Windows Laptop Security Hardening
Budget: ₹1,500 – ₹12,500 INR
We are a small India-based firm issuing company-owned Windows laptops to a team of 3 users (2 developers, 1 research). We require a one-time professional security hardening and device-management setup, executed remotely, with clear documentation so we can operate and maintain the setup independently afterward.
The goal is practical prevention and auditability of data loss, not theoretical or enterprise-overkill security.
1️⃣ Identity & Access Control
Configure company-managed user identities (Microsoft Entra ID / Azure AD or equivalent).
Enforce:
Multi-Factor Authentication (MFA)
Strong password policies
Account lockout and session controls
Ensure only compliant, managed devices can access company email, files, and repositories.
Prevent adding personal email or cloud accounts to company devices or browsers.
2️⃣ Device Management (MDM)
Enrol all 3 Windows laptops into a central device-management platform (preferably Microsoft Intune or equivalent).
Enforce:
Full disk encryption (BitLocker)
Screen lock and inactivity timeout
OS and security updates
Baseline security configuration policies
Enable remote lock and remote wipe for lost or off-boarded devices.
3️⃣ Endpoint Security
Deploy and configure enterprise-grade endpoint protection (Defender for Business / Defender for Endpoint / equivalent).
Enable:
Real-time malware and ransomware protection
Automatic definition updates
Scheduled full-disk scans
Validate protection via standard tests (e.g., EICAR).
4️⃣ Application & Web Usage Control (CRITICAL)
Implement real-world data exfiltration controls, including:
Web content filtering to block categories such as:
Web-based messaging
Personal cloud storage
Online note-taking platforms
Explicitly block access to:
WhatsApp Web
Telegram Web
Evernote
Notion
Personal Google Drive / Dropbox / similar platforms
Enforce browser-level policies to:
Prevent file uploads/downloads to unauthorised web applications
Prevent login to personal accounts on managed browsers
Restrict installation of unauthorised browser extensions
5️⃣ Data Loss Prevention (DLP)
Configure policies to:
Block unauthorised USB storage and file copy
Monitor and restrict email exfiltration of sensitive data
Control unauthorised cloud-sync activity
Ensure:
Business workflows remain functional
All blocked or flagged actions are logged centrally
6️⃣ Developer Workflow Controls
Since two users are developers, the setup must not break legitimate development work.
Define a secure approach for admin privileges (temporary elevation or controlled admin accounts).
Ensure:
Source code resides only in company-owned repositories
No secrets or credentials are stored in plaintext files
Development tools (Git, VS Code, Python, Docker, etc.) function without bypassing security controls
7️⃣ Monitoring, Logging & Visibility
Provide central visibility into:
Device health and compliance
Security alerts
Policy violations (USB, web, DLP)
Ensure logs and dashboards are accessible to the business owner without specialist tooling.
Clearly document what actions are blocked vs logged.
8️⃣ Documentation & Handover (Mandatory)
Provide clear, usable documentation (PDF or Markdown):
Employee Security Rulebook (2–4 pages)
Allowed vs prohibited actions
Data classification (Public / Internal / Confidential)
Device, email, cloud, USB and browser usage rules
Monitoring and privacy notice
Exit expectations
Admin Runbook
How to add/remove users
How to onboard new devices
How to wipe or lock a device
Where to view alerts and logs
How to roll back policies safely if required
Exit / Offboarding Checklist
Account disabling
Device wipe
Access and token revocation
Required Experience
You must have hands-on experience with:
Microsoft Intune / Endpoint Manager
Microsoft Entra ID (Azure AD)
Windows endpoint hardening
Data-loss-prevention controls in small business environments
Nice to have:
Defender for Business / Defender for Endpoint
Practical familiarity with Indian IT Act / DPDP Act expectations
ISO 27001 awareness (practical, not certification-only)
Do not apply if you only install antivirus or lack real MDM/DLP experience.
Acceptance Criteria
All three laptops report healthy and compliant in the management console.
Malware test file is blocked instantly.
