Microsoft baselines and the security compliance toolkit
To help with the hardening of organizations’ environments, Microsoft released the Security Compliance Toolkit. Download the Security Compliance Toolkit from https://www.microsoft.com/en-us/download/details.aspx?id=55319.
This toolkit contains the following:
- Policy Analyzer: A tool to evaluate and compare Group Policies.
- LGPO.exe: A tool to analyze local policies.
- SetObjectSecurity.exe: A tool to configure security descriptors for almost every Windows security object.
- Baselines for each recent operating system: These baselines contain monitoring as well as configuration recommendations.
You can find an overview of all security baseline GPOs if you open the respective GP Reports folder of each baseline:
Figure 6.14 – Overview of all GPOs of a single baseline
All security baselines were created for different configuration purposes. Some of the most important...