Web browsers don't process Java or web advertisements. Microsoft Office, web browsers and PDF readers run in environments with security configurations applied.
User application hardening
Turning off features in web browsers and Office that attackers commonly abuse.
The case for it
What you lose without user application hardening.
Flash is gone. Office still embeds objects from other programs, browsers still run add-ons nobody asked for, and PDF readers still launch things they should not. Hardening removes the features attackers use and leaves the ones your staff need.
Where you need to be
What each maturity level asks of user application hardening.
The Australian Cyber Security Centre (ACSC) sets a requirement for this control at each maturity level, ML1 through ML3. Your overall Essential Eight score is your weakest control rather than an average, so a gap here pulls the whole score down.
Web browsers and Office have hardened configurations via policy. PowerShell's Constrained Language Mode is enforced. Unrequired .NET Framework versions are removed.
PowerShell module logging, script block logging, and transcription are enabled and forwarded to centralised logging. Hardened configurations are validated annually.
Not sure which level you should aim for?
Three questions about your regulatory position and the data you keep will point you at the right target.
Take the maturity pickerThe rollout
Setting up user application hardening in your environment.
Browsers, Office and PDF readers get Microsoft and ACSC security baselines applied through Intune configuration profiles. Java is blocked in the browser and unneeded .NET versions are removed. PowerShell runs in Constrained Language Mode for anyone who is not an administrator, with its logging forwarded centrally. All of it arrives as policy, so nothing depends on someone remembering to re-apply it.
Free self-assessment
No email required.
Score yourself on all eight controls.
Eight questions, your estimated Essential Eight maturity level, and a branded PDF report you can share with your board, insurer, broker or auditor. Runs entirely in your browser. Nothing is sent to us unless you choose to book a call.
Take the self-assessmentAsked on client calls
Questions we get about user application hardening.
- We still need Java for one internal app. What then?
- That app gets a scoped exception. Java is enabled for that one application through a per-app Intune profile, rather than switched back on across the browser. Staff who don't need Java don't have it.
- Does this affect how Chrome or Edge feel for users?
- Not measurably. Hardening removes rarely-used or deprecated features (Flash, Java applets, unusual file handlers) and enforces protective defaults. Day-to-day browsing, Microsoft 365 in the browser, Teams, all work as normal.
- What's PowerShell Constrained Language Mode?
- It's a Windows feature that limits what PowerShell can do when someone who is not an administrator runs it. Attackers like PowerShell because it is a full scripting environment on every Windows machine. Constrained Language Mode narrows that down without stopping your administrators doing their job.
Where to go next
Essential Eight controls that work with user application hardening.
Control 03
Configure Microsoft Office macro settings
Stopping the little automation scripts inside Word and Excel from running unless they're from a trusted source.
Read the controlControl 01
Application control
Only letting approved programs run on your computers. Everything else is blocked by default.
Read the controlControl 02
Patch applications
Keeping your software up to date so it has the latest security fixes.
Read the controlThe maturity level summaries on this page are a plain-English version of the ACSC's published Essential Eight Maturity Model. For the full text, see the ACSC Essential Eight Maturity Model .
The qualifier
Let's see if we're a fit.
Seven questions, one moment of your time. We'd rather tell you now than three months in.