Battle-Tested Windows Server 2025/2022 Hardening Baseline for MSPs
A production-verified hardening runbook stripping unnecessary attack surfaces, configuring SMB signing, auditing LSASS protections, and locking down NTLM without breaking legacy clients.
Audio Overview: Battle-Tested Windows Server 2025/2022 Hardening Baseline for MSPs
Listen to the high-level conversation while following along with the code and runbooks below.
When managing dozens of client environments across an MSP, applying an entire 400-page CIS Benchmark blindly is the fastest way to brick line-of-business (LOB) applications and trigger a flood of Tier 1 helpdesk tickets.
This runbook documents our curated baseline—the critical 10% of hardening configurations that eliminate 90% of opportunistic lateral movement techniques (Mimikatz, LLMNR/NBT-NS poisoning, and SMB relay attacks), while preserving application compatibility.
1. Quick Summary & Target Architecture
- Objective: Eliminate legacy protocols, enforce cryptographic integrity on network traffic, and shield credential material in memory.
- Target OS: Windows Server 2022 / 2025 (Standard & Datacenter).
- Rollout Strategy: Audit mode first via Group Policy Object (GPO), followed by progressive enforcement across tiered server OUs.
[ Tier 0: Domain Controllers ] ──▶ Immediate Credential Guard + SMB Signing
[ Tier 1: Member Servers ] ──▶ Staged NTLM Audit ──▶ Restrict NTLM
[ Tier 2: Endpoints ] ──▶ LLMNR/NetBIOS Disabled via DHCP & GPO
2. Step 1: Kill LLMNR and NetBIOS Over TCP/IP
Link-Local Multicast Name Resolution (LLMNR) and NetBIOS are relics that allow attackers with Responder or similar tools on a network to capture NetNTLM hashes trivially.
PowerShell Disable Command (Audit & Apply)
Run the following script to disable NetBIOS across all active IPv4 interfaces:
# Disable NetBIOS on all active network adapters
Get-CimInstance -ClassName Win32_NetworkAdapterConfiguration -Filter "IPEnabled = True" | ForEach-Object {
Write-Output "Disabling NetBIOS on interface: $($_.Description)"
$_.SetTcpipNetbios(2) | Out-Null # 2 = Disable NetBIOS over TCP/IP
}
# Verify status (0 = Default/DHCP, 1 = Enabled, 2 = Disabled)
Get-CimInstance -ClassName Win32_NetworkAdapterConfiguration -Filter "IPEnabled = True" |
Select-Object Description, TcpipNetbiosOptions
Group Policy Setting
To enforce domain-wide via GPO:
- Path:
Computer Configuration > Administrative Templates > Network > DNS Client - Setting:
Turn off multicast name resolution➔ Enabled
3. Step 2: Enforce SMB Signing & Disable SMBv1
Unsigned SMB traffic exposes your network to SMB Relay attacks (such as NTLM relaying to LDAP/ADCS).
[!IMPORTANT] Windows Server 2025 now enables SMB signing by default for all connections. On Windows Server 2022 and 2019, you must enforce it explicitly.
# Verify SMBv1 is completely uninstalled
Get-WindowsOptionalFeature -Online -FeatureName SMB1Protocol | Select-Object State
# Enforce SMB Signing on the Server
Set-SmbServerConfiguration -RequireSecuritySignature $true -EnableSMB1Protocol $false -Force
# Enforce SMB Signing on the Client side
Set-SmbClientConfiguration -RequireSecuritySignature $true -Force
4. Step 3: Run LSASS as a Protected Process (PPL) & Credential Guard
Running Local Security Authority Server Service (LSASS) in Protected Process Light (PPL) mode prevents non-protected processes—even those with local SYSTEM privileges—from reading LSASS memory using OpenProcess calls.
# Enable LSASS PPL via registry
$RegistryPath = "HKLM:\SYSTEM\CurrentControlSet\Control\Lsa"
New-ItemProperty -Path $RegistryPath -Name "RunAsPPL" -Value 1 -PropertyType DWORD -Force
# Audit Event Logs: Look for Event ID 3065 or 3066 in Microsoft-Windows-CodeIntegrity/Operational
Get-WinEvent -LogName "Microsoft-Windows-CodeIntegrity/Operational" -MaxEvents 10 |
Where-Object { $_.Id -in 3065, 3066 }
5. Verification Checklist
Before moving this baseline out of staging, verify the following:
- All line-of-business SQL or ERP service accounts can still connect without SMB negotiation failures.
- No Event ID 3065 errors (blocked third-party driver injection into LSASS) from backup or endpoint agents.
- Network capture confirms zero LLMNR (UDP 5355) packets broadcasted from the server.
- Remote management via WinRM (PowerShell remoting) remains functional with Kerberos authentication.
Get The Next Production Runbook in Your Inbox
Join 500+ MSP & SecOps engineers. Receive battle-tested configurations, 5-minute audio briefings, and critical security advisories every Tuesday.