Skip to content

Runbook 03 — Windows Security Assessment

Windows systems remain at the center of most enterprise environments.

They commonly operate as:

Employee Workstations
Administrative Workstations
Application Servers
File Servers
Jump Hosts
Cloud Virtual Machines
Management Servers
Domain-Joined Endpoints

A Windows security assessment therefore needs to evaluate more than antivirus or patch status.

A professional assessment considers:

ASSET
+
IDENTITY
+
PRIVILEGE
+
AUTHENTICATION
+
CONFIGURATION
+
ENDPOINT PROTECTION
+
NETWORK
+
APPLICATIONS
+
DATA
+
LOGGING
+
MONITORING

This runbook provides a repeatable methodology for reviewing Windows systems in an authorized enterprise or lab environment.

Runbook: Windows Security Assessment
Type: Defensive Host Security Assessment
Level: Intermediate
Primary Roles: Windows Security Engineer, Endpoint Security Engineer, Security Consultant
Supporting Roles: SOC Analyst, Incident Responder, System Administrator, Cloud Security Engineer
Primary Objective: Identify Windows security weaknesses, prioritize business risk, recommend remediation, and validate improvements

At completion, you should have:

Windows Asset Inventory
Operating System Assessment
Local Identity Review
Administrative Access Matrix
Authentication Assessment
Security Policy Review
Endpoint Protection Assessment
Firewall Assessment
Encryption Assessment
Application Inventory
Service Review
Persistence Review
PowerShell Security Review
Audit Assessment
Network Exposure Review
Security Findings
Remediation Roadmap
Retest Results
Executive Security Report

Use this sequence:

SCOPE
ASSET
OPERATING SYSTEM
IDENTITY
PRIVILEGE
AUTHENTICATION
SECURITY POLICY
DEFENDER
FIREWALL
ENCRYPTION
APPLICATIONS
SERVICES
PERSISTENCE
POWERSHELL
LOGGING
NETWORK
FINDINGS
REMEDIATION
RETEST

Before reviewing any Windows system, confirm:

Written Authorization
Systems in Scope
Systems Excluded
Permitted Accounts
Permitted Tools
Assessment Window
Production Restrictions
Evidence Requirements
Escalation Contacts

Document:

Assessment:
Business Owner:
Technical Owner:
Security Owner:
Systems in Scope:
Environment:
Start Date:
End Date:
Change Restrictions:
Emergency Contact:

Typical objectives include:

Validate Windows Hardening
Reduce Administrative Privilege
Identify Unsupported Systems
Review Endpoint Protection
Review Firewall Configuration
Validate Disk Encryption
Identify Unnecessary Services
Assess Security Logging
Reduce Network Exposure
Improve Incident Readiness

Determine whether the system is a:

User Workstation
Privileged Workstation
Member Server
Application Server
File Server
Jump Server
Cloud VM
Management Server

The expected security baseline depends on the system’s role.

Do not assess:

Finance Workstation
Domain Controller
Public Application Server

against exactly the same operational baseline.

Suggested structure:

Windows-Security-Assessment
|
+-- 01-Scope
|
+-- 02-System
|
+-- 03-Accounts
|
+-- 04-Privilege
|
+-- 05-Authentication
|
+-- 06-Security-Policy
|
+-- 07-Defender
|
+-- 08-Firewall
|
+-- 09-Encryption
|
+-- 10-Applications
|
+-- 11-Services
|
+-- 12-Persistence
|
+-- 13-PowerShell
|
+-- 14-Logging
|
+-- 15-Network
|
+-- 16-Findings
|
+-- 17-Report

Windows assessment evidence may contain:

Usernames
Computer Names
IP Addresses
Installed Software
Security Configuration
Administrative Membership
Internal Architecture

Apply:

Approved Storage
Access Control
Encryption
Retention Requirements
Secure Disposal

Do not unnecessarily collect:

Passwords
Private Keys
Tokens
Credential Material

Run:

Terminal window
hostname

Collect system information:

Terminal window
Get-ComputerInfo |
Select-Object CsName,WindowsProductName,WindowsVersion,OsBuildNumber,OsArchitecture

Record:

Hostname
Operating System
Version
Build
Architecture
Business Role
Owner

Run:

Terminal window
Get-CimInstance Win32_ComputerSystem |
Select-Object Name,Domain,PartOfDomain

Determine whether the system is:

Workgroup
Active Directory Joined
Cloud Managed
Hybrid Managed

Run:

Terminal window
Get-CimInstance Win32_OperatingSystem |
Select-Object LastBootUpTime

Long uptime can indicate:

Delayed Maintenance
Pending Restart
Incomplete Patch Cycles

but requires operational context.

Determine whether the operating system:

Is Vendor Supported
Receives Security Updates
Meets Enterprise Standards
Has an Approved Upgrade Path
Finding ID:
WIN-001
Title:
Unsupported Windows Operating System
Severity:
High
Observation:
The assessed Windows system uses an
operating-system release outside the
organization's approved support lifecycle.
Risk:
Security vulnerabilities may remain
unpatched and vendor support may be
unavailable.
Recommendation:
Migrate the system to a supported Windows
release through the organization's approved
upgrade or replacement process.

