Hardening Windows Server
This module covers how to harden the security configuration of your Windows Server environment. You learn how to deploy Windows LAPS to centrally manage local administrator passwords, configure Privileged Access Workstations (PAWs) for secure administration, harden domain controllers using Server Core, TPM, BitLocker, and Device Guard with RDP restrictions, apply and analyze security baselines using the Microsoft Security Compliance Toolkit with Policy Analyzer and LGPO, and secure file-sharing traffic with SMB 3.1.1 encryption and preauthentication integrity.
Learning objectives
After completing this module, you will be able to:
Manage local administrator passwords using Local Administrator Password Solution
Limit administrative access to Privileged Access Workstations (PAWs)
Explain how to secure domain controllers from being compromised
Describe how to use the Microsoft Security Compliance Toolkit to harden servers
Secure SMB traffic using SMB encryption
Prerequisites
Working knowledge of common Windows Server administration basics
Experience with managing Active Directory Domain Services