Microsoft 365 and Entra ID
Third-party app consent only with approval, legacy authentication disabled, automatic external forwarding blocked, and guest and external access settings in Teams reviewed.
Software and devices leave the factory configured to be easy to set up, not to be safe. Old protocols stay enabled for compatibility, any employee can let an outside app into company mailboxes, and the printer's web interface sits on the network with its default password. None of these is a disaster on its own, but they are exactly what attackers look for. Consider a law firm where the file server still speaks a file-sharing protocol from a decade ago, staff in Microsoft 365 can let any app read their email, and Office macros run even in documents downloaded from the internet. Fixing all of that needs no new product, only settings. System hardening is the methodical review of those settings against published references like CIS Benchmarks and Microsoft security baselines. Changing a setting is simple; changing it without breaking something that works is the real skill. So we measure first, test on a small group, then apply, and record every exception along with its reason.
Work proceeds tier by tier, starting with the cloud tenant and ending at individual printers, and every tier is assessed, adjusted and retested.
Third-party app consent only with approval, legacy authentication disabled, automatic external forwarding blocked, and guest and external access settings in Teams reviewed.
Microsoft baselines deployed via Intune or GPO, macros blocked in documents from the internet, PowerShell restrictions and a tidy-up of local admin accounts.
Retiring SMBv1 and NTLMv1, unneeded services like the print spooler switched off on servers that do not print, admin accounts tiered and password policies modernised.
SSH restricted to keys, root unable to log in directly, a local firewall on each host, unattended security patching and a trimmed package list.
Default passwords changed, unencrypted management protocols turned off and firmware updated. Printers, NAS units and camera recorders are frequently the weakest link.
Regular automated checks that hardened settings are still in place, so that an update or a rushed change undoing them gets noticed.
Hardening without preparation can break things, which is why progress comes in small steps that can each be checked.
Systems are scanned automatically against the selected benchmark. The output lists each setting's current value, the recommended value and the likely impact of changing it.
We jointly settle which settings change and where a justified exception stays, for example a protocol an old business application still depends on.
Changes land on test machines and a few pilot users before the wider estate. They are applied through policies so they can be rolled back if needed.
A repeat scan and the exception register with reasons. If you like, drift monitoring carries on as a recurring service.
The cheapest security improvement is switching on something you already own. Hardening needs no new product, console or licence, only attention and discipline. Many attack chains run through a single default setting that should have been changed years ago.
Consensus-built hardening guides from the Center for Internet Security, a not-for-profit body, covering operating systems, cloud platforms and network equipment in setting-by-setting detail. They are free to access and are widely used as a concrete, setting-level reference in frameworks such as ISO 27001.
No. Some do not suit every environment and a few can break older applications. We pick those that make sense for you and write a short justification for the rest. A documented exception looks far better in an audit than a silent gap.
We keep the protocol enabled only on the server and clients that run that application and disable it everywhere else. The exception goes into the risk register with a reminder to upgrade or replace the application.
Because changes are made through policies, rolling back takes minutes, and the pilot catches most problems early. If something slips through, email helpme@apply.tr; we reverse the setting, find the cause and apply a targeted fix.
Tell us which systems you run and roughly how many. We will say which layer to harden first for the biggest benefit.
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.