### `author` Alex Mwaura # Windows server gap analysis Requirements - fundamentals Security concepts ## Key take aways - Apply security principles to secure enterprise infrustructure - Perform risk analysis - Understand security controls in windows baseline ## Step 1: Locate your windows version using the search tool, in the toolkit for example ![Screenshot 2024-05-10 at 11.07.09](https://hackmd.io/_uploads/ry4QU8sGR.png) ![Screenshot 2024-05-10 at 11.07.38](https://hackmd.io/_uploads/S1uNULoMA.png) note down your windows version, for example `Microsoft Windows Version 22H2` ## step 2 Go to your browser and locate where the compliance toolkit is hosted and Download it. For example; search `microsoft compliance toolkit`, or [here](https://www.microsoft.com/en-us/download/details.aspx?id=55319) ![Screenshot 2024-05-10 at 13.02.53](https://hackmd.io/_uploads/HkWgb_izR.png) ## step 3 Extract the files. - Locate the policyanalyzer.exe and launch ![Screenshot 2024-05-10 at 12.38.06](https://hackmd.io/_uploads/HJqIiPiGC.png) ![Screenshot 2024-05-10 at 12.38.37](https://hackmd.io/_uploads/HyvDsDofC.png) ![Screenshot 2024-05-10 at 12.38.59](https://hackmd.io/_uploads/S1iuoDoz0.png) ## step 4 Choose the baseline policy rule. - pick the folder containing the policyanalyzer policy rules files ![Screenshot 2024-05-10 at 12.02.31](https://hackmd.io/_uploads/ByAzrDiGC.png) Choose `Documentation` as the folder to open ![Screenshot 2024-05-10 at 12.03.15](https://hackmd.io/_uploads/BkcLBwif0.png) You should see something like this in your policyanalyzer tool ![Screenshot 2024-05-10 at 12.10.09](https://hackmd.io/_uploads/ByqYHvoG0.png) - Select, then choose view/compare, this will tell you of your current security policy [**Click yes if promted**] ![Screenshot 2024-05-10 at 12.04.22](https://hackmd.io/_uploads/B1XUdwiGC.png) - Select, then choose gap analysis i.e Compare \ Effective State [**Click yes if promted**] **yellow means, there is a difference between the baseline and effective state.** ![Screenshot 2024-05-10 at 12.28.01](https://hackmd.io/_uploads/rk92uvoGA.png) Congratulations, you are done.