implementing-anti-ransomware-group-policy - Anti-Ransomware Group Policy Configuration
Configures Windows GPO to prevent ransomware execution and limit spread
Tags
Updated: 2026-05-28Capabilities
What this skill does
- Configure AppLocker rules
- Enable Controlled Folder Access
- Configure ASR rules
- Restrict SMBv1
- Restrict RDP access
- Block WMI remote
- Disable AutoPlay
- Configure PowerShell restrictions
- Audit GPO compliance
- Validate GPO settings
Inputs
- Active Directory environment
- Domain Admin privileges
- Windows 10/11 endpoints
- Protected folder paths
- Trusted application paths
Outputs
- AppLocker GPO rules
- Controlled Folder Access settings
- ASR rule configurations
- Network restriction policies
- PowerShell execution policies
- GPO compliance reports
Requirements
- Windows Server 2016+
- Group Policy Management Console
- Domain Admin privileges
- Windows 10/11 Enterprise or Education
- Microsoft Defender Antivirus enabled
- Python 3.8+
