surprisingly common configuration:

Windows Firewall disabled

Why?

Usually:

Something didn't work once.

So somebody solved it using:

Turn firewall off.

That is troubleshooting by surrender.

Windows Firewall should normally remain enabled for:

Domain
Private
Public

Check:

Get-NetFirewallProfile |
Select-Object Name, Enabled

Expected:

Name     Enabled
----     -------
Domain   True
Private  True
Public   True

Default inbound policy should be restrictive

Most workstations do not need arbitrary inbound connectivity.

Think:

OUTBOUND
Generally allowed

INBOUND
Blocked unless required

If an application requires a port, create a specific rule.

For example:

Application:
Management Agent

Port:
TCP 12345

Source:
10.1.10.0/24

is better than:

Allow all inbound traffic.

Do not create "Any → Any" firewall rules

Bad:

Source:
Any

Destination:
Any

Protocol:
Any

Action:
Allow

Better:

Source:
Management VLAN

Destination:
Workstations

Protocol:
Required management service only

Firewall rules should answer:

Who needs access?

To what?

On which port?

Why?

If nobody can answer those questions, the rule probably should not exist.


Priority 7: Do not expose RDP directly to the Internet

This deserves capital letters.

Do not do this:

INTERNET
    ↓
TCP 3389
    ↓
Windows PC

Changing:

3389

to:

43892

does not meaningfully fix the problem.

It merely moves the door.

Use something such as:

VPN
Zero Trust access
RD Gateway
secured remote management platform

instead.


If you use RDP, keep NLA enabled

Network Level Authentication requires authentication before the full remote desktop session is established.

Check RDP configuration through policy rather than manually wherever possible.

Conceptually:

Without NLA:

Connection
    ↓
RDP session resources
    ↓
Authentication

With NLA:

Connection
    ↓
Authentication
    ↓
RDP session

Also restrict which users are actually allowed to use Remote Desktop.

Not everyone needs RDP.


Check whether RDP is needed at all

On many employee computers the correct configuration is simply:

Remote Desktop:
Disabled

If IT administration uses another remote support tool, there may be no reason to leave RDP enabled.

Reduce unnecessary attack surface.

A service you do not run cannot be exploited remotely.


Priority 8: Remove SMBv1

SMBv1 belongs in history.

If a device still requires SMBv1, ask:

Why?

Usually the answer is:

Old scanner
Old NAS
Old software
Old industrial device

That does not automatically mean SMBv1 should be enabled throughout the company.

Check SMB1 server configuration:

Get-SmbServerConfiguration |
Select-Object EnableSMB1Protocol

Check optional feature status:

Get-WindowsOptionalFeature `
-Online `
-FeatureName SMB1Protocol

For modern Windows environments, SMBv1 should normally be disabled.

If one legacy system absolutely requires it, isolate the problem rather than weakening every computer.


Priority 9: Patch Windows automatically

Hardening an unpatched computer is like installing a high-security door while leaving the window open.

For workstations, establish predictable update deployment.

A sensible model might be:

Microsoft releases updates
       ↓
Small pilot group
       ↓
Short validation period
       ↓
General deployment

Not:

Disable Windows Update
because users dislike restarts.

Windows 10 needs special attention

A small business should inventory old Windows 10 devices.

By 2026, ordinary Windows 10 editions are no longer on normal standard support unless the organization is using an applicable Extended Security Updates arrangement.

The preferred long-term direction is:

Windows 11

on supported hardware.

Do not let:

It still turns on.

become your lifecycle policy.

Old unsupported operating systems accumulate security risk.


Check OS versions

PowerShell:

Get-ComputerInfo |
Select-Object WindowsProductName,
              WindowsVersion,
              OsBuildNumber

For inventory across many machines, collect this centrally.

You need to know:

What do we have?

Which builds?

Which machines are unsupported?

Which machines have missed updates?

You cannot secure devices you do not know exist.


Priority 10: Harden Microsoft Office

Office documents remain an attractive attack vector.

The classic attack:

Invoice.xlsm
      ↓
User opens file
      ↓
Macro runs
      ↓
Script executes
      ↓
Payload downloaded

Modern Office versions already provide substantial protections against macros originating from the Internet.

Do not weaken them because one employee wants to run a random spreadsheet from email.


Macro policy

For users who do not need macros:

Macros disabled

is a perfectly reasonable policy.

For environments that genuinely require macros:

Signed macros
+
Trusted publishers
+
Controlled trusted locations

is preferable to:

Enable all macros

Never create a giant writable network share and mark the entire thing trusted.

