Which script should I use for Windows Server 2019 VM Baseline Hardening

Anonymous
2022-11-24T14:18:57.63+00:00

Hello Folks,

I am using Microsoft Hyper-V Server 2019 (Version 1809 : OS build 17763.3653)

There are 2 scripts available for Hardening.
263955-image.png

*****Link for Cloud Security Best Practice*****
https://raw.githubusercontent.com/Cloudneeti/os-harderning-scripts/master/WindowsServer2019/CSBP_WindowsServer2019.ps1

****Link for CIS benchmark Windows Server****
https://raw.githubusercontent.com/Cloudneeti/os-harderning-scripts/master/WindowsServer2019/CIS_Benchmark_WindowsServer2019_v100.ps1

I am confused which one is better for my server and which one should I use. Please help me to select one of them.
Please help me resolve this issue.

Thanks and Regards,
Vikash Kumar Choudhary

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,478 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,200 questions
Windows Server Management
Windows Server Management
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Management: The act or process of organizing, handling, directing or controlling something.
422 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Dave Patrick 426.1K Reputation points MVP
    2022-11-24T14:41:21.683+00:00

    Maybe this one could help.
    https://learn.microsoft.com/en-us/azure/defender-for-cloud/apply-security-baseline

    --please don't forget to upvote and Accept as answer if the reply is helpful--


  2. Anonymous
    2022-11-27T18:51:56.803+00:00

    Hello Patrick,

    Thanks for your reply and suggestion.

    I am new to this security role.
    I am not understanding about the Windows server hardening concept.

    From the 2 options mentioned by me from the last mail, could you please suggest me which is better one and should be used by me.

    Please suggest sir.

    Thanks and Regards,
    Vikash

    0 comments No comments

  3. Dave Patrick 426.1K Reputation points MVP
    2022-11-27T19:09:42.167+00:00

    From the 2 options mentioned by me from the last mail, could you please suggest me which is better one

    I'd try asking them here.
    https://github.com/Cloudneeti/os-harderning-scripts/issues

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  4. Ian Xue (Shanghai Wicresoft Co., Ltd.) 30,361 Reputation points Microsoft Vendor
    2022-11-28T09:17:05.547+00:00

    Hi,

    The two scripts look almost the same except that some settings in CIS_Benchmark_WindowsServer2019_v100.ps1, like "Ensure 'Turn off Internet Connection Wizard if URL connection is referring to Microsoft.com' is set to 'Enabled'" and "Ensure 'Windows Firewall: Public: Settings: Apply local connection security rules' is set to 'No'" are commented out.

    Best Regards,
    Ian Xue

    -----------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.