Secured new Windows and Debian workstations for ABC Tech by applying baseline endpoint controls across both systems. The scenario focused on reducing exposed services, enforcing stronger authentication, and aligning workstation configuration with organizational hardening directives.
Enabled Windows Firewall on ZYWIN01, disabled Guest access, and shut down Print Spooler, SMTP, and OpenSSH services to reduce attack surface
Applied stronger Windows account controls with a 10-character minimum password, complexity enabled, lockout after 5 failed attempts, and a 60-minute lockout duration
Enabled UFW on ZYDEB01, then stopped and disabled nginx and vsftpd to prevent unnecessary network exposure
Hardened Debian password policy with PASS_MAX_DAYS 45, PASS_MIN_DAYS 10, WARN_AGE 3, minimum length 12, digit and uppercase requirements, and enforcement for root