Filter
Exclude
Time range
-
Near
๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐——๐—ผ ๐—ฌ๐—ผ๐˜‚ ๐—จ๐˜€๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€? Security Baselines are one of the ๐—บ๐—ผ๐˜€๐˜ ๐—ฐ๐—ฟ๐—ถ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—ฐ๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐˜€ for locking down your Windows infrastructure. They allow you to enforce a ๐—ฑ๐—ฒ๐—ณ๐—ถ๐—ป๐—ฒ๐—ฑ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐˜€๐˜๐—ฎ๐˜๐—ฒ across your environment via Group Policy or Microsoft Intuneโ€”hundreds of settings, centrally managed. Microsoft provides free Security Baselines. Stricter ones exist tooโ€”often behind a paywall. Or you can build your own. (I break this down in detail inside my ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—œ๐—ป๐—ณ๐—ฟ๐—ฎ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—–๐—ผ๐˜‚๐—ฟ๐˜€๐—ฒ.) But hereโ€™s the catch: ๐—œ๐—บ๐—ฝ๐—น๐—ฒ๐—บ๐—ฒ๐—ป๐˜๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ๐—บ ๐—ฐ๐—ฎ๐—ป ๐—ฏ๐—ฟ๐—ฒ๐—ฎ๐—ธ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜. ๐Ÿ’กWhy? Because most real-world environments still rely on ๐—ผ๐˜‚๐˜๐—ฑ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—ฝ๐—ฟ๐—ผ๐˜๐—ผ๐—ฐ๐—ผ๐—น๐˜€ and ๐˜„๐—ฒ๐—ฎ๐—ธ๐—ฒ๐—ฟ ๐—ฐ๐—ฟ๐˜†๐—ฝ๐˜๐—ผ ๐—ฎ๐—น๐—ด๐—ผ๐—ฟ๐—ถ๐˜๐—ต๐—บ๐˜€ like: โ–ช๏ธRC4 โ–ช๏ธLM Hashes โ–ช๏ธNTLM โ–ช๏ธDES โ–ช๏ธOlder TLS versions ...and more. ๐Ÿ”’ And Security Baselines rightfully ๐—ฑ๐—ถ๐˜€๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ฎ๐—น๐—น ๐—ผ๐—ณ ๐˜๐—ต๐—ฒ๐—บ. โ“So how do you implement baselines safely? Treat it as a ๐—ฝ๐—ฟ๐—ผ๐—ท๐—ฒ๐—ฐ๐˜, ๐—ป๐—ผ๐˜ ๐—ฎ ๐—พ๐˜‚๐—ถ๐—ฐ๐—ธ ๐—ณ๐—ถ๐˜…. Years of ignoring best practices canโ€™t be reversed overnight. โœ… Use Microsoftโ€™s ๐—ฃ๐—ผ๐—น๐—ถ๐—ฐ๐˜† ๐—”๐—ป๐—ฎ๐—น๐˜†๐˜‡๐—ฒ๐—ฟ to: โ–ช๏ธCompare your current configuration vs. the baseline โ–ช๏ธIdentify exactly what will change โ–ช๏ธAssess potential impact to applications or services Even though it takes time and careful planning, ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€ ๐—ฎ๐—ฟ๐—ฒ ๐˜„๐—ผ๐—ฟ๐˜๐—ต ๐—ถ๐˜โ€”theyโ€™re one of the strongest foundational measures in Windows security. ๐—›๐—ฎ๐˜ƒ๐—ฒ ๐˜†๐—ผ๐˜‚ ๐—ถ๐—บ๐—ฝ๐—น๐—ฒ๐—บ๐—ฒ๐—ป๐˜๐—ฒ๐—ฑ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€ ๐—ถ๐—ป ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜? Drop a comment belowโ€”curious to see how others are tackling this ๐Ÿ‘‡ #SecurityBaselines #Windows #ActiveDirectory #Cybersecurity @BlueTeamDave
