implementing-anti-ransomware-group-policy - Configure Windows GPO for Ransomware Prevention
Configures Windows Group Policy to block ransomware execution and limit spread via AppLocker, CFA, and ASR rules
Tags
Updated: 2026-05-28Capabilities
Typical Inputs
Typical Outputs
What this skill does
- configure AppLocker rules
- enable Controlled Folder Access
- set ASR rules
- restrict SMBv1
- restrict RDP
- restrict WMI
- disable AutoPlay
- restrict PowerShell
- audit GPO compliance
Inputs
- Active Directory environment
- domain admin privileges
- Windows 10/11 endpoints
- Microsoft Defender Antivirus
- test organizational unit
Outputs
- configured GPO settings
- AppLocker rules
- protected folder list
- ASR rule settings
- network restrictions
- GPO compliance reports
Requirements
- Windows Server 2016+
- Group Policy Management Console
- Windows 10/11 Enterprise or Education
- Microsoft Defender Antivirus
- Python 3.8+
