Windows Server
Active Directory Part 3 — GPO Hardening for the Whole Domain
The GPOs every domain should have — password policy, account lockout, audit, RDP restrictions, SMBv1 / LLMNR / NTLMv1 kill, BitLocker enforcement. The defaults are not enough.