15
86
4,308
๐Ÿ”Ž๐—™๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—™๐—ถ๐—ฒ๐—น๐—ฑ: Real-World Findings from Security Assessments ๐Ÿ“Œ๐Ÿด๐Ÿฒ% of infrastructures I analyzed had ๐—ป๐—ผ ๐—ง๐—ถ๐—ฒ๐—ฟ๐—ถ๐—ป๐—ด ๐— ๐—ผ๐—ฑ๐—ฒ๐—น ๐—ผ๐—ฟ ๐—”๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€ ๐—ฅ๐—ฒ๐˜€๐˜๐—ฟ๐—ถ๐—ฐ๐˜๐—ถ๐—ผ๐—ป๐˜€ in place. This is a critical oversight โ€” especially when attackers gain a foothold in your environment. ๐—›๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐˜„๐—ต๐˜† ๐˜๐—ต๐—ฎ๐˜ ๐—บ๐—ฎ๐˜๐˜๐—ฒ๐—ฟ๐˜€: ๐Ÿšจ By default, Active Directory is too permissive โ–ช๏ธ Privileged accounts can log in anywhere โ–ช๏ธ There are escalation paths everywhere โ–ช๏ธ Secrets get spread across the entire environment Without access restrictions, attackers donโ€™t need zero-days โ€” they just move laterally. ๐—ช๐—ต๐—ฎ๐˜ ๐—ฐ๐—ฎ๐—ป ๐˜†๐—ผ๐˜‚ ๐—ฑ๐—ผ? โœ” Implement a Tiering Model to control where privileged accounts can authenticate. โœ” Restrict access between tiers. โœ” Make secrets useless outside their designated tier. This is one of the most effective defenses in Active Directory โ€” and it doesnโ€™t rely on patching vulnerabilities. ๐Ÿง  I explain Tiering Models and how to implement Access Restrictions in my ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—œ๐—ป๐—ณ๐—ฟ๐—ฎ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฐ๐—ผ๐˜‚๐—ฟ๐˜€๐—ฒ โ€” perfect if you want to secure your AD the right way. ๐Ÿ” Are you using a Tiering Model in your environment? #Windows #Cybersecurity #ActiveDirectory #SecurityBaselines @blueteamdave
8
45
3,392
๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐˜๐—ฟ๐—ฎ๐—ฐ๐—ธ ๐—ก๐—ง๐—Ÿ๐—  ๐˜‚๐˜€๐—ฎ๐—ด๐—ฒ ๐—ฏ๐—ฒ๐—ณ๐—ผ๐—ฟ๐—ฒ ๐—ฒ๐—ป๐—ณ๐—ผ๐—ฟ๐—ฐ๐—ถ๐—ป๐—ด/๐—ฑ๐—ถ๐˜€๐—ฎ๐—ฏ๐—น๐—ถ๐—ป๐—ด ๐—ถ๐˜? NTLM is a legacy protocol thatโ€™s still hanging around in many environments โ€” and itโ€™s a ๐—ฝ๐—ผ๐—ฝ๐˜‚๐—น๐—ฎ๐—ฟ ๐˜๐—ฎ๐—ฟ๐—ด๐—ฒ๐˜ ๐—ณ๐—ผ๐—ฟ ๐—ฎ๐˜๐˜๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ๐˜€. But enforcing strict NTLM restrictions without auditing first? ๐—ง๐—ต๐—ฎ๐˜โ€™๐˜€ ๐—ฎ ๐—ฟ๐—ฒ๐—ฐ๐—ถ๐—ฝ๐—ฒ ๐—ณ๐—ผ๐—ฟ ๐—ผ๐˜‚๐˜๐—ฎ๐—ด๐—ฒ๐˜€. ๐—›๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐—ต๐—ผ๐˜„ ๐˜๐—ผ ๐—ฝ๐—ฟ๐—ผ๐—ฐ๐—ฒ๐—ฒ๐—ฑ ๐˜๐—ต๐—ฒ ๐—ฟ๐—ถ๐—ด๐—ต๐˜ ๐˜„๐—ฎ๐˜†: ๐Ÿ“Œย ย ๐—ข๐—ฝ๐˜๐—ถ๐—ผ๐—ปย ๐Ÿญ: ๐—˜๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ก๐—ง๐—Ÿ๐—  ๐—”๐˜‚๐—ฑ๐—ถ๐˜๐—ถ๐—ป๐—ด Use these GPOs to track NTLM on the Domain Controller side: Security Settings\Local Policies\Security Options\ โ†’ Network security: Restrict NTLM: Audit incoming NTLM traffic โ†’ Network security: Restrict NTLM: Audit NTLM authentication in this domain โœ… These give you Event IDs:ย ๐Ÿด๐Ÿฌ๐Ÿฌ๐Ÿฎ, ๐Ÿด๐Ÿฌ๐Ÿฌ๐Ÿฏ, ๐—ฎ๐—ป๐—ฑ ๐Ÿด๐Ÿฌ๐Ÿฌ๐Ÿฐ. This way you can track NTLM through your domain controllers - no need to collect 4624 on every device. โš ๏ธ ๐——๐—ฟ๐—ฎ๐˜„๐—ฏ๐—ฎ๐—ฐ๐—ธ:ย  They donโ€™t show ๐˜„๐—ต๐—ถ๐—ฐ๐—ต ๐—ก๐—ง๐—Ÿ๐—  ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ถ๐—ผ๐—ปย is used โ€” so theyโ€™re great for auditing overall NTLM usage, but not ideal for enforcingย NTLMv2 only. ๐Ÿ“Œย ๐—ข๐—ฝ๐˜๐—ถ๐—ผ๐—ป ๐Ÿฎ: ๐—–๐—ผ๐—น๐—น๐—ฒ๐—ฐ๐˜ ๐Ÿฐ๐Ÿฒ๐Ÿฎ๐Ÿฐ ๐—Ÿ๐—ผ๐—ด๐˜€ ๐—ผ๐—ป ๐—ฎ๐—น๐—น ๐—ฑ๐—ฒ๐˜ƒ๐—ถ๐—ฐ๐—ฒ๐˜€ Event IDย 4624ย logs on the machine where the user authenticates โ€” thisย doesย ๐—ถ๐—ป๐—ฐ๐—น๐˜‚๐—ฑ๐—ฒ ๐˜๐—ต๐—ฒ ๐—ก๐—ง๐—Ÿ๐—  ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ถ๐—ผ๐—ป and it tells you if NTLMv1 or v2 was used โ€” great for planning phased enforcement. Pair this with Event IDย 4776ย on DCs (less useful alone), and youโ€™ll get the full picture. ๐Ÿ“Œย ๐—ข๐—ฝ๐˜๐—ถ๐—ผ๐—ป ๐Ÿฏ: ๐—ช๐—ฎ๐˜๐—ฐ๐—ต ๐—ณ๐—ผ๐—ฟ ๐—˜๐—ป๐—ต๐—ฎ๐—ป๐—ฐ๐—ฒ๐—ฑ ๐—ก๐—ง๐—Ÿ๐—  ๐—”๐˜‚๐—ฑ๐—ถ๐˜๐—ถ๐—ป๐—ด (๐—–๐—ผ๐—บ๐—ถ๐—ป๐—ด ๐—ฆ๐—ผ๐—ผ๐—ป) A new NTLM auditing mode is on the way inย Windows 11 24H2ย andย Windows Server 2025. This will finally logย who,ย why, andย whereย โ€” ๐—ฑ๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—น๐˜† ๐—ผ๐—ป ๐——๐—ผ๐—บ๐—ฎ๐—ถ๐—ป ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐—น๐—ฒ๐—ฟ๐˜€ โ€” ๐—ฎ๐—ป๐—ฑ ๐—ฒ๐˜ƒ๐—ฒ๐—ป ๐˜€๐—ต๐—ผ๐˜„ ๐˜๐—ต๐—ฒ ๐—ก๐—ง๐—Ÿ๐—  ๐˜ƒ๐—ฒ๐—ฟ๐˜€๐—ถ๐—ผ๐—ป. ๐ŸŽฏ Itโ€™s not fully rolled out yet, but GPO options are already appearing. ๐Ÿง  ๐—ง๐—ฎ๐—ธ๐—ฒ๐—ฎ๐˜„๐—ฎ๐˜†: โ†’ Start with auditing. โ†’ Find whatโ€™s still using NTLM, identify NTLMv1 accounts, andย phase outย usage safely. ๐Ÿ’ฌ Are you planning to enforce NTLMv2 or eliminate NTLM entirely? #NTLM #ActiveDirectory #CyberSecurity #SecureBits #SecurityBaselines #BlueTeam #HorizonSecured @BlueTeamDave
