Week 13 · lesson
Lesson 4: Secure Endpoint Configuration Lab
Core path: 42 minutes
You are reviewing a fictional staff laptop, mobile device, and wireless-access requirement before deployment.
Nothing in this lab changes a real account, endpoint, or network.
Workstation baseline
Daily user: local administrator
Guest account: enabled
Screen lock: never
BIOS/UEFI password: not configured
AutoRun: enabled
Several unused services: enabled
BitLocker: disabled
Defender AV: enabled/current
Firewall: enabled
MFA: enabled for cloud identity
Mobile baseline
Ownership: corporate
Device encryption: enabled
Screen lock: simple swipe
OS/apps: updates pending
MDM profile: missing
Remote backup: disabled
Locator/remote wipe: unavailable until management enrollment
Failed-login restriction: not configured
Wireless requirement
Staff network: WPA3-capable infrastructure
Central user authentication required
Guest network: separated from staff resources
One legacy endpoint supports only old/weak wireless settings
Station A: account privilege
Permanent daily administrator access is broader than normal work requires.
Propose a standard-user baseline and an approved elevation/support process.
Station B: session protection
Add an appropriate screen-lock/timeout rule. Explain why a strong password does not protect an already unlocked session.
Station C: workstation hardening
Review:
- BIOS/UEFI password need;
- AutoRun;
- unused services;
- guest account;
- failed-login lockout;
- account expiration/login-time concepts where policy applies;
- password-manager use;
- encryption/recovery planning.
Do not enable BitLocker without defining recovery-key handling.
Station D: Windows protection
Verify:
- Defender AV state/definitions;
- firewall state;
- whether a specific application needs a rule;
- UAC/elevation behavior;
- share/NTFS permission boundary for a supplied folder scenario.
Station E: mobile hardening
Create a target state covering:
- strong screen lock;
- encryption;
- OS/application patching;
- MDM/configuration profile;
- content/endpoint protection where required;
- remote backup;
- locator/remote wipe;
- failed-login restriction.
Station F: wireless authentication
Design the staff network using modern WPA2/WPA3 protection with AES-based security and centralized authentication where required.
Explain where RADIUS, Kerberos, MFA, or TACACS+ fit conceptually and where they do not substitute for wireless encryption.
Station G: legacy wireless device
The legacy endpoint cannot support the required modern security configuration.
Do not weaken the entire staff network for one old client. Document replacement, isolation, or an explicitly approved compatibility exception.
Station H: physical control
The laptop is used in a shared office and stored overnight.
Select two physical controls such as:
- equipment lock;
- controlled room/door access;
- badge reader;
- surveillance;
- locked storage.
Explain the risk each addresses.
Lab deliverable
For every station record:
asset/risk:
current state:
selected control:
objective boundary:
tradeoff:
recovery/management dependency:
verification:
Success criteria
A passing design reduces unnecessary privilege/exposure without destroying usability, recoverability, or organizational management.
Read it. Prove it.