Hardening Windows 11 with SecPol and GPO: A Complete Guide

Last update: 17/12/2025
Author Isaac
  • The hardening of Windows 11 It is based on SecPol, GPO, Defender and Microsoft security baselines to reduce the attack surface.
  • Credential protection, the Boot Secure, BitLocker and application control (AppLocker, ASR, PowerShell) are key pillars of reinforcement.
  • A well-configured firewall, disabling legacy services and protocols, and strict account policies limit the attacker's ability to move.
  • Centralized auditing, robust backups, and a continuous patching strategy complete the endpoint security posture.

Windows 11 Hardening with SecPol

When you start delving into Windows 11 security secrets , you inevitably reach the same point: user computers are the weak link. A freshly installed Windows 11 system, without proper security configuration, is an easy target for malware , ransomware, and attackers moving laterally across the network.

The good news is that Windows 11 brings a huge arsenal of hardening features , many of which can be controlled with SecPol (Local Security Policy) and Group Policy Objects (GPOs). The challenge lies in knowing what to modify, how to combine it with Microsoft's security baselines, and how not to break half your business in the process. Here you'll find a comprehensive guide to strengthening Windows 10 and, especially, Windows 11 with SecPol, GPOs, Defender, and official tools like the Security Compliance Toolkit.

What is Windows 11 hardening and why should you do it now?

Security in Windows 11 with policies

When we talk about hardening Windows 11, we mean minimizing the system's attack surface: disabling unnecessary components, securely configuring only what's needed, and strengthening credentials, network, applications, and startup processes. This is all done using SecPol.msc, Gpedit.msc, GPMC, and tools like RSAT, Intune, or Configuration Manager.

Windows 10 and 11 workstations are a favorite target for attackers because they're where users browse the web, open emails, connect USB drives, install software, and run macros. Effective hardening drastically reduces the chances of exploitation, but it requires planning, testing, and a clear policy on what is and isn't allowed.

Simply turning on your antivirus isn't enough. A serious hardening approach combines application control, attack surface reduction (ASR), credential protection, encryption, firewalls, logging, strong authentication , and a sound update strategy. And, very importantly, all of this must be managed centrally through domain GPOs or MDM policies , not manually by clicking on each PC.

Beyond the technical aspects, there's a mindset factor: a "functional" Windows isn't necessarily a "secure" Windows. Many features enabled by default make life easier for the user but also for the attacker , so hardening is about finding the right balance for your environment.

SecPol, Gpedit and GPMC: gateway to hardening

Local security policies in Windows

The first step in hardening Windows 11 involves thoroughly understanding its native tools: SecPol.msc (Local Security Policy), Gpedit.msc (Group Policy Editor), and GPMC (Group Policy Management Console) . These tools allow you to control almost every aspect of system security.

On domain-joined computers, practical management is done with Group Policy Management Console (GPMC) from a server or a client with RSAT installed . To open it, simply go to Start, search for "Group Policy Management," and launch the console. From there, you can create Group Policy Objects (GPOs), link them to sites, domains, or organizational units (OUs), and control editing and linking permissions.

At the local level, Gpedit.msc and SecPol.msc are your allies for testing or for computers that are not joined to a domain. Access them by typing gpedit.msc or secpol.msc in the search box or in Run. If you encounter permission errors or messages that the program cannot be opened, check your administrator group membership and, in some cases, repair the C:\Windows\System32\GroupPolicy folder (for example, by renaming Machine to Machine.old and regenerating the configuration).

Note that to use GPMC you need to have the Group Policy Management (RSAT) feature installed and appropriate permissions on GPOs and OUs. By default, only Domain and Enterprise Admins can create and link GPOs, although control can be delegated to specific groups.

Creating a basic hardening GPO for Windows 11 using PowerShell

A very efficient way to deploy hardening in bulk is to combine GPO and PowerShell . From the GroupPolicy module, you can create and populate policies without using a mouse, allowing you to version scripts, replicate environments, and automate processes.

First, install RSAT from Settings > Apps > Optional features > Add a feature , searching for “RSAT: Group Policy Management Tools”. Then import the module in a PowerShell session with administrator privileges.