Run:

Terminal window
Get-HotFix |
Sort-Object InstalledOn -Descending

Use this as supporting evidence.

Do not treat Get-HotFix as a complete vulnerability-management platform.

Review:

Patch Management
Update History
Pending Reboots
Failed Updates
Maintenance Windows

Ask:

Who Owns Patching?
How Frequently Are Updates Deployed?
How Are Critical Updates Prioritized?
How Are Failures Identified?
How Are Exceptions Managed?

Run:

Terminal window
whoami

Then:

Terminal window
whoami /groups

Document:

Current Identity
Security Groups
Integrity Context
Administrative Membership

Run:

Terminal window
Get-LocalUser

Review:

Name
Enabled State
Description
Last Logon
Account Purpose
Account Enabled Purpose Owner Admin Required
LocalUser Yes Application App Team No Yes
OldSupport Yes Unknown Unknown Yes Review
Guest No Built-in System No No

Look for:

Unknown Owner
No Current Business Use
Former Support Account
Temporary Account
Old Project Account

Do not automatically delete accounts.

Use:

IDENTIFY
VALIDATE
DISABLE
MONITOR
REMOVE

according to the approved lifecycle.

Finding ID:
WIN-002
Title:
Dormant Enabled Local Account
Severity:
Medium
Observation:
An enabled local account has no documented
current owner or business requirement.
Risk:
Unused accounts create unnecessary
authentication paths to the system.
Recommendation:
Validate ownership and disable or remove
the account through the approved account
lifecycle process.

Run:

Terminal window
Get-LocalGroup

Prioritize groups related to:

Administration
Remote Desktop
Backup
Remote Management
Event Log Access

Run:

Terminal window
Get-LocalGroupMember -Group "Administrators"

Create:

Identity Source Type Business Need Review
Administrator Local User Emergency/Admin Review
IT-Admins Domain Group Administration Current
User-A Domain User Unknown Review

For each privileged identity ask:

Who Owns It?
Why Is Administrator Access Required?
Is Access Permanent?
Could Standard User Rights Work?
Could Controlled Elevation Work?
Is Administrative Activity Audited?
Finding ID:
WIN-003
Title:
Excessive Local Administrator Access
Severity:
High
Observation:
A standard business user has permanent
membership in the local Administrators
group without a documented administrative
requirement.
Risk:
Credential compromise or malicious activity
in the user's context may gain elevated
control over the endpoint.
Recommendation:
Remove unnecessary permanent local
administrator access and provide approved
administrative elevation when required.

19 — Review Built-In Administrator Governance

Section titled “19 — Review Built-In Administrator Governance”

Assess:

Enabled State
Business Requirement
Remote Usage
Credential Management
Monitoring

Renaming the account alone should not be considered sufficient protection.

20 — Review Local Administrator Password Management

Section titled “20 — Review Local Administrator Password Management”

Determine whether local administrator credentials are:

Unique Per Device
Centrally Managed
Rotated
Protected
Auditable

Where appropriate, evaluate Windows LAPS or the organization’s equivalent solution.

Avoid:

ONE LOCAL ADMIN PASSWORD
EVERY WINDOWS DEVICE

Prefer:

UNIQUE CREDENTIAL
+
CONTROLLED RETRIEVAL
+
ROTATION

Review the applicable password policy.

In standalone environments, inspect approved local security configuration.

In domain environments, determine which domain policies apply.

Assess:

Password Length
History
Password Requirements
Age
Exceptions

Do not evaluate password policy in isolation.

Consider:

MFA
Credential Protection
Lockout
Monitoring

Assess:

Threshold
Duration
Counter Reset
Business Impact

Balance:

PASSWORD GUESSING RESISTANCE

against:

AVAILABILITY

Where available:

secpol.msc

Review:

Account Policies
Local Policies
User Rights Assignment
Security Options
Audit Configuration

Pay attention to rights such as:

Log On Locally
Log On Through Remote Desktop Services
Access This Computer from the Network
Log On as a Service
Back Up Files and Directories
Debug Programs

Ask:

Who Has the Right?
Why?
Is It Required?

Run:

Terminal window
Get-LocalGroupMember -Group "Remote Desktop Users"

Assess:

Who Can Connect?
Does the System Need RDP?
From Which Networks?
Are Privileged Accounts Used?
How Is Authentication Protected?

Identify approved management mechanisms such as:

RDP
PowerShell Remoting
Endpoint Management
Administrative Tools
Remote Support

Ensure remote administration is:

Required
Restricted
Authenticated
Monitored

Run:

Terminal window
Get-MpComputerStatus

Review fields relevant to:

Antivirus
Real-Time Protection
Behavior Monitoring
Security Intelligence
Protection Health

Run:

Terminal window
Get-MpPreference

Review areas such as:

Exclusions
Scanning
Cloud Protection
Protection Configuration

depending on the system and security architecture.

Create:

Exclusion Type Business Owner Required Review
Application Path Folder App Team Yes Current
C:\ Folder Unknown No Urgent

Broad exclusions deserve particular attention.

