Put some endpoint MFA on the servers? Use a PIM tool like CyberArk? Restrict the IP ranges that can connect? Use FSLogix to hide the consoles from everyone except members of a certain group? Use AppLocker to restrict execution to certain groups?
e
Eamonn Tully
03/29/2023, 2:35 PM
All good ideas, thank you! There will be IP restrictions in place but I'll look into all the other options as extras!