Build a small, measurable baseline
Hardening should leave the computer usable and recoverable. Start by noting the Windows version, current security provider and applications the device must run. On a work PC, use the administrator's policy rather than overriding settings that may be centrally managed.
Check the main protections
- Open Settings, Windows Update. Install applicable updates and finish required restarts. Check the About page to identify the Windows edition and version.
- Open Windows Security. Review Virus & threat protection, Firewall & network protection and the available device-security pages. Investigate warnings before dismissing them.
- Confirm that the antivirus provider is expected. Microsoft Defender Antivirus may be passive or inactive when another product is protecting the device; two active real-time products are not automatically better.
- Check encryption status and where the recovery key is kept. Do not change TPM or firmware settings before understanding their effect on recovery.
Reduce unnecessary access
Use a standard account for ordinary work and a separate administrator account when practical. Review installed applications and browser extensions. Remove tools you do not need using their supported uninstall process. Keep Remote Desktop and other remote-management services disabled unless there is a legitimate requirement and a secure access design.
Set a screen lock and use Windows Hello where supported. Review your Microsoft account's security and MFA separately: a local device PIN and online account recovery are different controls.
Check a recovery path
Run the existing backup process, then restore a harmless sample file to a different folder. Record where recovery information lives without publishing passwords or keys. A business computer should also have a known route for contacting IT if a change breaks access.
Verify the baseline
After a restart, revisit Windows Security and Windows Update. Confirm normal applications, printers and required network connections work. Record each control as enabled, unavailable, managed or needing follow-up. This is more useful than marking everything secure because one scan completed.
Common mistakes
Turning off the firewall to fix one application hides the actual rule problem. Adding broad antivirus exclusions weakens protection. Using unsupported hardware workarounds does not make an unsupported installation equivalent to a supported device. Edition-dependent controls should be documented honestly rather than treated as missing free features.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.