A typical workflow for a hardening GPO might be:

  • Create a base GPO, for example “Hardening-W11”, dedicated solely to security.
  • Use Set-GPRegistryValue to write critical keys: USB lock, PowerShell policies, Office macros, CMD, AutoRun, Edge, RDP, SMB, etc.
  • Link the GPO to the OU that contains the target computers and force its application with New-GPLink - Enforced Yes.
  Windows calculator tricks: hidden functions and advanced modes

With this approach you can, for example, disable USB storage by changing the Start value of the USBSTOR service to 4, require PowerShell to only run signed scripts (ExecutionPolicy=AllSigned), block untrusted macros in Office (VBAWarnings), prevent the use of CMD (DisableCMD), or disable SMBv1 to get rid of a stack of legacy vulnerabilities.

The key is that each change is documented and tested in a lab environment or pilot OU before being deployed to the entire organization, because some policies can break workflows or legacy applications.

Microsoft Security Compliance Toolkit and Security Baselines

Instead of reinventing the wheel, it makes far more sense to leverage Microsoft's official security baselines . All of this is distributed within the Security Compliance Toolkit (SCT) , a package containing pre-configured GPOs, analysis tools, and documentation.

The SCT includes baselines for Windows 11 (21H2, 22H2, 23H2, 24H2), Windows 10, Windows Server 2016/2019/2022/2025, Microsoft 365 Apps , and Edge . It also includes utilities such as:

It also includes utilities such as:

  • Policy Analyzer: compares GPOs with each other or against the actual configuration of a computer, detects redundancies, conflicts and deviations.
  • LGPO.exe: Applies local policies from Registry.pol files, security templates, or GPO backups, ideal for non-domain computers.
  • SetObjectSecurity.exe: adjusts security descriptors on files, registry keys, services, SMB shares, etc.
  • GPO2PolicyRules: converts GPO backups into .PolicyRules files that can be analyzed with Policy Analyzer without going through the GUI.

The baselines follow clear principles: they are designed for well-managed organizations where standard users do not have administrator rights , only configurations that mitigate current threats are modified, and the aim is to avoid breaking more than they fix. For example, an option is not enforced if the risk it mitigates is low and the operational impact is high.

These baselines are available for Windows Pro, Enterprise, Education and Pro Education/SE , and can be applied using both traditional GPOs and MDM policies (Intune includes specific security baseline templates for Windows 10/11).

Credential protection and LSASS hardening

One of the most critical components of Windows is LSASS (Local Security Authority Subsystem Service) , the process that stores credentials in memory so the user doesn't have to authenticate constantly. If an attacker manages to dump LSASS, they can steal password hashes, Kerberos tickets, or even plaintext passwords if WDigest is active.

To reduce this risk, there are several recommended measures you can implement with SecPol or GPO:

  • Limit credential caching: reduce the number of cached logons or disable them completely on critical workstations, preventing domain administrator credentials from residing in SAM.
  • Disable WDigestThis prevents the passphrase from being stored in plain text in LSASS.
  • Enable Credential GuardIn Windows 10/11 Enterprise, it isolates credentials in a virtualized environment, inaccessible to processes with fewer privileges.
  • Enable memory integrity (HVCI): further strengthens the code that can be loaded in the context of LSASS.

All of this is controlled through advanced security policies and MS Security Guide policies , included in the Security Compliance Toolkit. It requires compatible hardware (UEFI, suitable TPM , virtualization support), but the security improvement is significant, especially against Pass-the-Hash or Pass-the-Ticket attacks.

Application control: AppLocker, ASR, and execution restrictions

A typical attack vector is a user running anything: attachments, GitHub binaries, scripts from who-knows-where, and portable applications. Application control in Windows 10/11 is addressed with several components: AppLocker, Defender ASR rules, and script execution policies (especially PowerShell).

With AppLocker, you can define which executables, MSI installers, scripts, and packaged applications can be run, basing the rules on publisher, path, or hash. It's configured via Gpedit or Group Policy in Computer Configuration > Windows Settings > Security Settings > Application Control Policies > AppLocker . Ideally, you should start in audit mode, review the effects, and then switch to application mode.

Finally, control PowerShell with execution policies: require AllSigned or, in very demanding environments, directly block the execution of user scripts and only allow corporate-signed scripts. Additionally, you can log transcripts and block older versions of PowerShell to reduce evasion vectors.