USB copy attempt is blocked and logged.
Access to WhatsApp Web / Telegram Web / Evernote is blocked.
Documentation delivered and walkthrough completed.
The goal is practical prevention and auditability of data loss, not theoretical or enterprise-overkill security.
1️⃣ Identity & Access Control
Configure company-managed user identities (Microsoft Entra ID / Azure AD or equivalent).
Enforce:
Multi-Factor Authentication (MFA)
Strong password policies
Account lockout and session controls
Ensure only compliant, managed devices can access company email, files, and repositories.
Prevent adding personal email or cloud accounts to company devices or browsers.
2️⃣ Device Management (MDM)
Enrol all 3 Windows laptops into a central device-management platform (preferably Microsoft Intune or equivalent).
Enforce:
Full disk encryption (BitLocker)
Screen lock and inactivity timeout
OS and security updates
Baseline security configuration policies
Enable remote lock and remote wipe for lost or off-boarded devices.
3️⃣ Endpoint Security
Deploy and configure enterprise-grade endpoint protection (Defender for Business / Defender for Endpoint / equivalent).
Enable:
Real-time malware and ransomware protection
Automatic definition updates
Scheduled full-disk scans
Validate protection via standard tests (e.g., EICAR).
4️⃣ Application & Web Usage Control (CRITICAL)
Implement real-world data exfiltration controls, including:
Web content filtering to block categories such as:
Web-based messaging
Personal cloud storage
Online note-taking platforms
Explicitly block access to:
WhatsApp Web
Telegram Web
Evernote
Notion
Personal Google Drive / Dropbox / similar platforms
Enforce browser-level policies to:
Prevent file uploads/downloads to unauthorised web applications
Prevent login to personal accounts on managed browsers
Restrict installation of unauthorised browser extensions
5️⃣ Data Loss Prevention (DLP)
Configure policies to:
Block unauthorised USB storage and file copy
Monitor and restrict email exfiltration of sensitive data
Control unauthorised cloud-sync activity
Ensure:
Business workflows remain functional
All blocked or flagged actions are logged centrally
6️⃣ Developer Workflow Controls
Since two users are developers, the setup must not break legitimate development work.
Define a secure approach for admin privileges (temporary elevation or controlled admin accounts).
Ensure:
Source code resides only in company-owned repositories
No secrets or credentials are stored in plaintext files
Development tools (Git, VS Code, Python, Docker, etc.) function without bypassing security controls
7️⃣ Monitoring, Logging & Visibility
Provide central visibility into:
Device health and compliance
Security alerts
Policy violations (USB, web, DLP)
Ensure logs and dashboards are accessible to the business owner without specialist tooling.
Clearly document what actions are blocked vs logged.
8️⃣ Documentation & Handover (Mandatory)
Provide clear, usable documentation (PDF or Markdown):
Employee Security Rulebook (2–4 pages)
Allowed vs prohibited actions
Data classification (Public / Internal / Confidential)
Device, email, cloud, USB and browser usage rules
Monitoring and privacy notice
Exit expectations
Admin Runbook
How to add/remove users
How to onboard new devices
How to wipe or lock a device
Where to view alerts and logs
How to roll back policies safely if required
Exit / Offboarding Checklist
Account disabling
Device wipe
Access and token revocation
Required Experience
You must have hands-on experience with:
Microsoft Intune / Endpoint Manager
Microsoft Entra ID (Azure AD)
Windows endpoint hardening
Data-loss-prevention controls in small business environments
Nice to have:
Defender for Business / Defender for Endpoint
Practical familiarity with Indian IT Act / DPDP Act expectations
ISO 27001 awareness (practical, not certification-only)
Do not apply if you only install antivirus or lack real MDM/DLP experience.
Acceptance Criteria
All three laptops report healthy and compliant in the management console.
Malware test file is blocked instantly.
USB copy attempt is blocked and logged.
Access to WhatsApp Web / Telegram Web / Evernote is blocked.
Documentation delivered and walkthrough completed.