3
46
258
14,859
๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—ช๐—ฎ๐—ป๐˜ ๐˜๐—ผ ๐—ฑ๐—ถ๐˜€๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ฅ๐—–๐Ÿฐ ๐—ฎ๐—ป๐—ฑ ๐—ฒ๐—ป๐—ณ๐—ผ๐—ฟ๐—ฐ๐—ฒ ๐—”๐—˜๐—ฆ ๐—ถ๐—ป ๐—ž๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐˜€? You should โ€” butย ๐—ฑ๐—ผ๐—ปโ€™๐˜ ๐—ฑ๐—ผ ๐—ถ๐˜ ๐—ฏ๐—น๐—ถ๐—ป๐—ฑ๐—น๐˜†. Enforcing strong authentication (like AES-only Kerberos) is an important part of ๐—บ๐—ผ๐—ฑ๐—ฒ๐—ฟ๐—ป ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€ย โ€” just like LDAP signing or NTLM hardening. But in older environments,ย RC4 is still widely used, and flipping the switch ๐—ฐ๐—ฎ๐—ป ๐—ฏ๐—ฟ๐—ฒ๐—ฎ๐—ธ ๐˜๐—ต๐—ถ๐—ป๐—ด๐˜€ ๐—ณ๐—ฎ๐˜€๐˜. ๐Ÿ›‘ย Donโ€™t deploy security baselines without visibility first. ๐—›๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐—ต๐—ผ๐˜„ ๐˜๐—ผ ๐˜€๐—ฎ๐—ณ๐—ฒ๐—น๐˜† ๐˜๐—ฟ๐—ฎ๐—ฐ๐—ธ ๐—ž๐—ฒ๐—ฟ๐—ฏ๐—ฒ๐—ฟ๐—ผ๐˜€ ๐—ฒ๐—ป๐—ฐ๐—ฟ๐˜†๐—ฝ๐˜๐—ถ๐—ผ๐—ป ๐˜‚๐˜€๐—ฎ๐—ด๐—ฒ: ๐Ÿ“ ๐—˜๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ ๐˜๐—ต๐—ฒ ๐—ณ๐—ผ๐—น๐—น๐—ผ๐˜„๐—ถ๐—ป๐—ด ๐—ฎ๐˜‚๐—ฑ๐—ถ๐˜ ๐—ฝ๐—ผ๐—น๐—ถ๐—ฐ๐—ถ๐—ฒ๐˜€: โ†’ Advanced Audit Policy Configuration\Account Logon โœ” Audit Kerberos Authentication Service โœ” Audit Kerberos Service Ticket Operations ๐—ง๐—ต๐—ถ๐˜€ ๐—ฒ๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ๐˜€ ๐—˜๐˜ƒ๐—ฒ๐—ป๐˜ ๐—œ๐——๐˜€ ๐Ÿฐ๐Ÿณ๐Ÿฒ๐Ÿด ๐—ฎ๐—ป๐—ฑ ๐Ÿฐ๐Ÿณ๐Ÿฒ๐Ÿต, ๐˜„๐—ต๐—ถ๐—ฐ๐—ต ๐—น๐—ผ๐—ด: ๐Ÿ”ธ Ticket Encryption Type ๐Ÿ”ธ Pre-Authentication Encryption Type ๐—”๐—ป๐—ฑ ๐˜€๐—ถ๐—ป๐—ฐ๐—ฒ ๐—๐—ฎ๐—ป ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ โ€” ๐—ฒ๐˜…๐˜๐—ฟ๐—ฎ ๐—ณ๐—ถ๐—ฒ๐—น๐—ฑ๐˜€ ๐—น๐—ถ๐—ธ๐—ฒ: ๐Ÿ”น Advertised Etypes ๐Ÿ”น Supported Encryption Types ๐Ÿ”น Available Keys Once you seeย which accounts still rely on ๐—ฅ๐—–๐Ÿฐ, you can fix them โ€” andย safely enforce AESย across the domain. โœ… Audit first. Enforce later. Break nothing. ๐Ÿ“Œ Iโ€™ll continue this series onย real-world challengesย when applying security baselines โ€” and how to do it without breaking legacy systems. #Kerberos #RC4 #AES #SecurityBaselines #SecureBits #WindowsSecurity #ActiveDirectory #BlueTeam #HorizonSecured @BlueTeamDave
3
24
154
7,672
