All insights

What is user application hardening?

5 min readBy Brendon Whiting, Founder · 2 March 2026

User application hardening means switching off the features in everyday software that attackers most often exploit: web browser add-ons and legacy plugins, scripting inside PDF readers, and unnecessary functionality in Office applications. It is one of the Essential Eight controls, it is mostly configuration rather than purchasing, and it is the control most commonly left undone.

The reason it gets skipped is that it has no product to buy and nothing visible to show for it. Nobody notices hardened software, there is no dashboard that turns green, and it never becomes urgent. Meanwhile the attack it prevents is entirely ordinary: a staff member opens a document or visits a page, a feature buried in the software does exactly what it was designed to do, and code runs that nobody intended. Hardening closes those doors in advance, and the doors were never load-bearing.

Start with the browser, because that is where most of the working day happens. Hardening here means removing or restricting extensions, since browser add-ons request sweeping permissions and are a well-worn route into a business; disabling legacy technologies that modern sites no longer need; and controlling what web content is allowed to execute. Most staff will never notice any of it, because the features being removed have not been genuinely useful for years.

PDF readers come next, and they surprise people. A PDF is not just a page: the format supports scripting and embedded content, which is precisely why malicious PDFs remain a durable delivery method. Hardening means disabling that scripting and locking the setting so it cannot be re-enabled by a user, or by malware pretending to be one. This is exactly what the Essential Eight expects, and it is a two-minute change per machine that almost nobody makes.

Office applications are the third area, and they overlap with the separate macro control. Beyond macros, hardening restricts the features that let documents reach out to other content or run code, and disables the legacy formats and integrations that persist for backwards compatibility rather than because anyone uses them. If your business genuinely needs one of these, the answer is a documented exception for the specific case rather than leaving it open everywhere.

The way this fails in practice is not disagreement but drift. A business hardens its machines during a project, and then a new laptop arrives unhardened, a browser update resets a setting, someone reinstalls a reader with defaults restored, and eighteen months later the configuration exists in a document and nowhere else. This is why hardening must be applied centrally through device management, Intune in a Microsoft environment, rather than by hand. The tool does not just set the configuration, it re-asserts it, which is what turns hardening from an event into a state.

Two things make the effort worth writing down. It is free in licensing terms, since you already own the software, so the cost is the time to decide and deploy. And it generates evidence: an exported policy showing the settings enforced across the fleet is exactly what an Essential Eight assessment, an insurer or a tender panel will ask to see, and it is far easier to produce from a management tool than to reconstruct from memory later.

Verifying it is applied is a separate job from applying it, and the two get conflated. A policy that exists in your management console is not the same as a setting enforced on the laptop in someone's bag that has not checked in for a month. Ask for a compliance report showing the settings actually in force per device, not the policy as configured, because the gap between those two views is where hardening quietly stops being true.

The honest caveats. Hardening will occasionally break something, most often an old internal web application relying on a legacy feature, and the answer is to find those in a pilot rather than in production. It protects against a specific class of attack and does nothing about stolen passwords or unpatched systems, so it belongs alongside the other controls rather than instead of them. And it needs revisiting as software changes, because vendors add features and reset defaults on their own schedule, not yours.

If your machines have never been hardened, this is the cheapest meaningful security work available to you, and the Cyber Security Scorecard will tell you where you stand on it, free. Otherwise call 1800 456 567 and we will apply it across the fleet and keep it applied.

Close the settings nobody checks

Hardening is configuration work that pays for itself and never gets done. We apply it across the fleet and keep it applied as software changes.

Frequently asked questions

Occasionally, which is why it is applied in stages and tested rather than switched on wholesale. The common friction points are an old internal web tool that relies on a legacy browser feature, or a PDF workflow using scripting. Both are findable in advance, and both are usually signals that the tool itself is overdue for replacement.

No. Patching fixes flaws the vendor has found and repaired; hardening switches off features that work exactly as designed but are dangerous in a business setting. A fully patched browser with every risky feature still enabled is not hardened, which is why the Essential Eight lists them as separate controls rather than folding one into the other.

Whoever manages your devices, and it should be applied centrally rather than machine by machine. Doing it manually on fifteen laptops guarantees drift, because the next laptop will not match. Tools like Intune push the settings and, more importantly, keep pushing them, which is what stops the configuration decaying over the following year.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.