implementing-anti-ransomware-group-policy - Windows Ransomware Defense via Group Policy
Configures Windows GPO to prevent ransomware execution and spread
Tags
Updated: 2026-05-28Capabilities
Typical Inputs
Typical Outputs
What this skill does
- configure AppLocker rules
- enable Controlled Folder Access
- enable Attack Surface Reduction rules
- disable SMBv1
- restrict Remote Desktop
- disable remote WMI
- disable AutoPlay
- restrict PowerShell remoting
- configure network protection
- disable Application Identity service
- block executable paths
Inputs
- Active Directory environment
- Group Policy Creator Owners privileges
- Windows 10/11 Enterprise or Education
- Microsoft Defender Antivirus
- Group Policy Management Console
- Test OU
Outputs
- Configured AppLocker rules
- Enabled Controlled Folder Access
- Enabled Attack Surface Reduction rules
- Configured Software Restriction Policies
- Configured network protection settings
- Configured system services
- Disabled SMBv1
- Restricted Remote Desktop
- Disabled remote WMI
- Disabled AutoPlay
- GPO compliance audit results
Requirements
- Windows Server 2016+
- Windows 10/11 Enterprise or Education
- Microsoft Defender Antivirus
- Python 3.8+
- Group Policy Management Console
- Domain Admin privileges
