These hardening guidelines apply to the EcoStruxure Building Commission mobile application.
On all devices running Microsoft Windows where Commission mobile application is installed:
Ensure that exploit protection mitigation is enabled on the computer.
Ensure that Export Address Filtering (EAF) is enabled for SE.EBC.exe.
If supported, ensure to validate access for modules that are commonly abused by exploits.
For more information, see Microsoft Learn – Exploit protection
In addition:
Review and align additional exploit protection mitigations with your internal endpoint hardening standards.
Test the setting in a representative environment before broad deployment, especially if additional exploit protection rules are enabled.
Document the applied configuration as part of the site hardening baseline and change management process.