That simply creates a new attack path.


Beware the "Unblock" workaround

Windows uses Mark of the Web to identify files originating from untrusted locations.

If someone says:

Right-click the file
Properties
Unblock

understand what you are doing.

You are removing information Windows uses to treat the file as originating from the Internet.

Sometimes that is justified for a verified business file.

It should not become:

Standard instructions for every attachment that doesn't work.

Priority 11: Keep SmartScreen enabled

Microsoft Defender SmartScreen helps protect against:

malicious websites
phishing sites
untrusted applications
dangerous downloads

This is particularly valuable for small businesses because phishing remains one of the easiest ways to obtain initial access.

Do not train users to think:

Windows warned me.

Click Run anyway.

Security controls are useless when the company culture teaches users to bypass them automatically.


Priority 12: Protect credentials

Passwords are not just used at login.

Windows processes, applications and authentication systems handle credentials throughout the session.

Attacker goals often include extracting credentials from:

LSASS
browser stores
cached credentials
tokens
memory

Modern Windows security technologies such as virtualization-based security and Credential Guard can make credential theft harder on supported systems.

For new Windows 11 hardware, evaluate these features rather than automatically disabling them for compatibility with ancient software.


Use Windows Hello for Business where possible

A PIN sounds weaker than a 20-character password until you understand how Windows Hello works.

The important distinction is that a Windows Hello credential is tied to the device and protected using hardware-backed mechanisms such as TPM.

A stolen password can potentially be used elsewhere.

A Windows Hello credential is designed differently.

For managed modern Windows environments:

Windows Hello for Business
+
MFA

is worth considering as part of the identity strategy.


Priority 13: Disable unnecessary services and software

Attack surface is not only Windows configuration.

Look at installed software.

A typical workstation may contain:

Old Java
Old VPN client
Three PDF readers
Remote access software
Vendor update utility
Old printer tools
Abandoned browser extensions
Legacy middleware

Every additional application is:

another thing to patch
another potential vulnerability
another persistence mechanism

Remove software nobody uses.

This is one of the cheapest security improvements available.


Do not install five remote access tools

It is surprisingly common to find:

AnyDesk
TeamViewer
RustDesk
Quick Assist
vendor remote agent
old MSP agent

on the same workstation.

That creates unnecessary attack surface.

Decide which remote administration tools the organization actually allows.

Remove the rest.


Priority 14: Control browser extensions

Browser extensions are software.

They can potentially access:

webpage contents
cookies
form data
browser sessions

A business browser policy should ideally restrict unnecessary extensions.

At minimum:

Remove abandoned extensions

Remove extensions from unknown publishers

Avoid random PDF/download/coupon/search extensions

For centrally managed Edge or Chrome deployments, consider extension allowlists where practical.


Priority 15: Configure screen locking

This is boring.

It is also necessary.

If an employee walks away from a logged-in computer for an hour, an attacker does not need an exploit.

They need a chair.

Require automatic locking after a reasonable period of inactivity.

Also train users to use:

Win + L

when leaving the desk.

Physical access is still access.


Priority 16: Disable unnecessary autorun behavior

USB devices and removable media remain relevant.

Organizations with higher exposure may want additional controls around:

USB storage
removable media
unknown devices

You do not necessarily need to disable USB storage across a ten-person architecture company.

But you should at least know whether employees regularly move sensitive files onto random USB drives.

Hardening should reflect real business risk.


Priority 17: Backups are part of endpoint hardening

This might sound unrelated.

It is not.

Ransomware defense has two objectives:

Prevent compromise

and:

Survive compromise

Backups solve the second problem.

A company should have:

multiple backup copies
+
offsite or isolated copy
+
retention
+
restore testing

A backup continuously mounted with administrative write access from every workstation may simply become:

more data for ransomware to encrypt.

Test restores

A backup job saying:

SUCCESS

means:

The backup software believes it wrote something.

It does not prove:

You can restore the company.

Periodically restore:

a file
a folder
a VM
a database

depending on your environment.

A backup without restore testing is an assumption.


Priority 18: Logging matters

Small companies often investigate incidents with:

We don't know.

The logs are already gone.

At minimum, retain enough information to answer:

Who logged in?

From where?

Which account became administrator?

Was Defender disabled?

Did a process get blocked?

When was software installed?

When did the incident start?

If you have centralized monitoring:

Microsoft Defender for Business
Wazuh
Sentinel
SIEM

send useful endpoint events there.

You do not need to ingest every Windows event ever created.