Ransomware protection: Controlled access to folders and backups

Ransomware directly attacks user files and shared resources. To mitigate this, Windows 10/11 includes Controlled Folder Access within Microsoft Defender Exploit Guard. This feature prevents unauthorized processes from modifying certain paths (Documents, Desktop, etc.).

From Windows Security, you can enable Ransomware Protection > Controlled Folder Access , add protected folders, and allow trusted applications. At the enterprise level, it's best configured using Group Policy Objects (GPOs) or Intune to ensure all computers apply the same policy.

  How to install Java JDK correctly on Windows 11

In addition, best practices require a robust 3-2-1 backup plan : at least three copies, on two different storage media, and one off-site or in an immutable repository. No matter how robust your hardening is, if ransomware encrypts data and there's no verified backup, the incident becomes critical.

It is recommended to schedule frequent backups, test periodic restores , and ensure that the credentials used for backup are not exposed on the same workstations that could be compromised.

Secure Boot, ELAM, and disk encryption with BitLocker

Another critical level of security lies in the system boot process itself and disk protection. This is where UEFI, Secure Boot, TPM, ELAM, and BitLocker come into play.

With Secure Boot enabled in UEFI, the firmware only allows signed and validated bootloaders to load, making it difficult to install bootkits that lock onto the operating system before it loads. ELAM (Early Launch Anti-Malware) allows you to register an anti-malware driver that loads before any third-party drivers and classifies which drivers can be initialized.

Measured booting , combined with TPM, generates a log of which components are loaded during the boot process, which can be reviewed by security solutions to detect tampering. This reduces the likelihood of a malicious change to the boot chain going undetected.

Regarding data, BitLocker offers full disk encryption with AES , protecting information if the computer is lost, stolen, or the disk is removed. Ideally, BitLocker should be used with a TPM and, if necessary, a PIN at startup. Group Policy Objects (GPOs) allow you to standardize the encryption algorithm, enforce encryption on all drives, control the storage of recovery keys, and prevent weak configurations.

Account management, privileges, and authentication

Account management is another pillar of hardening. The first step is to eliminate bad practices such as using the built-in administrator account for everything or leaving it with the same password on all devices . This account should be renamed, disabled if possible, and managed with a solution like LAPS , which assigns unique passwords per device and rotates them.

Equally important is separating user accounts from administrator accounts. An administrator should not browse the internet or read email using a privileged account. A dual-account model is recommended : one standard account for everyday use and another administrative account solely for high-level tasks, ideally with restrictions on web and email access.

For sensitive access (VPNs, remote access, changes to critical infrastructure, access to confidential data), it is highly recommended to require hardware-based multi-factor authentication : Windows Hello for Business (PIN or biometrics supported by TPM), FIDO2 keys, smart cards, etc. This greatly reduces the impact of credential theft.

At the protocol level, it's advisable to enforce the use of Kerberos and NTLMv2 , disable NTLMv1, and, where possible, avoid legacy mechanisms. It's also essential to enable the NoLMHash policy to prevent the storage of extremely weak LM hashes.

Network, firewall, legacy services and protocols

A hardened Windows system also controls what can enter and leave the network and which open network ports are exposed. The Windows Firewall should be enabled for domain, private, and public profiles, with explicit inbound and outbound rules. Typically, only strictly necessary traffic associated with known services and applications should be allowed.

At the network layer, it is advisable to:

  • Sign and encrypt secure channels between workstations and domain controllers, preventing man-in-the-middle attacks.
  • Sign SMB communications and disable SMBv1.
  • Deactivate NetBIOS over TCP/IP in modern interfaces, as it only poses risks in older environments.
  • Block anonymous connections that allow listing users, shares, or policies.

We also need to consider high-risk interfaces like FireWire or Thunderbolt, which allow direct DMA access to memory . If possible, these should be disabled in UEFI or via Group Policy, or at least the kernel DMA protection available in Windows 10/11 should be enabled.

Regarding services, the rule is clear: anything that isn't essential should be removed or disabled . Review services that start automatically, installed roles, and Windows features. On critical servers and workstations, also limit RDP usage to the bare minimum, protected by VPN, MFA, and specific GPOs that reinforce service security.

