Advanced Windows hardening configurations
Next, let's look at the advanced Windows hardening configurations to deploy to your client workstations. These configurations will cover user authentication with biometrics and PINs, risk prevention by setting up Defender AV scan settings and SmartScreen filters, and the protection of user data with BitLocker Drive Encryption. We will also discuss how to mitigate common attack vectors, such as name resolution poisoning and Man-in-the-Middle (MITM) attacks, that can be overlooked in your default Windows baseline policies and put your systems at risk from an inside attack.
First, let's look at using Windows Hello for Business to replace passwords as an authentication mechanism.
Enabling Windows Hello for Business
Windows Hello for Business is a great first step in a passwordless journey and enables the use of biometric sensors or device PINs as an alternative way to log in to Windows. Windows Hello for Business is backed by...