Start with events that help investigate real incidents.


Priority 19: Do not share administrator passwords

Another classic small-business design:

Administrator password:

Company2026!

known by:

IT
accountant
manager
external technician
printer technician
the guy who installed the ERP in 2018

Do not do this.

Administrative access should be attributable.

You should know:

Who logged in?

Not:

Someone using Administrator.

Use individual accounts where possible.

Use LAPS for local recovery accounts.


Priority 20: Protect management systems even more strongly

Your IT administrator's workstation is more valuable than a normal user workstation.

Because it may access:

Microsoft 365 Admin Center
Intune
Entra ID
firewalls
hypervisors
backup systems
servers
DNS
domain controllers

Consider separating administrative activity from ordinary browsing and email.

For example:

Normal workstation/session
        ↓
Email
Teams
Web

Administrative workstation/session
        ↓
Management portals
Servers
Infrastructure

Even a small company can implement some version of this concept.


A realistic small-business baseline

If I had to secure a 30-person Windows environment without creating an enterprise security bureaucracy, my minimum would look something like this:

Windows 11 Pro
        +
Users are standard users
        +
Separate IT admin accounts
        +
Windows LAPS
        +
BitLocker
        +
Microsoft Defender
        +
Tamper Protection
        +
Cloud protection
        +
ASR rules
        +
Windows Firewall
        +
No Internet-facing RDP
        +
NLA for required RDP
        +
SMBv1 disabled
        +
Automatic patching
        +
Office macro protection
        +
SmartScreen
        +
MFA
        +
Central device inventory
        +
Tested backups

That architecture is not exotic.

Most of the technology is already included in Windows or Microsoft 365 environments.

The difficult part is configuration and discipline.


A 15-minute workstation audit

Open PowerShell as Administrator.

1. Check local administrators

Get-LocalGroupMember Administrators

Investigate unexpected users.


2. Check Defender

Get-MpComputerStatus |
Select-Object AntivirusEnabled,
              RealTimeProtectionEnabled,
              BehaviorMonitorEnabled

Expected:

True
True
True

3. Check firewall

Get-NetFirewallProfile |
Select-Object Name,Enabled

Expected:

Domain   True
Private  True
Public   True

4. Check BitLocker

Get-BitLockerVolume |
Select-Object MountPoint,
              VolumeStatus,
              ProtectionStatus

Look for:

FullyEncrypted
Protection On

5. Check SMBv1

Get-SmbServerConfiguration |
Select-Object EnableSMB1Protocol

Prefer:

False

where legacy compatibility is not required.


6. Check RDP

Get-Service TermService

Ask whether Remote Desktop is actually required.

If not:

disable unnecessary remote access

7. Check Windows version

Get-ComputerInfo |
Select-Object WindowsProductName,
              WindowsVersion,
              OsBuildNumber

Confirm the OS is supported.


8. Check recent patches

Get-HotFix |
Sort-Object InstalledOn -Descending |
Select-Object -First 10

Look for machines that stopped receiving updates months ago.


A useful PowerShell inventory command

You can combine several checks:

Write-Host "=== COMPUTER ==="
hostname

Write-Host "`n=== WINDOWS ==="
Get-ComputerInfo |
Select WindowsProductName, WindowsVersion, OsBuildNumber

Write-Host "`n=== LOCAL ADMINS ==="
Get-LocalGroupMember Administrators

Write-Host "`n=== DEFENDER ==="
Get-MpComputerStatus |
Select AntivirusEnabled,
       RealTimeProtectionEnabled,
       BehaviorMonitorEnabled

Write-Host "`n=== FIREWALL ==="
Get-NetFirewallProfile |
Select Name, Enabled

Write-Host "`n=== BITLOCKER ==="
Get-BitLockerVolume |
Select MountPoint,
       VolumeStatus,
       ProtectionStatus

Write-Host "`n=== SMB1 ==="
Get-SmbServerConfiguration |
Select EnableSMB1Protocol

Write-Host "`n=== RDP ==="
Get-Service TermService

This is not a vulnerability scanner.

But it gives you a very fast picture of whether a workstation is obviously poorly configured.


What not to do

Hardening can also go wrong.

Do not simply copy 600 registry settings from a random GitHub repository.

Do not deploy every CIS Level 2 recommendation to the entire company without understanding it.

Do not disable services just because someone on a forum called them unnecessary.

Do not turn off IPv6 because:

We don't use IPv6.

Do not disable Windows Defender because another tool once generated a false positive.

Do not disable the firewall because an application failed.

Do not permanently use one shared local administrator password.

