Platform Module · In Development

Windows is not an operating system. It is an ecosystem.

Active Directory, ten years of GPO sprawl, WSUS debt, Server 2012 already end-of-life, Server 2016 following in 2027. Your Linux team has Ansible, Golden Images, and a compliance scanner. Your Windows team is still managing Group Policies by hand.

Secure Windows Platform Automation is the module that will close this gap. It brings Ansible automation, CIS Windows Benchmark hardening, and machine-generated compliance assessment to grown Windows landscapes. The module is under development. Today, Benjamin Strebel is available as a Windows specialist in the EaaS model.

What your Linux team has. What your Windows team has.

In most organizations, two worlds exist side by side: a Linux infrastructure that has run on automation for years, and a Windows infrastructure still managed the same way it was a decade ago. Both carry the same compliance requirements. Only one of them has the tooling to meet them.

Your Linux Team
  • Ansible playbooks for reproducible configuration
  • Golden Images: hardened, versioned, documented
  • Compliance scanner with automatically generated reports
  • Infrastructure as Code: target state visible in Git
  • Hardening baseline per CIS Benchmark, machine-verified
  • Drift detection when deviation from the defined state occurs
Your Windows Team
  • GPO console: edited manually, accumulated over ten years
  • PowerShell scripts from 2016, original author unknown
  • WSUS: manual approvals, incomplete update chains
  • Configuration state: undocumented, barely reproducible
  • Compliance evidence: PDF export from the last audit
  • Drift: not visible until the next audit

Why Windows hardening is systemically more complex

Linux systems tend to be more isolated: one service, one configuration, one defined state. Windows infrastructures are interconnected. Every GPO change affects all connected systems. Active Directory is the invisible link that holds everything together and at the same time makes everything dependent.

This is not a criticism of Windows. It is a description of the reality that fundamentally shapes any hardening approach.

  • Active Directory as a multiplier Every GPO change propagates system-wide. A mistake does not affect one server. It affects all of them.
  • GPO sprawl Ten years of environment often means hundreds of GPOs with no clear picture. Which one applies? Which one is outdated? Which one overrides which? Nobody knows anymore.
  • WSUS debt Manual approvals, broken update chains, systems that have not received a patch in months. No automated documentation of patch status.
  • Service account chaos Accounts without expiry, with domain admin rights, for services nobody uses or remembers configuring.
  • EOL pressure without a migration plan Windows Server 2012 reached end-of-life in October 2023. Server 2016 loses Extended Support in January 2027. A defined target state for the destination platform is missing.

"The Linux team gets a merge request when something changes in the hardening baseline. The Windows team gets an audit finding."

That is not a failure of the Windows team. It is the result of missing tooling. That is exactly what this module is designed to change.

Relevant frameworks for these environments

  • CIS Windows Server Benchmark
  • NIS2: technical protective measures and risk management
  • BSI IT-Grundschutz: common in public sector and financial institutions
  • ISO 27001: evidence of technical controls

Three situations we encounter regularly

01

EOL pressure without a migration plan

Windows Server 2012 is already end-of-life. Server 2016 loses Extended Support in January 2027. There is no migration to 2022 because no clear target state has been defined for the destination platform and no reproducible base to build the migration on.

02

GPO sprawl with no overview

The environment has 150 to 300 active Group Policies. No visibility into which one applies, which is outdated, or which overrides which. A CIS baseline does not exist as a defined system state, only as a Word document from a project years ago.

03

Compliance audit reveals gaps

ISO 27001, NIS2, or BSI IT-Grundschutz require technical evidence for hardening measures. The Windows team cannot produce machine-readable reports. The audit finding describes the actual state as insufficiently documented.

What the module will deliver

This module is under development. The capabilities below describe the planned scope. They represent a direction, not a delivery commitment available today.

In Development

Ansible for Windows

Configuration and hardening via Ansible for Windows (WinRM). Playbooks for reproducible system states, integrable into existing CI/CD pipelines. What the Linux team has had for years, coming to Windows.

In Development

CIS Windows Baseline

Hardening standard based on the CIS Windows Server Benchmark as a versioned, documented target state. GPO migration to the baseline, not to the next ad-hoc configuration.

In Development

Automated Compliance Assessment

PowerShell- or Python-based assessment of systems against the defined baseline. Machine-readable reports for internal audits and frameworks including NIS2, ISO 27001, and BSI IT-Grundschutz.

In Development

Drift Detection

Continuous detection of deviations from the defined system state. Enforcement via PowerShell DSC or Ansible remediation, risk-based and fully traceable.

Windows and IIS: one platform, two layers

IIS runs on Windows. IIS is configured through Windows mechanisms: Registry, GPO, certificate management. An unhardened Windows base undermines any IIS-specific security measure. The two modules are aligned and together cover the complete platform layer.

Platform Module · In Development

What is available today

The module is described, the implementation is open. Today, Benjamin Strebel, DevOps Engineer with a focus on Windows automation, is available full-time in the EaaS model.

Available today
  • EaaS engagement: Benjamin Strebel as Windows specialist, available full-time
  • Windows hardening consulting based on the CIS Windows Benchmark
  • GPO analysis and migration planning to the CIS baseline
  • PowerShell DSC and Ansible for Windows in concrete project contexts
  • Active Directory integration and service account audit
  • EOL migration planning: Server 2012/2016 to 2022
In Development
  • Ansible playbook library for Windows hardening
  • Automated compliance scanner with machine-readable reports
  • Drift detection and automated remediation
  • Golden Images for Windows Server 2022
  • Productized module as a standalone offering

Speak with our Windows Expert

Benjamin Strebel, DevOps Engineer specializing in Windows automation, PowerShell DSC, and Ansible for Windows, is available full-time in the EaaS model.

No commitment · No sales pitch · Confidential

lennlay – Secure Platforms. Automated. Auditable.