Skip to content

Windows

Colin Stubbs edited this page Sep 11, 2018 · 2 revisions

Hardening

Active Directory Managed Devices

Generally speaking you want to leverage AD GPO's to apply CIS hardening.

If you're a CIS subscriber can import the remediation GPO content to achieve this very very quickly. You Windows systems should hit a > 90% compliance level immediately without any further work.

Go here to read more on this: https://www.cisecurity.org/cis-securesuite/cis-securesuite-remediation-content/

Otherwise create your own GPO's based on the freely available CIS PDF content.

Non-Active Directory Managed Devices

You can use the lgpo.exe commands with the CIS remediation GPO content to achieve this reasonably quickly.

You can also configure LGPO options via the existing Salt execution and state modules,

Using the CIS PDF guides you should define what needs to be modified via pillar, then create a state that iterates thru that pillar to apply LGPO options on Windows minions.

Clone this wiki locally