Finding ID:
WIN-004
Title:
Overly Broad Endpoint Protection Exclusion
Severity:
High
Observation:
Microsoft Defender excludes a filesystem
scope significantly broader than required
by the documented application dependency.
Risk:
Malicious files placed within the excluded
location may receive reduced endpoint
protection.
Recommendation:
Reduce the exclusion to the minimum
supported scope and establish recurring
review of endpoint-protection exceptions.

Determine:

Who Manages Defender?
How Are Alerts Monitored?
Who Approves Exclusions?
How Are Protection Failures Detected?

Run:

Terminal window
Get-NetFirewallProfile

Review:

Domain
Private
Public
Enabled State

Run:

Terminal window
Get-NetFirewallRule |
Where-Object {
$_.Enabled -eq "True" -and
$_.Direction -eq "Inbound"
} |
Select-Object DisplayName,Action,Profile

For important rules determine:

Application
Port
Protocol
Source Scope
Profile
Business Requirement

Prioritize rules allowing:

Any Source
Any Profile
Unnecessary Ports
Legacy Applications
Unknown Services
Finding ID:
WIN-005
Title:
Overly Broad Windows Firewall Rule
Severity:
Medium / High
Observation:
An inbound firewall rule permits network
access broader than required for the
documented service.
Risk:
The Windows host exposes unnecessary
network attack surface.
Recommendation:
Restrict the rule to the required
application, protocol, port, source network,
and firewall profile.

Run:

Terminal window
Get-NetTCPConnection -State Listen |
Select-Object LocalAddress,LocalPort,OwningProcess

Use:

PORT
PROCESS
SERVICE
APPLICATION
BUSINESS REQUIREMENT

For an approved PID:

Terminal window
Get-Process -Id <PID>

Document unexpected listeners for investigation.

Remember:

LISTENING PORT
INTERNET EXPOSURE

Reachability also depends on:

Host Firewall
Network Firewall
Cloud Security Rules
Routing
Segmentation

Run where supported:

Terminal window
Get-BitLockerVolume

Review:

Volume Status
Protection Status
Encryption State
Key Protectors

Determine whether recovery information is:

Securely Stored
Access Controlled
Recoverable
Audited
Tested
Finding ID:
WIN-006
Title:
System Volume Lacks Required Disk
Encryption
Severity:
High
Observation:
The operating-system volume does not meet
the organization's required disk-encryption
baseline.
Risk:
Loss, theft, or unauthorized physical
access may expose locally stored corporate
information.
Recommendation:
Enable the approved full-disk encryption
control and securely manage recovery
information.

Run where applicable:

Terminal window
Get-Tpm

Review:

TPM Present
TPM Ready
TPM Enabled

TPM may support controls such as:

BitLocker
Credential Protection
Device Trust
Windows Hello

Build an inventory using approved endpoint-management or software-inventory tooling.

For every important application ask:

Is It Required?
Who Owns It?
Is It Supported?
Is It Current?
Is It Approved?

Prioritize software that is:

End-of-Life
Unpatched
Unknown
Unmanaged
No Longer Required
Finding ID:
WIN-007
Title:
Unsupported Application Installed
Severity:
Medium / High
Observation:
The assessed Windows system contains
software that no longer receives required
security support.
Risk:
Known vulnerabilities may remain
unresolved and increase endpoint attack
surface.
Recommendation:
Upgrade, replace, isolate, or remove the
unsupported application based on business
requirements.

Security hardening includes reducing:

Unused Software
Legacy Tools
Old Browser Components
Unnecessary Administrative Utilities

because every additional application introduces:

Code
Dependencies
Configuration
Potential Vulnerabilities

Run:

Terminal window
Get-Service |
Where-Object {$_.Status -eq "Running"}

For important services identify:

Service Name
Purpose
Startup Type
Service Account
Executable
Network Exposure
Service Purpose Identity Network Required Review
AppService Application Service Account Yes Yes Current
LegacySvc Unknown SYSTEM Yes Review Urgent

Ask:

Which Identity Runs the Service?
Why Does It Need That Privilege?
Can a Lower-Privilege Identity Work?
Is the Credential Managed?
Is Interactive Logon Required?

Do not disable a service simply because:

You Do Not Recognize It

First establish:

Purpose
Dependency
Owner
Business Requirement

Assess:

Executable Location
File Ownership
Filesystem Permissions
Configuration Ownership
Service Identity

The security model is:

SERVICE
+
EXECUTABLE
+
PERMISSIONS
+
PRIVILEGE

Run:

Terminal window
Get-ScheduledTask

Prioritize:

Custom Tasks
Privileged Tasks
Unknown Tasks
Script-Based Tasks
Legacy Tasks
Task Action Run-As Owner Required Review
Backup Approved Script svc-backup IT Yes Current
OldTask Unknown SYSTEM Unknown Review Urgent

Assess:

Trigger
Action
Executable
Script
Run-As Identity
Filesystem Permissions
Business Owner
Finding ID:
WIN-008
Title:
Unmanaged Privileged Scheduled Task
Severity:
Medium / High
Observation:
A scheduled task runs with elevated
privileges but lacks a documented owner and
current business purpose.
Risk:
The task provides an unmanaged privileged
execution mechanism and may increase
persistence or configuration risk.
Recommendation:
Validate the task, remove it if obsolete,
or formally manage its owner, execution
content, permissions, and privilege.

