implementing-anti-ransomware-group-policy - Configure Windows GPO for Ransomware Defense
Configures Windows Group Policy to prevent ransomware execution and spread
Tags
Updated: 2026-05-28Capabilities
Typical Inputs
Typical Outputs
What this skill does
- configure AppLocker rules
- enable Controlled Folder Access
- configure ASR rules
- restrict network protocols
- audit GPO compliance
Inputs
- Windows Server 2016+
- Active Directory environment
- Group Policy Management Console
- Domain Admin privileges
- Windows 10/11 Enterprise
- Microsoft Defender Antivirus
Outputs
- AppLocker rules
- Controlled Folder Access configuration
- Attack Surface Reduction rules
- network restriction settings
- GPO compliance report
Requirements
- Windows Server 2016+
- Domain Admin privileges
- Windows 10/11 Enterprise or Education
- Microsoft Defender Antivirus enabled