๐Ÿ”’ย Secure Bits ๐Ÿ’ก ๐—›๐—ผ๐˜„ ๐˜๐—ผ ๐˜๐—ฟ๐—ฎ๐—ฐ๐—ธ ๐—Ÿ๐——๐—”๐—ฃ ๐˜€๐—ถ๐—ด๐—ป๐—ถ๐—ป๐—ด ๐—ถ๐—ป ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—ฏ๐—ฒ๐—ณ๐—ผ๐—ฟ๐—ฒ ๐—ฒ๐—ป๐—ณ๐—ผ๐—ฟ๐—ฐ๐—ถ๐—ป๐—ด ๐—ถ๐˜? When applying ๐˜€๐˜๐—ฟ๐—ถ๐—ฐ๐˜ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€, enforcingย LDAP signingย is a common (and critical) step. It disables weak authentication methods likeย LDAP simple bind, which transmits credentials in plaintext and no signing allows MITM attacks. But if your infrastructure is older, ๐—ฒ๐—ป๐—ณ๐—ผ๐—ฟ๐—ฐ๐—ถ๐—ป๐—ด ๐—ถ๐˜ ๐—ผ๐˜‚๐˜๐—ฟ๐—ถ๐—ด๐—ต๐˜ ๐—ฐ๐—ฎ๐—ป ๐—ฏ๐—ฟ๐—ฒ๐—ฎ๐—ธ ๐˜๐—ต๐—ถ๐—ป๐—ด๐˜€. ๐Ÿ’ฅ So before enforcement โ€”ย ๐˜๐—ฟ๐—ฎ๐—ฐ๐—ธ ๐˜„๐—ต๐—ฎ๐˜โ€™๐˜€ ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐˜‚๐—ป๐˜€๐—ถ๐—ด๐—ป๐—ฒ๐—ฑ ๐—Ÿ๐——๐—”๐—ฃ. ๐—›๐—ฒ๐—ฟ๐—ฒโ€™๐˜€ ๐—ต๐—ผ๐˜„: ๐Ÿ“ย ๐—ฆ๐˜๐—ฒ๐—ฝ ๐Ÿญ โ€” ๐—–๐—ต๐—ฒ๐—ฐ๐—ธ ๐—ฑ๐—ฒ๐—ณ๐—ฎ๐˜‚๐—น๐˜ ๐—น๐—ผ๐—ด๐˜€ Event IDย 2887ย in theย Directory Serviceย log reports unsigned LDAP attempts every 24 hours. But itโ€™s vague. ๐Ÿ”ย ๐—ฆ๐˜๐—ฒ๐—ฝ ๐Ÿฎ โ€” ๐—˜๐—ป๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ฑ๐—ฒ๐˜๐—ฎ๐—ถ๐—น๐—ฒ๐—ฑ ๐—ฑ๐—ถ๐—ฎ๐—ด๐—ป๐—ผ๐˜€๐˜๐—ถ๐—ฐ๐˜€ Registry path: HKLM\System\CurrentControlSet\Services\NTDS\Diagnostics Setย 16 LDAP Interface Eventsย toย 2 This gives youย ๐—˜๐˜ƒ๐—ฒ๐—ป๐˜ ๐—œ๐—— ๐Ÿฎ๐Ÿด๐Ÿด๐Ÿต, which showsย exact clientsย using unsigned LDAP. โœ… Use this toย find and fix legacy appsย before enforcing LDAP Signing and disabling Simple Bind. ๐Ÿ’กย ๐—”๐˜ƒ๐—ผ๐—ถ๐—ฑ ๐˜๐—ต๐—ฒ โ€œ๐—ฒ๐—ป๐—ณ๐—ผ๐—ฟ๐—ฐ๐—ฒ โ†’ ๐—ฏ๐—ฟ๐—ฒ๐—ฎ๐—ธ ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜†๐˜๐—ต๐—ถ๐—ป๐—ดโ€ scenario โ€” audit first. ๐Ÿ“Œ In this series, Iโ€™ll be coveringย ๐—ฟ๐—ฒ๐—ฎ๐—น-๐˜„๐—ผ๐—ฟ๐—น๐—ฑ ๐—ฐ๐—ต๐—ฎ๐—น๐—น๐—ฒ๐—ป๐—ด๐—ฒ๐˜€ ๐—ผ๐—ณ ๐—ฎ๐—ฝ๐—ฝ๐—น๐˜†๐—ถ๐—ป๐—ด ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฏ๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€ย โ€” including the exceptions you sometimesย mustย make to keep legacy infrastructure operational. Based on lessons from production environments. #LDAP #ActiveDirectory #CyberSecurity #SecureBits #SecurityBaselines #BlueTeam #HorizonSecured @BlueTeamDave
1
48
282
15,923
๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐——๐—ผ ๐—ฌ๐—ผ๐˜‚ ๐—จ๐˜€๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€? Security Baselines are one of the ๐—บ๐—ผ๐˜€๐˜ ๐—ฐ๐—ฟ๐—ถ๐˜๐—ถ๐—ฐ๐—ฎ๐—น ๐—ฐ๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น๐˜€ for locking down your Windows infrastructure. They allow you to enforce a ๐—ฑ๐—ฒ๐—ณ๐—ถ๐—ป๐—ฒ๐—ฑ ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐˜€๐˜๐—ฎ๐˜๐—ฒ across your environment via Group Policy or Microsoft Intuneโ€”hundreds of settings, centrally managed. Microsoft provides free Security Baselines. Stricter ones exist tooโ€”often behind a paywall. Or you can build your own. (I break this down in detail inside my ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ ๐—œ๐—ป๐—ณ๐—ฟ๐—ฎ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—–๐—ผ๐˜‚๐—ฟ๐˜€๐—ฒ.) But hereโ€™s the catch: ๐—œ๐—บ๐—ฝ๐—น๐—ฒ๐—บ๐—ฒ๐—ป๐˜๐—ถ๐—ป๐—ด ๐˜๐—ต๐—ฒ๐—บ ๐—ฐ๐—ฎ๐—ป ๐—ฏ๐—ฟ๐—ฒ๐—ฎ๐—ธ ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜. ๐Ÿ’กWhy? Because most real-world environments still rely on ๐—ผ๐˜‚๐˜๐—ฑ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—ฝ๐—ฟ๐—ผ๐˜๐—ผ๐—ฐ๐—ผ๐—น๐˜€ and ๐˜„๐—ฒ๐—ฎ๐—ธ๐—ฒ๐—ฟ ๐—ฐ๐—ฟ๐˜†๐—ฝ๐˜๐—ผ ๐—ฎ๐—น๐—ด๐—ผ๐—ฟ๐—ถ๐˜๐—ต๐—บ๐˜€ like: โ–ช๏ธRC4 โ–ช๏ธLM Hashes โ–ช๏ธNTLM โ–ช๏ธDES โ–ช๏ธOlder TLS versions ...and more. ๐Ÿ”’ And Security Baselines rightfully ๐—ฑ๐—ถ๐˜€๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ฎ๐—น๐—น ๐—ผ๐—ณ ๐˜๐—ต๐—ฒ๐—บ. โ“So how do you implement baselines safely? Treat it as a ๐—ฝ๐—ฟ๐—ผ๐—ท๐—ฒ๐—ฐ๐˜, ๐—ป๐—ผ๐˜ ๐—ฎ ๐—พ๐˜‚๐—ถ๐—ฐ๐—ธ ๐—ณ๐—ถ๐˜…. Years of ignoring best practices canโ€™t be reversed overnight. โœ… Use Microsoftโ€™s ๐—ฃ๐—ผ๐—น๐—ถ๐—ฐ๐˜† ๐—”๐—ป๐—ฎ๐—น๐˜†๐˜‡๐—ฒ๐—ฟ to: โ–ช๏ธCompare your current configuration vs. the baseline โ–ช๏ธIdentify exactly what will change โ–ช๏ธAssess potential impact to applications or services Even though it takes time and careful planning, ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€ ๐—ฎ๐—ฟ๐—ฒ ๐˜„๐—ผ๐—ฟ๐˜๐—ต ๐—ถ๐˜โ€”theyโ€™re one of the strongest foundational measures in Windows security. ๐—›๐—ฎ๐˜ƒ๐—ฒ ๐˜†๐—ผ๐˜‚ ๐—ถ๐—บ๐—ฝ๐—น๐—ฒ๐—บ๐—ฒ๐—ป๐˜๐—ฒ๐—ฑ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—•๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€ ๐—ถ๐—ป ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜? Drop a comment belowโ€”curious to see how others are tackling this ๐Ÿ‘‡ #SecurityBaselines #Windows #ActiveDirectory #Cybersecurity
