Summary
In this chapter, we covered how to secure Windows Server. First, we reviewed different installation options for Windows Server and looked at security enhancements with Windows Server 2019. In the next section, we discussed different server roles and features and highlighted specific roles that could be used as part of your security strategy. Then, we moved on and look at the installation of WSUS on a Windows Server Core installation.
In the next section, we covered Windows updates and how to manage and deploy them using WSUS and Azure Update Management. Then, we reviewed threat protection with Microsoft Defender ATP – specifically, how to onboard your Windows server machines to the ATP service. Afterward, we discussed hardening Windows server and walked through implementing a baseline, reviewed CIS benchmark configurations for Microsoft defaults, and discussed enabling Azure Disk Encryption. Finally, we covered how to deploy a Windows Defender Application Control...