Run:

Terminal window
Get-CimInstance Win32_StartupCommand |
Select-Object Name,Command,Location,User

Review:

Expected Application
Unknown Application
Administrative Utility
Legacy Component

Windows persistence mechanisms can be used by:

Legitimate Software
Administrative Tools
Management Agents
Threat Actors

Review common categories such as:

Startup Entries
Services
Scheduled Tasks
Approved Auto-Start Locations
PERSISTENCE
MALWARE

Validate:

Publisher
Executable Path
Owner
Purpose
Timeline
Telemetry

Run:

Terminal window
Get-Process

For suspicious or unknown processes assess:

Process
Executable
User
Parent
Network Activity
Publisher
Business Purpose

Use:

PROCESS
PATH
OWNER
PARENT
NETWORK
PURPOSE
TELEMETRY

Run:

Terminal window
$PSVersionTable

Document:

PowerShell Version
Administrative Usage
Management Dependencies
Logging Strategy

Run:

Terminal window
Get-ExecutionPolicy -List

Remember:

EXECUTION POLICY
COMPLETE SECURITY BOUNDARY

It is one part of a broader administrative security strategy.

Where required by the enterprise baseline, assess capabilities such as:

Script Block Logging
Module Logging
Transcription
Central Log Collection

For privileged scripts determine:

Owner
Source
Change Control
Filesystem Permissions
Execution Context
Secret Handling

Avoid:

Privileged Scheduled Task
Script Writable by Ordinary Users

58 — Review Credential Handling in Scripts

Section titled “58 — Review Credential Handling in Scripts”

Look for insecure practices such as:

Hard-Coded Passwords
Embedded API Secrets
Plaintext Credentials
Shared Administrative Credentials

Do not copy actual secrets into assessment reports.

Finding ID:
WIN-009
Title:
Insecure Credential Handling in
Administrative Script
Severity:
High
Observation:
A privileged automation process relies on
credential material stored in an
inappropriately accessible script or
configuration location.
Risk:
Unauthorized access to the credential may
enable additional privileged access.
Recommendation:
Move credential material to the approved
enterprise secret-management mechanism and
restrict access according to least
privilege.

Run:

Terminal window
auditpol /get /category:*

Save evidence if appropriate:

Terminal window
auditpol /get /category:* |
Out-File C:\WindowsSecurityAssessment-AuditPolicy.txt

Evaluate categories relevant to the asset, including:

Account Logon
Account Management
Logon/Logoff
Object Access
Policy Change
Privilege Use
Process Tracking
System

Run:

Terminal window
Get-WinEvent -LogName Security -MaxEvents 100

The goal is not to copy hundreds of events.

Determine whether important security activity is:

Generated
Retained
Collected
Searchable
Monitored

Common event IDs that may assist investigation include:

Event ID Common Meaning
4624 Successful logon
4625 Failed logon
4720 User account created
4722 User account enabled
4725 User account disabled
4726 User account deleted
4728 Member added to global security group
4732 Member added to local security group
4738 User account changed
4740 Account locked out
4756 Member added to universal security group
4768 Kerberos authentication ticket requested
4769 Kerberos service ticket requested
4776 Credential validation
1102 Audit log cleared

Availability and meaning depend on:

Audit Policy
System Role
Event Source
Environment Configuration

Always validate events within the actual environment.

Investigate patterns involving:

Repeated Failures
Administrative Accounts
Unknown Users
Unexpected Sources
Unusual Times

Possible explanations include:

User Error
Expired Credential
Scheduled Task
Service
Mapped Resource
Credential Guessing

Successful authentication can be more important than failed attempts.

Look for:

Unexpected Remote Logon
Privileged Logon
Unusual Account
Unexpected Time
Unexpected Source

Determine whether the organization can detect:

Account Creation
Account Enablement
Account Disablement
Password Changes
Group Membership Changes

Prioritize changes affecting:

Administrators
Remote Desktop Users
Sensitive Local Groups
User Rights
Service Accounts

Security log clearing deserves investigation.

Do not automatically conclude malicious activity.

Determine:

Who Performed It?
Why?
Was It Authorized?
What Happened Before?
What Happened After?

Determine whether endpoint security telemetry can identify:

Malware Detection
Remediation
Protection Changes
Security Configuration Changes

System logs may provide evidence regarding:

Service Installation
Service Failure
Drivers
Startup
Shutdown
System Errors

Run:

Terminal window
w32tm /query /status

Accurate time is critical for:

Authentication
Event Correlation
Forensics
Incident Response

Run:

Terminal window
Get-NetIPConfiguration

Document:

Interfaces
IP Addresses
Gateway
DNS
Network Role

Run:

Terminal window
Get-DnsClientServerAddress

For domain-joined systems, unexpected DNS configuration can contribute to:

Authentication Failures
Name Resolution Problems
Operational Issues

Run:

Terminal window
Get-NetRoute

Look for:

Default Route
Unexpected Static Routes
Management Networks
Multiple Interfaces

Run:

Terminal window
Get-NetTCPConnection |
Where-Object {$_.State -eq "Established"} |
Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,OwningProcess

Correlate:

REMOTE DESTINATION
PORT
PROCESS
APPLICATION
BUSINESS REQUIREMENT

Determine which networks can communicate with the system.