10
53
2,870
Lock Down Your Windows Server: Easy Security with Microsoft's Secret Recipe! #SecurityBaselines #MicrosoftSecurity #WindowsServer #ITPro #CybersecurityTools #PowerShell
1
7
641
14 Nov 2024
๐Ÿš€ Windows Server 2025: Simplified Drift Control and Security Baselines with OSConfig! ๐Ÿš€ Imagine deploying a full security baseline to Windows Server 2025 in seconds, knowing itโ€™s locked down and stays compliant. No GPO refreshes or manual tweaks required. Windows Server 2025โ€™s new OSConfig feature introduces Declared Configuration for seamless baseline deployment and automatic drift control, putting compliance on autopilot. Are you curious about how OSConfig can transform your server management strategy? Join me as I explain this powerful new tool, which is set to change the game for configuration management! lnkd.in/ea48PYUj #WindowsServer2025 #OSConfig #DeclaredConfiguration #DriftControl #ConfigurationManagement #SecurityBaselines #Security #Intune #MSIntune #Windows #Windows11 #patchmypc
8
38
3,212
Have you ever received the โ€œThis App Has Been Blocked by Your System Administratorโ€ message and thought, โ€œOh, itโ€™s probably just AppLocker or some security policy.โ€ patchmypc.com/this-app-has-bโ€ฆ But then you dive in, only to realize itโ€™s like being stuck in a dense forest, with every tree representing a different policy blocking your path. Each step forward reveals another dead end: #AppLocker, #WDAC, #ConditionalAccess, and #SecurityBaselinesโ€ฆ but none of them are the real culprit. Itโ€™s easy to feel lost, chasing shadows through layers of settings designed to keep you guessing. Itโ€™s not just a troubleshooting task anymore; itโ€™s a full-blown mystery hunt! ๐Ÿ•ต๏ธโ€โ™‚๏ธ Ultimately, the solution is often hidden in a place youโ€™d never expect. Curious whatโ€™s really causing the block? Letโ€™s shed some light on this forest of hidden settings together! ๐Ÿ”ฆ #Windows11 #Windows #Intune #MSIntune
1
19
52
5,607
What's the best way to compare and migrate the new #SecurityBaselines in #Intune? I tried using the following script from @mwbengtsson to compare but it's not picking up my new 23H2 policy: github.com/imabdk/Powershellโ€ฆ Trying to piece it together but PS isn't my top skill...
