hardening•Published

Battle-Tested Windows Server 2025/2022 Hardening Baseline for MSPs

A production-verified hardening runbook stripping unnecessary attack surfaces, configuring SMB signing, auditing LSASS protections, and locking down NTLM without breaking legacy clients.

#Windows Server#Active Directory#CIS Benchmarks#PowerShell

NotebookLM Audio Briefing
⏱ 6m 45s

Audio Overview: Battle-Tested Windows Server 2025/2022 Hardening Baseline for MSPs

Listen to the high-level conversation while following along with the code and runbooks below.

Speed:
MP3
Video Walkthrough
YouTube Stream (0 Egress)

Video Walkthrough: Battle-Tested Windows Server 2025/2022 Hardening Baseline for MSPs

When managing dozens of client environments across an MSP, applying an entire 400-page CIS Benchmark blindly is the fastest way to brick line-of-business (LOB) applications and trigger a flood of Tier 1 helpdesk tickets.

This runbook documents our curated baseline—the critical 10% of hardening configurations that eliminate 90% of opportunistic lateral movement techniques (Mimikatz, LLMNR/NBT-NS poisoning, and SMB relay attacks), while preserving application compatibility.


1. Quick Summary & Target Architecture

  • Objective: Eliminate legacy protocols, enforce cryptographic integrity on network traffic, and shield credential material in memory.
  • Target OS: Windows Server 2022 / 2025 (Standard & Datacenter).
  • Rollout Strategy: Audit mode first via Group Policy Object (GPO), followed by progressive enforcement across tiered server OUs.
[ Tier 0: Domain Controllers ] ──▶ Immediate Credential Guard + SMB Signing
[ Tier 1: Member Servers ]     ──▶ Staged NTLM Audit ──▶ Restrict NTLM
[ Tier 2: Endpoints ]          ──▶ LLMNR/NetBIOS Disabled via DHCP & GPO

2. Step 1: Kill LLMNR and NetBIOS Over TCP/IP

Link-Local Multicast Name Resolution (LLMNR) and NetBIOS are relics that allow attackers with Responder or similar tools on a network to capture NetNTLM hashes trivially.

PowerShell Disable Command (Audit & Apply)

Run the following script to disable NetBIOS across all active IPv4 interfaces:

# Disable NetBIOS on all active network adapters
Get-CimInstance -ClassName Win32_NetworkAdapterConfiguration -Filter "IPEnabled = True" | ForEach-Object {
    Write-Output "Disabling NetBIOS on interface: $($_.Description)"
    $_.SetTcpipNetbios(2) | Out-Null # 2 = Disable NetBIOS over TCP/IP
}

# Verify status (0 = Default/DHCP, 1 = Enabled, 2 = Disabled)
Get-CimInstance -ClassName Win32_NetworkAdapterConfiguration -Filter "IPEnabled = True" | 
    Select-Object Description, TcpipNetbiosOptions

Group Policy Setting

To enforce domain-wide via GPO:

  • Path: Computer Configuration > Administrative Templates > Network > DNS Client
  • Setting: Turn off multicast name resolution ➔ Enabled

3. Step 2: Enforce SMB Signing & Disable SMBv1

Unsigned SMB traffic exposes your network to SMB Relay attacks (such as NTLM relaying to LDAP/ADCS).

[!IMPORTANT] Windows Server 2025 now enables SMB signing by default for all connections. On Windows Server 2022 and 2019, you must enforce it explicitly.

# Verify SMBv1 is completely uninstalled
Get-WindowsOptionalFeature -Online -FeatureName SMB1Protocol | Select-Object State

# Enforce SMB Signing on the Server
Set-SmbServerConfiguration -RequireSecuritySignature $true -EnableSMB1Protocol $false -Force

# Enforce SMB Signing on the Client side
Set-SmbClientConfiguration -RequireSecuritySignature $true -Force

4. Step 3: Run LSASS as a Protected Process (PPL) & Credential Guard

Running Local Security Authority Server Service (LSASS) in Protected Process Light (PPL) mode prevents non-protected processes—even those with local SYSTEM privileges—from reading LSASS memory using OpenProcess calls.

# Enable LSASS PPL via registry
$RegistryPath = "HKLM:\SYSTEM\CurrentControlSet\Control\Lsa"
New-ItemProperty -Path $RegistryPath -Name "RunAsPPL" -Value 1 -PropertyType DWORD -Force

# Audit Event Logs: Look for Event ID 3065 or 3066 in Microsoft-Windows-CodeIntegrity/Operational
Get-WinEvent -LogName "Microsoft-Windows-CodeIntegrity/Operational" -MaxEvents 10 | 
    Where-Object { $_.Id -in 3065, 3066 }

5. Verification Checklist

Before moving this baseline out of staging, verify the following:

  • All line-of-business SQL or ERP service accounts can still connect without SMB negotiation failures.
  • No Event ID 3065 errors (blocked third-party driver injection into LSASS) from backup or endpoint agents.
  • Network capture confirms zero LLMNR (UDP 5355) packets broadcasted from the server.
  • Remote management via WinRM (PowerShell remoting) remains functional with Kerberos authentication.
Weekly Technical BriefingIncludes Podcast Feed

Get The Next Production Runbook in Your Inbox

Join 500+ MSP & SecOps engineers. Receive battle-tested configurations, 5-minute audio briefings, and critical security advisories every Tuesday.

✓ Zero spam & zero marketing fluff•✓ 5-min audio overview included•✓ Unsubscribe anytime in 1-click