Microsoft 365 and Entra ID
User consent to third-party apps only after approval, no automatic forwarding to outside addresses, audit logging on, tighter defaults for sharing and Teams guest access.
We harden layer by layer, from the cloud tenant down to a single printer. Each layer is assessed, changed and then tested.
User consent to third-party apps only after approval, no automatic forwarding to outside addresses, audit logging on, tighter defaults for sharing and Teams guest access.
Security baselines through Intune or Group Policy, internet macros blocked, a unique local admin password per device, unneeded services disabled, credential protection enabled.
Legacy protocols such as SMBv1 and NTLMv1 switched off, a tiered model for admin accounts, domain controllers locked down, stale accounts and groups removed.
Key-based login only, no direct root login, a host firewall, automatic security updates and a minimal package set.
Factory passwords replaced, insecure management access such as Telnet or plain HTTP closed, firmware updated, unused features like scan-to-FTP turned off.
Automated checks at intervals confirm the hardened settings still apply, for instance after updates or after someone changed something while troubleshooting.
Hardening can break things if done without preparation, so we move in small, verifiable steps.
An automated comparison of your systems against the chosen guidance. You get a list of deviations with risk and likely side effects.
Together we decide what changes and where justified exceptions apply, for example an older machine controller that relies on an old protocol.
Test systems and a pilot group first, then everyone else. Changes are made remotely in maintenance windows, with a documented rollback.
A re-check and handover of the exception list with reasons. Ongoing monitoring within a service plan if you wish.
The cheapest security measure is one you have already paid for. Many successful attacks on SMEs exploit settings that could have been closed with built-in tools: a legacy protocol, open app consent, a factory password on a printer. Hardening costs working time, not new software.
If done carelessly, yes. That is why we test with a pilot group first, confirm with the software partner which protocols and rights the application needs, and document justified exceptions instead of abandoning the hardening.
The assessment takes a few days; implementation takes two to six weeks depending on findings, because we work in waves and wait after each one to see whether problems appear.
Freely available configuration recommendations for operating systems, cloud services and applications, maintained by a non-profit organisation. They are not law, but they are a widely accepted yardstick that auditors also refer to.
Mostly yes, if it is applied through Intune or Group Policy. Major feature updates can introduce new settings, though, which is why we recommend regular automated checks.
Give us a rough outline of your systems. We will tell you which hardening steps pay off most in comparable environments.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.