Windows is not an operating system. It is an ecosystem.
Active Directory, ten years of GPO sprawl, WSUS debt, Server 2012 already end-of-life, Server 2016 following in 2027. Your Linux team has Ansible, Golden Images, and a compliance scanner. Your Windows team is still managing Group Policies by hand.
Secure Windows Platform Automation is the module that will close this gap. It brings Ansible automation, CIS Windows Benchmark hardening, and machine-generated compliance assessment to grown Windows landscapes. The module is under development. Today, Benjamin Strebel is available as a Windows specialist in the EaaS model.
What your Linux team has. What your Windows team has.
In most organizations, two worlds exist side by side: a Linux infrastructure that has run on automation for years, and a Windows infrastructure still managed the same way it was a decade ago. Both carry the same compliance requirements. Only one of them has the tooling to meet them.
- Ansible playbooks for reproducible configuration
- Golden Images: hardened, versioned, documented
- Compliance scanner with automatically generated reports
- Infrastructure as Code: target state visible in Git
- Hardening baseline per CIS Benchmark, machine-verified
- Drift detection when deviation from the defined state occurs
- GPO console: edited manually, accumulated over ten years
- PowerShell scripts from 2016, original author unknown
- WSUS: manual approvals, incomplete update chains
- Configuration state: undocumented, barely reproducible
- Compliance evidence: PDF export from the last audit
- Drift: not visible until the next audit
Why Windows hardening is systemically more complex
Linux systems tend to be more isolated: one service, one configuration, one defined state. Windows infrastructures are interconnected. Every GPO change affects all connected systems. Active Directory is the invisible link that holds everything together and at the same time makes everything dependent.
This is not a criticism of Windows. It is a description of the reality that fundamentally shapes any hardening approach.
- Active Directory as a multiplier Every GPO change propagates system-wide. A mistake does not affect one server. It affects all of them.
- GPO sprawl Ten years of environment often means hundreds of GPOs with no clear picture. Which one applies? Which one is outdated? Which one overrides which? Nobody knows anymore.
- WSUS debt Manual approvals, broken update chains, systems that have not received a patch in months. No automated documentation of patch status.
- Service account chaos Accounts without expiry, with domain admin rights, for services nobody uses or remembers configuring.
- EOL pressure without a migration plan Windows Server 2012 reached end-of-life in October 2023. Server 2016 loses Extended Support in January 2027. A defined target state for the destination platform is missing.
"The Linux team gets a merge request when something changes in the hardening baseline. The Windows team gets an audit finding."
That is not a failure of the Windows team. It is the result of missing tooling. That is exactly what this module is designed to change.
Relevant frameworks for these environments
- CIS Windows Server Benchmark
- NIS2: technical protective measures and risk management
- BSI IT-Grundschutz: common in public sector and financial institutions
- ISO 27001: evidence of technical controls
Three situations we encounter regularly
EOL pressure without a migration plan
Windows Server 2012 is already end-of-life. Server 2016 loses Extended Support in January 2027. There is no migration to 2022 because no clear target state has been defined for the destination platform and no reproducible base to build the migration on.
GPO sprawl with no overview
The environment has 150 to 300 active Group Policies. No visibility into which one applies, which is outdated, or which overrides which. A CIS baseline does not exist as a defined system state, only as a Word document from a project years ago.
Compliance audit reveals gaps
ISO 27001, NIS2, or BSI IT-Grundschutz require technical evidence for hardening measures. The Windows team cannot produce machine-readable reports. The audit finding describes the actual state as insufficiently documented.
What the module will deliver
This module is under development. The capabilities below describe the planned scope. They represent a direction, not a delivery commitment available today.
Ansible for Windows
Configuration and hardening via Ansible for Windows (WinRM). Playbooks for reproducible system states, integrable into existing CI/CD pipelines. What the Linux team has had for years, coming to Windows.
CIS Windows Baseline
Hardening standard based on the CIS Windows Server Benchmark as a versioned, documented target state. GPO migration to the baseline, not to the next ad-hoc configuration.
Automated Compliance Assessment
PowerShell- or Python-based assessment of systems against the defined baseline. Machine-readable reports for internal audits and frameworks including NIS2, ISO 27001, and BSI IT-Grundschutz.
Drift Detection
Continuous detection of deviations from the defined system state. Enforcement via PowerShell DSC or Ansible remediation, risk-based and fully traceable.
Windows and IIS: one platform, two layers
IIS runs on Windows. IIS is configured through Windows mechanisms: Registry, GPO, certificate management. An unhardened Windows base undermines any IIS-specific security measure. The two modules are aligned and together cover the complete platform layer.
Secure IIS Platform Automation
TLS, security headers, app pool isolation, and CIS IIS Benchmark hardening built on the hardened Windows foundation.
What is available today
The module is described, the implementation is open. Today, Benjamin Strebel, DevOps Engineer with a focus on Windows automation, is available full-time in the EaaS model.
- EaaS engagement: Benjamin Strebel as Windows specialist, available full-time
- Windows hardening consulting based on the CIS Windows Benchmark
- GPO analysis and migration planning to the CIS baseline
- PowerShell DSC and Ansible for Windows in concrete project contexts
- Active Directory integration and service account audit
- EOL migration planning: Server 2012/2016 to 2022
- Ansible playbook library for Windows hardening
- Automated compliance scanner with machine-readable reports
- Drift detection and automated remediation
- Golden Images for Windows Server 2022
- Productized module as a standalone offering
Speak with our Windows Expert
Benjamin Strebel, DevOps Engineer specializing in Windows automation, PowerShell DSC, and Ansible for Windows, is available full-time in the EaaS model.
No commitment · No sales pitch · Confidential