M1036Account Use Policies
Reduce brute-force and abuse with account lockout, logon time/location restrictions, and concurrent session limits.
Loading…
Gaining initial access to the network/system
Reduce brute-force and abuse with account lockout, logon time/location restrictions, and concurrent session limits.
Reducing application-layer vulnerabilities at the source through secure development practices.
Monitoring credential exposure in breach databases, paste sites, and dark web forums; over 30% of initial accesses use previously stolen credentials.
Layered phishing defense combining email authentication (SPF/DKIM/DMARC) and content protection (Defender for Office 365).
Platform protections (DEP, ASLR, CFG, CET) that block memory corruption and exploitation techniques.
Restricting inbound/outbound traffic with default-deny filtering, egress control, and anti-spoofing (uRPF/BCP38).
A formal incident response plan aligned with SANS PICERL and NIST SP 800-61; organizations with a tested IR plan contain incidents 3x faster.
Multi-factor authentication that stops the vast majority of password-based attacks; enforced in Entra via Conditional Access.
IDS/IPS that detects and blocks known malicious patterns and anomalies in network traffic, with proper sensor placement.
Keep the number and use of privileged accounts to a minimum: Domain Admins hygiene, LAPS, JIT/PIM.
Narrows egress channels with DNS hardening (protective DNS/RPZ + sinkhole) and web proxy/filtering.
Requiring Secure by Design / Secure by Default products from vendors; the CISA initiative shifts security responsibility to the manufacturer.
Closing the exploitation surface by timely patching of known vulnerabilities; eliminates one of the most common origins of breaches.
Reducing human-originated risk by training users on phishing, social engineering, and secure behavior.
Regular internal/external scanning and external attack surface management to find vulnerabilities before attackers do.
A least-privilege architecture that rejects the assumption of a trusted internal network and verifies every access request by identity, device, and context.