Local security policies, MSS, and removal of unnecessary features

SecPol.msc groups together a large portion of local security policies: password policies, account lockouts, user rights, and security options . These same options are typically managed by Group Policy Objects (GPOs) at the domain or organizational unit (OU) level, but it's important to clearly distinguish between what is applied locally and what comes from the domain. AccessChk can be used to audit permissions and check assignments.

Microsoft also defines a series of special settings known as MSS (Microsoft Security Settings) , exposed via additional administrative templates in the Security Compliance Toolkit. While some have become obsolete, others continue to provide additional hardening: connection expiration times, TCP packet handling, default network behaviors, etc.

  Telefónica and BBVA join forces with OpenAI to strengthen their cybersecurity

An important part of hardening is removing or disabling features that will not be used : optional Windows components, local file and printer sharing services, CD burning if not necessary, Telnet, unencrypted FTP, Windows Remote Shell, experimental or little-used features such as Copilot in corporate environments where the risk has not yet been assessed, and also cleaning up associated obsolete registry entries.

The fewer components there are in the system, the less attack surface you expose and the easier it is to keep the configuration under control and audited.

Auditing, centralized logging, and blocking of dangerous enumerations

You can't defend what you can't see. A critical part of hardening is defining a robust audit policy and ensuring that relevant events are reliably stored, ideally in a central repository.

In Windows 10/11, Advanced Audit Policies allow granularity by category (login, object access, policy changes, privilege usage, etc.). It is recommended to enable auditing for critical operations, configure an appropriate log size , and prevent logs from overwriting recent events without archiving them.

Furthermore, it's a good idea to send device logs to a central event server, SIEM, or equivalent solution , so that an attacker can't simply erase the trace on the compromised workstation itself. This makes it easier to detect patterns, correlate events, and conduct post-incident investigations.

In parallel, it is necessary to limit the information that a standard user can obtain from the system: block the generation of RSOP reports by non-privileged users, hide security properties of files and folders from users unnecessarily, and prevent too much information from being exposed on the lock screen.

Power management, sleep and hibernation in sensitive environments

On typical user computers, the sleep, hibernation, and hybrid sleep functions help save energy, but in highly sensitive environments they can also expose data: the contents of memory are either retained or dumped to disk in hiberfil.sys, where encryption keys or other sensitive information may be left.

Therefore, in high-security environments, it's common practice to disable these power states via Group Policy and configure strict session lock policies (for example, locking after 15 minutes of inactivity and activating a password-protected screensaver). This reduces the risk of someone exploiting an unlocked and unattended computer.

The combination of automatic locking , reasonable idle times, and disabling states that preserve memory content is an additional layer of physical protection, especially useful on laptops or equipment in shared areas.

Patching, x64 versions, and continuous updates

All this configuration effort is wasted if the system isn't properly patched. Windows and application patches fix vulnerabilities that are often quickly exploited in one-day attacks, so it's crucial to have a regular update strategy and control untimely automatic updates.

In corporate environments, this involves using WSUS, Configuration Manager, or Windows Update for Business , combined with Wake-on-LAN to apply updates outside of normal business hours. It's important to define maintenance windows, prioritize critical patches, and have a clear rollback procedure if a patch breaks something essential.

Furthermore, it is advisable to standardize on x64 versions of Windows , which include additional security mitigations (hardware-based kernel DEP, PatchGuard, mandatory driver signing, etc.) not present in x86 versions. Similarly, sticking to recent versions of Windows 10/11 reduces exposure to techniques that have already been mitigated in those versions.

The same principles apply to applications: Office, browsers, Java, .NET, PDF readers , email clients… anything that opens untrusted content should always be on the latest supported version with patches , ideally following vendor-specific hardening guides (e.g., security baselines for Office or secure browser configuration GUIs).

With all of the above well orchestrated—Microsoft baselines, intelligent use of SecPol and GPO, protected credentials, secure boot, encryption, thin firewall, application control, robust logging, and strict patching discipline—Windows 11 goes from being a simple functional system to a truly hardened endpoint , much more resistant to everyday attacks and ready to be integrated into a layered security strategy within the organization.

ASR rules
Related articles:
ASR Rules in Windows 11: Configure and optimize security