Consider:

User Networks
Server Networks
Management Networks
Internet
Cloud Networks
Administrative Networks

Where SMB is required, assess:

Business Requirement
Network Scope
Firewall Controls
Authentication
Security Configuration

Do not disable enterprise protocols blindly.

Validate dependencies first.

77 — Review Legacy Protocol Dependencies

Section titled “77 — Review Legacy Protocol Dependencies”

Identify dependencies on legacy technologies.

Use:

INVENTORY
DEPENDENCY ANALYSIS
RISK ASSESSMENT
PILOT
MIGRATION

Avoid:

DISABLE FIRST
ASK QUESTIONS LATER

Determine whether the system is centrally managed.

Assess:

Configuration Enforcement
Patch Management
Application Management
Security Baselines
Compliance Reporting
Remote Response

79 — Review Security Baseline Application

Section titled “79 — Review Security Baseline Application”

Compare the endpoint against an approved baseline such as the organization’s Windows hardening standard.

Example:

Control Expected
Supported OS Yes
Updates Current
Local Admin Restricted
Defender Active
Firewall Active
Disk Encryption Required
Audit Configured
Unnecessary Services Disabled
Logging Centralized

Example:

Control Expected Actual Result
OS Support Supported Supported Pass
Local Admin Restricted Broad Fail
Defender Active Active Pass
Firewall Active Active Pass
Encryption Enabled Disabled Fail
Audit Baseline Partial Review

Windows systems often drift from their approved baseline because of:

Temporary Troubleshooting
Manual Changes
Application Exceptions
Legacy Requirements
Failed Cleanup
Local Administrator Actions

Document:

Baseline
Actual State
Difference
Owner
Business Reason

Create an exception inventory.

Examples:

Firewall Exception
Defender Exclusion
Local Admin Exception
Application Exception
Audit Exception
Remote Access Exception

Every exception should have:

OWNER
+
REASON
+
SCOPE
+
APPROVAL
+
REVIEW DATE

Determine whether the security team can answer:

Who Logged In?
What Process Ran?
What Network Connection Occurred?
What Security Control Triggered?
What Account Changed?
What Service Changed?
When Did It Happen?

Determine whether relevant Windows logs reach:

SIEM
XDR
SOC Platform
Central Log Repository
WINDOWS ENDPOINT
SECURITY TELEMETRY
CENTRAL PLATFORM
DETECTION
SOC ANALYST
RESPONSE

Ask:

Who Receives Endpoint Alerts?
Who Triages Them?
What Is the Escalation Path?
What Is the Response SLA?
Who Owns Containment?

86 — Review High-Value Detection Scenarios

Section titled “86 — Review High-Value Detection Scenarios”

Consider visibility for:

New Local Administrator
Unexpected Remote Logon
Security Log Cleared
Defender Protection Changed
New Privileged Service
Suspicious Scheduled Task
Unexpected Startup Entry
Unusual Administrative PowerShell
Repeated Authentication Failure

87 — Review Endpoint Isolation Capability

Section titled “87 — Review Endpoint Isolation Capability”

Determine whether the incident-response process can:

Isolate a Device
Preserve Evidence
Maintain Security-Team Access
Investigate
Recover

depending on available endpoint-management and security capabilities.

Assess:

Backup
Recovery
Rebuild Process
Configuration Restoration
Encryption Recovery
Business Data Recovery

Before reporting:

OBSERVE
VERIFY
UNDERSTAND CONTEXT
CHECK COMPENSATING CONTROLS
ASSESS IMPACT
REPORT

Use the organization’s risk methodology.

A simplified scale:

Critical
High
Medium
Low
Informational

Consider:

Privilege
Exposure
Likelihood
Asset Criticality
Data Sensitivity
Business Impact
Existing Controls

Use:

Finding ID:
Title:
Severity:
Affected Asset:
Observation:
Evidence:
Security Risk:
Business Impact:
Recommendation:
Owner:
Target Date:
Validation Method:

