“Ransomware Threat Actors are very good at the basics, and this shows against companies that aren’t.”
- SANS DFIR Aug 2023
Ethical Threat Insight: Windows Misconfigs That Shouldn’t Exist in 2026
I still find these in well-managed environments, and yes, attackers know it.
I’ve spent countless hours pentesting Windows and Active Directory environments, and these are some of the biggest and most recurring issues I see.
Weak Local Admin Control – Shared local admin passwords and no LAPS? That’s pretty much guaranteed lateral movement for threat actors. But that’s not all…
Insecurely Installed/Configured Software - Where software gets installed at the root of C:\ which then gives that folder insecure permissions, for example.
Lack of Patching 3rd Party Software - Like when you have Adobe, Java, and a bunch of other non-Microsoft software on your endpoints, but you don’t patch them regularly.
Weak Endpoint Security - Having EDR is great, but it’s not the saving grace we all hoped it would be. Sharp IT teams know about this…
Insecure services & Tasks - This is where software gets installed, sets up a scheduled task or a service but does so insecurely. Like giving everyone the ability to modify the service binary of the script that’s running from the scheduled task.
Unrestricted PowerShell – Constrained Language Mode and Application Control are very strong defenses against ransomware gangs. But audit mode is not enough…
MFA on RDP but PSRemoting Not Restricted - I know this is a bit of a curveball, but I see this often. By default on Windows Server PSRemoting is enabled and IT admins who are not aware may miss restricting this.
Now that you know what these common Windows misconfigs are you, the task becomes identifying them in your environment.
Which is actually quite easy, once you know what to look for.
I did a webinar last year where I walked through these seven misconfigs, showed real-world attack paths they enable, and gave practical fixes you can roll out immediately.
If you’re an IT admin or work with Windows in any way, I’d definitely check it out.
All the best
Spencer
PS - These are not issues that your typical vulnerability scanners will find. You’ve got to hunt for them yourself.
