Hardening Windows Server

Intermediate
Administrator
Solution Architect
Technology Manager
Windows Server

This module covers how to harden the security configuration of your Windows Server environment. You learn how to deploy Windows LAPS to centrally manage local administrator passwords, configure Privileged Access Workstations (PAWs) for secure administration, harden domain controllers using Server Core, TPM, BitLocker, and Device Guard with RDP restrictions, apply and analyze security baselines using the Microsoft Security Compliance Toolkit with Policy Analyzer and LGPO, and secure file-sharing traffic with SMB 3.1.1 encryption and preauthentication integrity.

Learning objectives

After completing this module, you will be able to:

  • Manage local administrator passwords using Local Administrator Password Solution

  • Limit administrative access to Privileged Access Workstations (PAWs)

  • Explain how to secure domain controllers from being compromised

  • Describe how to use the Microsoft Security Compliance Toolkit to harden servers

  • Secure SMB traffic using SMB encryption

Prerequisites

  • Working knowledge of common Windows Server administration basics

  • Experience with managing Active Directory Domain Services