2
3
337
New video out! This time we have had the honor of having @lavanyal in the studio to talk about Settings Insights and Anomaly detection. Enjoy! youtube.com/watch?v=iU-7WHh3โ€ฆ #MSIntune #SecurityBaselines #Anomaly #MachineLearning #AI #MVPBuzz
1
9
19
10,730
๐Ÿ“ฏ๐Ÿ“ฏ๐Ÿ“ฏ Save the date! The team is back with another session for our Portuguese-speaking customers! ๐Ÿ–ฅ๏ธ @Windows MDM | Part 3 | #Securitybaselines, #Antivirus, #Bitlocker, and #Windows Hello for Business! ๐Ÿ“… August 18, 2022 ๐Ÿ‘‰ Register here: aka.ms/MSPortugueseMEM/Regisโ€ฆ #MEMpowered

Awesome opportunity for our Portuguese-speaking customers! Register NOW for our upcoming session on 18 August: Windows MDM Part 3. This session will focus on Security baselines, Antivirus, Bitlocker, and Windows Hello for Business! #MEMPowered #Windows aka.ms/MSPortugueseMEM/Regisโ€ฆ
1
2
Having some fun with #securitybaselines #MEMpowered
1
Cybersecurity teams are racing to find #cyberattacks and threats. As attacks become more widespread, a possible solution to mitigating risk is finding the optimal way to deploy automation e.g. #ML, #AI and #securitybaselines continuitycentral.com/index.โ€ฆ

1
2
Well written and explained: How to update Security Baselines in Microsoft Intune to a newer version! Thanks for Sharing it. #Community #EnterpriseMobilitySecurity #Intune #MicrosoftEndpointManager #MSIntune #SecurityBaselines bit.ly/3JKmShw
7
12
Working on a blog series about #mem #securitybaselines and #automation. A lot of options discussed, how to deploy etc. Started with one post, now I have 4 titles already ๐Ÿ˜…
1
1
11
It's always recommended to use the newest #SecurityBaselines for #Windows. With 20H2 new #AttackSurfaceReductionRules and #BlockAtFirstSight recommended! #Defender #ASR #Windows10 loom.ly/IbIvoGw
8
14
Hope to see and help support everyone working with Microsoft tech on techcommunity.microsoft.com in 2021! #Windows10 #MicrosoftEndpointManager #MSIntune #UniversalPrint #SecurityBaselines

Happy new year everyone! We start the new year with 2x the number of unique visitors than we did this time last year. Thank you for all your support and community contributions! You can catch up on the latest updates via @MSTCommunity's Weekly Roundup techcommunity.microsoft.com/โ€ฆ
5
Not a good #ITPro day today. of course I use @MSIntune #SecurityBaselines and tried to create a recovery usb and a windows 10 usb. Got in a right mess before I realised default setting is not writing to unencrypted USB.... #Sigh #NeverStopLearning #WastedDay