Windows Server 2022: Basic Server Hardening Checklist
A new Windows Server installation is often left with default settings, open management paths and unnecessary services.
Read solution →\n
Troubleshooting guides and practical solution notes based around the work we handle: Windows Server, RDP, VPN, Sophos Firewall, cloud accounting, CCTV, networking, backup, printers, websites and IT AMC.
A new Windows Server installation is often left with default settings, open management paths and unnecessary services.
Read solution →RDP is useful for remote support, but exposing it directly to the internet increases the attack surface.
Read solution →Server Manager may fail because of damaged system components, management service issues or a Windows component problem.
Read solution →A server upgrade can affect applications, permissions, shares, databases and remote access.
Read solution →Old accounts and unmanaged group membership make administration harder and can create unnecessary access.
Read solution →Repeated password mistakes can lock a domain account and stop a user from working.
Read solution →Users can have correct share permissions but still receive Access Denied because NTFS permissions, inheritance or group membership are wrong.
Read solution →Some businesses want RDP for application access but do not want clipboard or drive redirection to move files.
Read solution →A session server may need to run one business application while web browsing remains restricted.
Read solution →Shared RDP servers can become difficult to control when every user can launch installed software.
Read solution →Unexpected listening ports can reveal services that are no longer needed.
Read solution →A single backup copy on the same server does not protect well against disk failure, ransomware or accidental deletion.
Read solution →Patch reboots can interrupt business applications if they happen without planning.
Read solution →A high CPU reading is a symptom, not a diagnosis.
Read solution →Memory pressure can slow applications, trigger paging and make RDP sessions unstable.
Read solution →A server can have a fast CPU but still feel slow when storage latency is high.
Read solution →Event logs become difficult to use when nobody reviews them or when critical events are lost in noise.
Read solution →Routine maintenance is safer when technicians follow the same sequence every time.
Read solution →A single administrator account used everywhere makes auditing and recovery difficult.
Read solution →Unused services increase complexity and may expose ports or consume resources.
Read solution →Incorrect system time can cause authentication, certificate and application problems.
Read solution →Servers and network equipment can reboot or shut down when power drops or UPS capacity is insufficient.
Read solution →Backups are only useful if the team knows what to do when the main server fails.
Read solution →Support becomes faster when hardware, IPs, roles and software versions are documented.
Read solution →Adding memory is simple only when compatibility and workload requirements are understood.
Read solution →RAID can improve availability, but it is not a substitute for backup.
Read solution →Department folders often grow without a clear permission model.
Read solution →A shared RDP server needs capacity planning for CPU, RAM, storage and user sessions.
Read solution →When most VPN users work but one user fails, the problem is often local credentials, client configuration, network filtering or an outdated profile.
Read solution →A firewall becomes difficult to maintain when rules are added without naming and documenting their purpose.
Read solution →Port forwarding exposes a service from the internet to an internal host.
Read solution →Some devices stay on 2.4 GHz because of client compatibility, channel selection, signal strength or security settings.
Read solution →Large halls can suffer from weak coverage, interference and too many clients on one AP.
Read solution →A single SSID can simplify user experience, but roaming quality depends on proper AP configuration and client behavior.
Read solution →Users often describe every slowdown as “internet slow”, even when the LAN, server or Wi-Fi is the real bottleneck.
Read solution →A leased line should be evaluated with a controlled test and awareness of overhead, traffic load and routing.
Read solution →Loose connectors, poor termination and damaged cables can create random network failures.
Read solution →A dead port may be disabled, damaged, misconfigured or affected by a bad cable/device.
Read solution →Flat networks can become difficult to secure when every device shares the same broadcast domain.
Read solution →Guest devices should not normally have direct access to internal servers, NAS or management interfaces.
Read solution →Two offices may need access to selected servers or shared resources without exposing those services publicly.
Read solution →When a service works by IP but not hostname, DNS resolution is a prime suspect.
Read solution →A clean IP plan makes troubleshooting and firewall rules much easier.
Read solution →VPN errors become easier to diagnose when you correlate client time, authentication events and firewall logs.
Read solution →Accounting software on a remote server needs predictable performance, secure access and reliable backup.
Read solution →Moving Busy to a hosted environment affects licensing, data paths, printers and user workflows.
Read solution →Branch users may need access to the same accounting environment without exposing the application server unnecessarily.
Read solution →Slow RDP sessions can come from network latency, storage pressure, excessive visual effects or heavy applications.
Read solution →A redirected printer may fail because of driver compatibility, policy settings or the client/server print subsystem.
Read solution →Copy and paste can be blocked by policy, the RDP client or a stuck clipboard process.
Read solution →A business with around 1 TB of important data needs more than a simple file copy.
Read solution →The right choice depends on control, connectivity, application requirements, maintenance and recovery needs.
Read solution →RDP environments work better when users understand what they can install, where they should save data and how to report issues.