Do not expose RDP because configuring VPN takes longer.

Do not exempt:

C:\

from antivirus scanning because one application is slow.

Security configuration needs engineering.

Not superstition.


Hardening should happen in stages

A practical deployment might be:

PHASE 1

Inventory
Windows updates
Defender
Firewall
BitLocker
Local administrator cleanup

Then:

PHASE 2

LAPS
ASR audit mode
Macro policies
RDP restrictions
SMB cleanup

Then:

PHASE 3

ASR block mode
Central monitoring
Browser policies
Application control
Additional credential protections

This is much easier to manage than changing everything at once.


Test before production

Create a pilot group.

For example:

IT administrator
+
one accounting computer
+
one engineering computer
+
one normal office workstation

Why different departments?

Because accounting may use:

old Excel macros
bank software
ERP plugins

while engineering may use:

CAD software
license managers
special drivers

Security policies that work perfectly on a clean IT laptop may behave very differently on a ten-year-old business application.


Document exceptions

Suppose an application genuinely requires something insecure.

Do not simply disable the security setting globally.

Document:

Control:
ASR rule X

Exception:
Accounting workstation group

Reason:
Legacy ERP component

Owner:
Finance

Review date:
2027-01-15

Replacement plan:
Upgrade ERP

Exceptions should expire.

Otherwise:

Temporary exception

becomes:

Permanent architecture.

Hardening is not a one-time project

The worst possible process is:

2026:
Windows hardening project completed.

2027:
Nobody checked again.

Your environment changes.

Microsoft changes Windows.

Applications change.

Threats change.

Users install things.

New laptops arrive.

Policies break.

Review the baseline periodically.

At minimum:

OS support status
patch compliance
Defender health
BitLocker status
local administrators
LAPS coverage
ASR events
firewall status
RDP exposure
software inventory

Small-business hardening priority list

If your environment is currently mostly default Windows installations, do these first:

1. Remove users from Local Administrators.

2. Deploy LAPS.

3. Enable BitLocker.

4. Verify Defender is fully enabled.

5. Enable Tamper Protection.

6. Enable cloud-delivered protection.

7. Deploy ASR rules in Audit mode.

8. Keep Windows Firewall enabled.

9. Remove Internet-facing RDP.

10. Disable SMBv1.

11. Patch Windows consistently.

12. Upgrade unsupported Windows versions.

13. Protect Office macros.

14. Keep SmartScreen enabled.

15. Ensure backups cannot be destroyed by normal users.

This will give a small organization far more security value than buying another dashboard nobody monitors.


What should cost money?

A lot of Windows hardening does not require another security product.

Many useful controls already exist in:

Windows
Microsoft Defender
Microsoft Entra ID
Microsoft Intune
Microsoft 365

Before buying another:

AI-powered zero-trust next-generation endpoint cyber platform

make sure the basics are actually configured.

Because an expensive EDR agent does not fix:

Everyone is local admin.

Every PC has the same admin password.

RDP is open to the Internet.

BitLocker is disabled.

Backups are writable from user PCs.

Windows Update is disabled.

Architecture beats product collection.


The 80/20 rule of Windows hardening

For a small business, a relatively small number of controls deliver most of the practical security improvement.

The big ones are:

Least privilege
Unique admin credentials
Patch management
Endpoint protection
Attack Surface Reduction
Encryption
Firewall
Remote access restrictions
Macro protection
Backups

Get those right first.

Only then worry about obscure registry values.


Final thoughts

Windows is not inherently impossible to secure.

The bigger problem is that many business environments slowly accumulate insecure decisions:

Make him administrator because the software complains.

Disable the firewall because the printer doesn't work.

Use the same password because support needs access.

Open RDP because somebody works from home.

Disable Defender because the ERP folder is slow.

Ignore BitLocker because the laptop has a password.

Each individual shortcut feels small.

Together they create an environment where one compromised computer can become a company-wide incident.

Hardening reverses that process.

Not by buying one magical security product.

But by removing unnecessary trust.

Instead of:

Every user can administer the machine.

use:

Standard user.

Instead of:

One admin password everywhere.

use:

LAPS.

Instead of:

RDP from anywhere.

use:

VPN or controlled remote access.

Instead of:

Maybe the laptop is encrypted.

use:

BitLocker compliance.

Instead of:

Hopefully Defender is running.

use:

Central monitoring.

The objective is simple:

A compromised user should not automatically become a compromised computer, and a compromised computer should not automatically become a compromised company.

That is what Windows hardening is really about.