92 — Finding Example — Administrative Privilege

Section titled “92 — Finding Example — Administrative Privilege”
Finding ID:
WIN-010
Title:
Excessive Local Administrative Access
Severity:
High
Observation:
Multiple standard users retain permanent
local administrator access without a
documented technical requirement.
Risk:
Credential compromise or malicious activity
may gain elevated control over the Windows
endpoint.
Recommendation:
Remove unnecessary administrator
membership and implement approved
privilege-elevation mechanisms.
Finding ID:
WIN-011
Title:
Unnecessary Inbound Network Exposure
Severity:
Medium
Observation:
An inbound Windows Firewall rule allows
network access beyond the documented
application requirement.
Risk:
The endpoint exposes additional network
attack surface.
Recommendation:
Restrict the rule to the required source,
destination, protocol, port, and profile.
Finding ID:
WIN-012
Title:
Required Full-Disk Encryption Not Enabled
Severity:
High
Observation:
The Windows system does not meet the
organization's required disk-encryption
baseline.
Risk:
Physical loss or theft could expose
corporate information stored on the device.
Recommendation:
Enable the approved encryption control and
securely manage recovery information.
Finding ID:
WIN-013
Title:
Insufficient Windows Security Auditing
Severity:
Medium
Observation:
The system does not generate all security
telemetry required by the approved
endpoint audit baseline.
Risk:
Security incidents may be more difficult to
detect and reconstruct.
Recommendation:
Apply the approved audit configuration and
validate collection by the central
monitoring platform.
Finding ID:
WIN-014
Title:
Unnecessary Privileged Windows Service
Severity:
High
Observation:
A legacy service runs with elevated
privilege despite having no confirmed
current business requirement.
Risk:
The unnecessary privileged service
increases endpoint attack surface and the
potential impact of service compromise.
Recommendation:
Validate dependencies and remove or disable
the service through approved change
management if no requirement exists.
ID Finding Severity Owner Status
WIN-010 Excessive Admin Access High Endpoint Open
WIN-011 Broad Firewall Rule Medium Network Open
WIN-012 Encryption Missing High Endpoint Open
WIN-013 Audit Gap Medium Security Open
WIN-014 Unnecessary Service High App Team Open

Use:

RISK
+
ASSET CRITICALITY
+
BUSINESS IMPACT
+
EFFORT
+
DEPENDENCIES

Examples:

Remove Confirmed Unauthorized Admin Access
Restore Disabled Endpoint Protection
Contain Confirmed Compromised System
Close Unnecessary Critical Exposure
Disable Confirmed Unauthorized Account

Examples:

Reduce Local Administrators
Review Firewall Rules
Enable Required Encryption
Remove Unsupported Software
Review Privileged Services
Improve Audit Policy

Examples:

Deploy Windows LAPS
Standardize Security Baselines
Improve Endpoint Management
Improve Application Governance
Centralize Security Logging
Improve Privileged Access

Examples:

Automated Compliance
Continuous Configuration Assessment
Application Allowlisting Strategy
Privileged Access Management
Integrated Endpoint Detection
Automated Remediation
Finding Priority Owner Remediation Target
WIN-010 High Endpoint Reduce admins 14 days
WIN-011 Medium Network Restrict firewall 30 days
WIN-012 High Endpoint Enable encryption 14 days
WIN-013 Medium Security Improve audit 30 days
WIN-014 High App Team Remove service 14 days

For Windows security changes:

UNDERSTAND
BACKUP / ROLLBACK
APPROVE
PILOT
IMPLEMENT
VALIDATE
MONITOR

Changes to:

Firewall
Authentication
Services
Group Policy
Audit
Remote Access
Legacy Protocols

may affect business applications.

Use:

TEST
PILOT
DEPLOY
MONITOR

Run:

Terminal window
Get-LocalGroupMember -Group "Administrators"

Compare:

BEFORE
APPROVED REMEDIATION
AFTER

Run:

Terminal window
Get-MpComputerStatus

Confirm required protections are operational.

Run:

Terminal window
Get-NetFirewallProfile

Then validate required application connectivity and restricted unauthorized access.

Run:

Terminal window
Get-BitLockerVolume

Confirm:

Protection State
Encryption State
Recovery Governance

Verify:

Unnecessary Service Removed or Disabled
Required Applications Still Work
Required Services Remain Healthy

Confirm:

Obsolete Task Removed
Required Task Still Works
Run-As Identity Appropriate
Executed Content Protected

Run:

Terminal window
auditpol /get /category:*

Compare against the approved baseline.

Generate an approved benign security event in the test environment.

Validate:

Event Generated
Event Stored
Event Collected
Event Searchable
Alert Generated Where Required

Where authorized, validate that:

Standard User
Cannot Perform Admin-Only Activity
Unauthorized Network Source
Cannot Reach Restricted Service
Disabled Account
Cannot Authenticate
Removed User
Cannot Use Remote Access

A finding should close only when:

Remediation Implemented
Technical Validation Completed
Business Function Verified
Evidence Captured
Residual Risk Documented

If a finding cannot be remediated:

Document the Risk
Identify the Risk Owner
Document the Business Reason
Define Compensating Controls
Set a Review Date
Set an Expiration Date

Risk acceptance is not:

Ignore the Finding

117 — Build the Final Windows Security Report

Section titled “117 — Build the Final Windows Security Report”

Recommended structure:

01 Executive Summary
02 Scope
03 Asset Overview
04 Assessment Methodology
05 Operating System Security
06 Identity and Privilege
07 Authentication
08 Security Policy
09 Endpoint Protection
10 Firewall and Network Exposure
11 Encryption
12 Applications
13 Services
14 Persistence
15 PowerShell Security
16 Audit and Logging
17 Incident Readiness
18 Findings
19 Remediation Roadmap
20 Retest Results

Write for:

CISO
CIO
IT Leadership
Infrastructure Management
Business Owner

Explain:

What Was Assessed?
What Are the Main Risks?
What Is the Business Impact?
What Should Be Fixed First?

