Disable group policy service

broken image
broken image

It changes the default behavior of products and services to make them more resilient to unauthorized changes and compromise. Not a big change, but there may be some negative impact in your specific scenario.ĭisabling the Print Spooler service provides additional an additional layer to defense in depth approaches. Luckily, the vulnerability can be easily thwarted with a simple configuration change on Domain Controllers disabling the Print Spooler service. This is actually already happening in the real world, leading to a ‘zero day’ vulnerability event. Today, the news reached me that CVE-2021-1675 is weaponized to compromise Domain Controllers.