<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>HardenedHost</title><description>Production-tested sysadmin runbooks, enterprise hardening baselines, multi-tenant MSP automation, and zero-fluff IT post-mortems.</description><link>https://hardenedhost.com/</link><item><title>Post-Mortem: Why BitLocker Network Unlock Broke After a Core Switch Upgrade</title><link>https://hardenedhost.com/blog/bitlocker-network-unlock-core-switch-postmortem/</link><guid isPermaLink="true">https://hardenedhost.com/blog/bitlocker-network-unlock-core-switch-postmortem/</guid><description>A 3 AM outage investigation: how standard 802.1X re-authentication timers and DHCP option delays caused hundred-node server fleets to get stuck at BitLocker PIN prompts during reboots.</description><pubDate>Wed, 07 Oct 2026 00:00:00 GMT</pubDate><author>HardenedHost SecOps</author></item><item><title>Building Proactive PowerShell Daily Health Checks for Multi-Tenant MSPs</title><link>https://hardenedhost.com/blog/building-multi-tenant-powershell-health-checks/</link><guid isPermaLink="true">https://hardenedhost.com/blog/building-multi-tenant-powershell-health-checks/</guid><description>How to automate daily tenant hygiene checks across Exchange Online, Entra ID, and on-premises domain controllers using certificate-based authentication and secure app registrations.</description><pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate><author>HardenedHost SecOps</author></item><item><title>Locking Down Entra ID: 5 High-Impact Conditional Access Policies for Day 1</title><link>https://hardenedhost.com/blog/entra-id-conditional-access-day-one/</link><guid isPermaLink="true">https://hardenedhost.com/blog/entra-id-conditional-access-day-one/</guid><description>A blueprint of essential Conditional Access policies that immediately block legacy authentication, enforce phishing-resistant MFA for admins, and isolate risky sign-ins without locking yourself out.</description><pubDate>Thu, 08 Oct 2026 00:00:00 GMT</pubDate><author>HardenedHost SecOps</author></item><item><title>Battle-Tested Windows Server 2025/2022 Hardening Baseline for MSPs</title><link>https://hardenedhost.com/blog/windows-server-hardening-baseline/</link><guid isPermaLink="true">https://hardenedhost.com/blog/windows-server-hardening-baseline/</guid><description>A production-verified hardening runbook stripping unnecessary attack surfaces, configuring SMB signing, auditing LSASS protections, and locking down NTLM without breaking legacy clients.</description><pubDate>Fri, 09 Oct 2026 00:00:00 GMT</pubDate><author>HardenedHost SecOps</author></item></channel></rss>