| 01 | Application control | Only software you've approved can run, so a downloaded file can't quietly install malware. | Windows Defender Application Control (WDAC), Intune, Defender for Endpoint |
| 02 | Patch applications | The apps your team uses get security updates fast, before attackers exploit the holes everyone knows about. | Defender Vulnerability Management, Intune, Windows Autopatch |
| 03 | Office macros | A booby-trapped Word or Excel file can't run hidden code — one of the most common ways businesses get hit. | Intune Cloud Policy, ASR rules, Defender for Office 365 Safe Attachments |
| 04 | User application hardening | Risky browser and app features are switched off, shutting down the tricks used to sneak code onto a machine. | Intune Security Baselines, Edge policies, ASR rules |
| 05 | Restrict admin privileges | Few people hold the keys to everything, so one compromised account can't take down the whole business. | Entra ID PIM, Conditional Access, Privileged Access Workstations (PAW) |
| 06 | Patch operating systems | Windows itself stays up to date, closing the gaps that ransomware spreads through. | Windows Autopatch, Azure Update Manager, Defender VM |
| 07 | Multi-factor authentication | A second check at sign-in means a stolen password on its own isn't enough to get in. | Entra ID Conditional Access, Authentication Strengths, FIDO2 / Windows Hello for Business |
| 08 | Regular backups | If the worst happens, your business is back up by morning, not next month — with restores that are actually tested. | Purview retention, M365 backup partner (Veeam / AvePoint / Keepit), Azure Backup |