Example:

The Windows security assessment identified
opportunities to improve local
administrative access, endpoint hardening,
disk encryption, service governance, and
security auditing.
The highest-priority actions are to remove
unnecessary administrative access, ensure
required endpoint protection is active,
enable approved encryption, and reduce
unnecessary privileged services.

Include:

Hostname
Business Owner
Operating System
Version
Domain
Business Function
Criticality
Data Classification

Document:

Configuration Review
Account Review
Privilege Review
Endpoint Protection Review
Firewall Review
Encryption Review
Application Review
Service Review
Persistence Review
Audit Review
Network Review
Evidence Validation

Use a simple timeline:

0–14 Days
Critical exposure, privilege, protection,
and encryption issues
15–30 Days
Application, service, firewall, and
configuration cleanup
31–90 Days
Baseline, monitoring, and management
improvements
90+ Days
Automation and continuous validation
  • Written authorization confirmed
  • Systems in scope documented
  • Exclusions documented
  • Assessment window confirmed
  • Evidence requirements confirmed
  • Hostname documented
  • Owner documented
  • Business role documented
  • Criticality documented
  • Domain membership reviewed
  • OS version reviewed
  • Support status reviewed
  • Build reviewed
  • Patch process reviewed
  • Pending maintenance reviewed
  • Local users inventoried
  • Dormant accounts reviewed
  • Local groups reviewed
  • Account ownership reviewed
  • Disabled accounts reviewed
  • Administrators group reviewed
  • Permanent privilege reviewed
  • Built-in administrator reviewed
  • Remote admin access reviewed
  • Local credential management reviewed
  • Windows LAPS strategy reviewed
  • Password policy reviewed
  • Lockout reviewed
  • Remote authentication reviewed
  • Administrative authentication reviewed
  • Local security policy reviewed
  • User rights reviewed
  • Security options reviewed
  • Exceptions documented
  • Defender health reviewed
  • Real-time protection reviewed
  • Security intelligence reviewed
  • Exclusions reviewed
  • Alert ownership reviewed
  • Domain profile reviewed
  • Private profile reviewed
  • Public profile reviewed
  • Inbound rules reviewed
  • Listening ports reviewed
  • Network scope reviewed
  • BitLocker reviewed
  • System volume reviewed
  • Recovery process reviewed
  • TPM reviewed
  • Applications inventoried
  • Unsupported software reviewed
  • Unnecessary software reviewed
  • Application ownership reviewed
  • Running services reviewed
  • Service accounts reviewed
  • Privileged services reviewed
  • Unnecessary services reviewed
  • Service executables reviewed
  • Scheduled tasks reviewed
  • Startup items reviewed
  • Auto-start services reviewed
  • Unknown persistence validated
  • PowerShell environment reviewed
  • Execution policy reviewed
  • Logging reviewed
  • Administrative scripts reviewed
  • Credential handling reviewed
  • Audit policy reviewed
  • Security events reviewed
  • Authentication events reviewed
  • Account changes reviewed
  • Privilege changes reviewed
  • Defender events reviewed
  • Time synchronization reviewed
  • IP configuration reviewed
  • DNS reviewed
  • Routes reviewed
  • Listening ports reviewed
  • Established connections reviewed
  • Segmentation reviewed
  • Central logging reviewed
  • Alert ownership reviewed
  • Endpoint isolation process reviewed
  • Recovery process reviewed
  • Escalation process reviewed
  • Every finding validated
  • Business context considered
  • Severity justified
  • Evidence captured
  • Recommendations actionable
  • Owners assigned
  • Immediate actions defined
  • Short-term actions defined
  • Medium-term actions defined
  • Long-term improvements defined
  • Dependencies identified
  • Administrative access retested
  • Defender retested
  • Firewall retested
  • Encryption retested
  • Services retested
  • Audit retested
  • Business functionality validated
  • Evidence captured

Avoid:

Starting Without Authorization
Treating Every Open Port as a Vulnerability
Treating Every Unknown Process as Malware
Removing Local Administrators Without
Understanding Dependencies
Disabling Services Without Testing
Disabling Protocols Blindly
Disabling Firewall to Fix Applications
Creating Broad Defender Exclusions
Ignoring Disk Encryption
Ignoring Scheduled Tasks
Ignoring PowerShell Security
Ignoring Application Ownership
Ignoring Security Logs
Treating Logging as Monitoring
Hardening Without Rollback Planning
Reporting Configuration Differences
Without Business Context
Supported OS
Patching
Antivirus
Firewall
Disk Encryption
Restricted Local Admin
Security Baseline
Audit Policy
Reduced Services
Central Endpoint Management
Windows LAPS
Configuration Enforcement
Application Governance
Centralized Logging
EDR / XDR
Privileged Access Management
Automated Compliance
Continuous Detection
Automated Remediation
Continuous Security Validation

You discover that every employee is a local administrator. What should you do?

Do not remove everyone immediately.

