Skip to content
Menu

Essential Eight user application hardening

Switch off the features attackers use in everyday apps.

User application hardening switches off risky features in web browsers, Office and PDF software, and stops staff changing those settings back.

A desk monitor showing a web browser with a document open, beside a keyboard and a stack of printed pages.

At a glance

Control
04 of 08 · Prevent attacks
Stops
Browser and document-based attacks
Typical tools
Intune, Microsoft Defender attack surface reduction rules
Effort
Medium

What is user application hardening?

Where it stops an attack.

  1. The attack A malicious web ad or document tries to launch another program or inject code.
  2. Stopped here Browsers block web ads and Java, and Office and PDF software can’t start other programs.
  3. The result The page or file has nothing to work with.

Application hardening maturity levels

What changes at each level.

ML1 Maturity Level 1. ML2 Maturity Level 2. ML3 Maturity Level 3.
Web browsers No Java or web ads from the internetAdds ASD and vendor hardening guidance No change
Microsoft Office Not required Can’t start programs, create executables, inject code or run OLE packages. Hardened to guidance No change
PDF software Not required Can’t start programs. Hardened to guidance No change
Settings users can’t change Browser security settingsAdds Office and PDF settings No change
Legacy components Internet Explorer 11 off No change Adds .NET Framework 3.5 and PowerShell 2.0 off
PowerShell Not required Not required Constrained Language Mode
Logging Not required PowerShell and command-line events logged centrally. Internet-facing server logs analysedAdds analysis of workstation and internal server logs

Each level includes everything in the one before. A plain-English summary, not the requirement text. ASD Essential Eight Maturity Model (November 2023)

How to harden browsers, Office and PDF software

Protection first, disruption last.

  1. 01

    Baseline your browsers

    One or two approved browsers, managed centrally, with ads and legacy plugins blocked.
  2. 02

    Turn on attack surface reduction rules

    Microsoft Defender rules stop Office and PDF apps launching other programs. Audit first, then block.
  3. 03

    Remove legacy components

    Internet Explorer 11, PowerShell 2.0 and old .NET Framework versions come out.
  4. 04

    Lock and log

    Settings enforced by policy, with PowerShell and process events sent to a central log.
  • Unmanaged browsers

    A browser staff installed themselves ignores every setting.

  • Untested ASR rules

    Some rules affect add-ins and line-of-business tools. Audit mode first.

  • Forgetting PDF software

    Office locked down, an old PDF reader left wide open.

Application hardening questions

What clients ask before we start.

What are attack surface reduction (ASR) rules?
Do we still need to remove Internet Explorer?
Will hardening affect our line-of-business software?

Find out where you stand on user application hardening.

Book a free 45-minute Essential Eight review with a Perth engineer. You get your maturity on all eight controls and what to fix first. The report is yours to keep.

Or call (08) 9467 2269

What’s bugging you
Staff

A Perth engineer, not a salesperson, replies within one business day.

We hold ISO/IEC 27001:2022 certification from BSI, certificate IS 840964.