Read solution →Accounting data is business-critical and should be backed up before migrations, upgrades and major configuration changes.
Read solution →Not every accounting user needs access to every company or function.
Read solution →Adding users can push a server beyond its practical capacity.
Read solution →Blocking clipboard and drive mapping without an alternative can create unsafe workarounds.
Read solution →Cloud or hosted servers need visibility just like physical servers.
Read solution →A CCTV system may record correctly on-site but fail for mobile or remote viewing.
Read solution →Storage depends on camera count, resolution, frame rate, codec and motion activity.
Read solution →One camera offline can be caused by power, PoE, cabling, IP conflict or configuration.
Read solution →A camera can display live video while recording has stopped because of disk, schedule or storage configuration problems.
Read solution →Changing the ISP router can alter gateway, DHCP, port forwarding or remote-access behavior.
Read solution →Attendance devices may fail to sync because of IP settings, time mismatch, service status or software configuration.
Read solution →Incorrect device time can create payroll and attendance discrepancies.
Read solution →Access-control controllers are infrastructure devices and can benefit from network separation.
Read solution →A recorder without backup power can stop recording during short outages and may suffer unsafe shutdowns.
Read solution →A large CCTV deployment can create traffic and security concerns when cameras share the same flat network as office devices.
Read solution →A system that black-screens or restarts during rendering may have a power, temperature, driver, memory or GPU stability issue.
Read solution →GPU rendering stresses graphics drivers, power delivery and thermals more than ordinary desktop use.
Read solution →PSU sizing should consider actual CPU/GPU draw, transient behavior, drives, fans and PSU quality.
Read solution →Legal-size jobs can fail when the printer tray, driver or application paper size does not match.
Read solution →A stuck job can block every later print request.
Read solution →A Windows update can expose driver compatibility problems or replace a vendor driver.
Read solution →A printer whose IP changes can disappear from user computers.
Read solution →Slow computers are not always short of RAM; storage latency, CPU age and software load also matter.
Read solution →Dust, blocked airflow and dried thermal material can raise temperatures and cause throttling.
Read solution →UPS alarms can indicate overload, low battery, mains problems or a fault.
Read solution →RAID protects availability against some disk failures but does not protect against deletion, ransomware or many logical failures.
Read solution →NAS shares are easier to manage when permissions are group-based and departments are separated.
Read solution →A backup failure can come from storage, credentials, network connectivity, locked files or insufficient space.
Read solution →A green backup status does not prove the business can recover.
Read solution →No single control prevents every ransomware event, but layered access, segmentation and recoverable backups reduce impact.
Read solution →A local backup can be lost with the primary site through theft, fire or other physical events.
Read solution →Keeping only the latest backup can make it impossible to recover from a problem discovered late.
Read solution →Moving shares can break permissions, paths and applications if the migration is treated as a simple copy.
Read solution →NAS capacity disappears faster when snapshots, backups, CCTV or large media files are added without planning.
Read solution →A server image alone may not provide the recovery flexibility needed for business databases.
Read solution →HTTPS issues on IIS commonly come from certificate binding, certificate chain, DNS or port 443 problems.
Read solution →A certificate can be installed correctly while the site remains unreachable because the network path to 443 is blocked.
Read solution →PHP applications on IIS need a working FastCGI handler and a PHP build compatible with the server.
Read solution →A generic 500 response hides the actual PHP or IIS error.
Read solution →SMTP failures often come from incorrect host, port, TLS mode, DNS, credentials or certificate negotiation.
Read solution →Domain email delivery depends on correct DNS records and consistent authentication settings.
Read solution →A form may appear to send successfully and then repeat or show a confusing message after refresh.
Read solution →Public forms are an entry point for malicious input if the server trusts browser data.
Read solution →Generic titles make it harder for users and search engines to understand the page topic.
Read solution →Images are more accessible and easier for search engines to understand when their purpose is described accurately.
Read solution →A useful AMC is more than fixing a computer after it fails.
Read solution →Servers can develop issues gradually, so monthly checks help catch capacity and hardware problems early.
Read solution →Remote troubleshooting becomes faster when the technician gets the exact error, time, affected users and recent changes.
Read solution →A consistent incident format helps teams track recurring problems and prove what was done.
Read solution →Many IT failures begin with simple issues such as low disk space, loose cables, failed backups or overheating.
Read solution →Without an asset list, warranty, replacement and troubleshooting decisions become slower.
Read solution →Server reliability depends on the room as well as the server hardware.
Read solution →A support contract works better when covered systems, hours, response expectations and exclusions are written down.
Read solution →Too many alerts lead to alert fatigue and missed incidents.
Read solution →Multiple simultaneous changes make it difficult to know what fixed or caused a problem.
Read solution →These guides are for practical information. For a live server, network, cloud, CCTV or website issue, share the error and your environment with our IT team.
Talk to an Expert →