Hardening Guidelines for Workgroup Managed Sites

Hardening Guidelines for Workgroup Managed Sites

To help prevent potential NTLM relay and Pass-the-Hash vulnerabilities, consider the following security best practices when setting up Barracuda RMM in a workgroup environment, from most secure to least secure:

  1. Use a Device Manager on each machine within the environment so that a local service account is used to authenticate to each device (agent-based configuration).

  2. If an Onsite Manager is to be used within the workgroup, ensure that each machine managed by the Onsite Manager uses a unique local Administrator password (do not re-use the same password for every machine).

In addition, we recommend enforcing SMB signing on all machines.