Use:

IDENTIFY DEPENDENCIES
CLASSIFY USER REQUIREMENTS
DESIGN ELEVATION MODEL
PILOT
REMOVE PERMANENT ADMIN
VALIDATE

You discover a Windows Firewall profile is disabled. Is that automatically critical?

No.

Determine:

System Role
Network Exposure
Other Firewalls
Segmentation
Reason
Business Impact

Then assess actual risk.

You find an unknown scheduled task running as SYSTEM. What do you do?

Review:

Task Definition
Executable
Script
Owner
Creation Context
Publisher
Business Purpose
Security Telemetry

Do not immediately delete it.

A server cannot enable BitLocker immediately. What should happen?

Document:

Reason
Data Sensitivity
Physical Exposure
Compensating Controls
Risk Owner
Remediation Plan
Target Date

Why is centralized Windows logging important?

Because local logs may be:

Unavailable After Failure
Modified
Cleared
Difficult to Correlate

Centralized telemetry improves:

Detection
Investigation
Correlation
Retention

40 Windows Security Assessment Interview Questions

Section titled “40 Windows Security Assessment Interview Questions”
  1. What is a Windows security assessment?
  2. Why must system role be identified before assessment?
  3. Why is OS support status important?
  4. How would you review Windows patching?
  5. Why should local users be inventoried?
  6. What is a dormant account?
  7. Why should local Administrators membership be restricted?
  8. What is least privilege?
  9. Why separate standard and administrative activity?
  10. What problem does Windows LAPS help solve?
  11. Why is local administrator password reuse risky?
  12. What is Local Security Policy?
  13. What are user rights assignments?
  14. Why should RDP access be reviewed?
  15. What is Microsoft Defender Antivirus?
  16. Why should Defender exclusions be reviewed?
  17. What is Windows Firewall?
  18. What are Windows Firewall profiles?
  19. How would you review inbound firewall exposure?
  20. How do you identify listening ports?
  21. Why does a listening port not automatically mean internet exposure?
  22. What is BitLocker?
  23. Why is recovery-key governance important?
  24. What role can TPM play in Windows security?
  25. Why should installed applications be inventoried?
  26. Why is unsupported software a risk?
  27. Why should running services be reviewed?
  28. Why are service accounts security sensitive?
  29. Why should scheduled tasks be reviewed?
  30. What is Windows persistence?
  31. Does an auto-start mechanism automatically indicate malware?
  32. Why is PowerShell important to defenders?
  33. Is PowerShell Execution Policy a security boundary?
  34. What is Windows audit policy?
  35. Which Windows events are useful for authentication investigations?
  36. Why is time synchronization important?
  37. Why should established network connections be reviewed?
  38. What is configuration drift?
  39. Why must remediation be retested?
  40. What should a professional Windows security report contain?

Remember:

UNDERSTAND THE ASSET
VERIFY THE OS
IDENTIFY USERS
IDENTIFY ADMINISTRATORS
REVIEW AUTHENTICATION
REVIEW SECURITY POLICY
VERIFY ENDPOINT PROTECTION
VERIFY FIREWALL
VERIFY ENCRYPTION
REVIEW APPLICATIONS
REVIEW SERVICES
REVIEW PERSISTENCE
REVIEW POWERSHELL
REVIEW AUDITING
REVIEW NETWORK EXPOSURE
VALIDATE FINDINGS
PRIORITIZE RISK
REMEDIATE
RETEST

The most important question is not:

Is This Windows Setting Enabled?

It is:

Does This Windows System
Have the Appropriate Security Controls
for Its Business Role,
Threat Exposure,
Privilege,
and Data Sensitivity?

You have now completed a repeatable professional procedure for assessing:

Windows Operating System Security
Local Identity
Administrative Privilege
Authentication
Security Policy
Microsoft Defender
Windows Firewall
BitLocker
Applications
Services
Scheduled Tasks
Persistence
PowerShell
Audit Policy
Security Logs
Network Exposure
Incident Readiness
Remediation
Retesting

You have now completed the Microsoft security sequence:

00 Introduction
Microsoft Security Certification Roadmap
Microsoft 365 Fundamentals
Endpoint Administration
Microsoft Identity & Security
Lab 01 — Active Directory
Lab 02 — Endpoint Security
Lab 03 — Identity Security
Lab 04 — Microsoft 365 Security
Lab 05 — Windows Security
Runbook 01 — Active Directory Assessment
Runbook 02 — Microsoft 365 Security Review
Runbook 03 — Windows Security Assessment

You have progressed from understanding Microsoft technologies to assessing them through the mindset of:

Administrator
Security Engineer
SOC Analyst
Identity Defender
Security Consultant

The final principle to carry forward is:

SECURITY ASSESSMENT
IS NOT
A CHECKLIST OF SETTINGS

A professional assessment connects:

TECHNICAL CONFIGURATION
+
THREAT EXPOSURE
+
BUSINESS CONTEXT
+
SECURITY IMPACT
+
ACTIONABLE REMEDIATION

➡️ Microsoft Security Path Complete

You are ready to apply these runbooks repeatedly against authorized lab and enterprise environments, build assessment evidence, document professional findings, validate remediation, and develop the practical assessment mindset expected from enterprise security professionals.