The Caution ListChanges You Should Not Make
There are certain tweaks that you should not make. Nevertheless, you see them recommended in various sources. It is worth mentioning these and why you should not make them.
Account Lockout
We do not go into depth about it here. However, account lockout will almost certainly increase your help desk cost significantly. In addition, it also only protects bad passwords. You would be better off getting rid of guessable passwords.
Full Privilege Auditing
FullPrivilegeAuditing, or "Audit: Audit the use of Backup and Restore privilege" in Group Policy, configures the system to audit all file access even when they are performed by a backup program. This setting is one of several "blow up my event logs" settings that will simply fill your event logs with a large amount of mostly useless information that you probably do not care about anyway.
In this tutorial:
- Protecting Hosts
- Security Configuration Myths
- Myth 1: Security Guides Make Your System Secure
- Myth 2: If We Hide It, they Not Find It
- Myth 3: The More Tweaks, the Better
- Myth 4: Tweaks Are Necessary
- Myth 5: All Environments Should At Least Use <Insert Favorite Guide Here>
- Myth 6: "High Security" Is an End Goal for All Environments
- Myth 7: Start Securing Your Environment by Applying a Security Guide
- Myth 8: Security Tweaks Can Fix Physical Security Problems
- Myth 9: Security Tweaks Will Stop Worms/Viruses
- Myth 10: An Expert Recommended This Tweak as Defense in Depth
- Server Security Tweaks
- Software Restriction Policies
- Do Not Store LAN Manager Hash Value
- Anonymous Restrictions
- Security Identifiers (SIDs)
- Password Policies
- SMB Message Signing
- Networking LAN Manager Authentication Level
- TCP Hardening
- Restricted Groups
- Audit Settings
- Client Security Tweaks
- Firewalls
- IPsec Filters
- SafeDllSearchMode
- Local Administrator Account Control
- Limit Local Account Use of Blank Passwords to Console Logon Only
- Logon Events
- Allowed to Format and Eject Removable Media
- The Caution ListChanges You Should Not Make
- Crash on Audit Failure
- Clear Virtual Memory Page File
- Security Configuration Tools