This is the script I made
$hardening=@('Set-Service AxInstSV -StartupType Disabled','Set-Service bthserv -StartupType Disabled','Set-Service CDPUserSvc -StartupType Disabled','Set-service PinIndexMaintenanceSvc -StartupType Disabled','Set-service dnmappushservice -StartupType Disabled','Set-Service MapsBroker -StartupType Disabled','Set-Service lfsvc -StartupType Disabled','Set-Service wlindsvc -StartupType Disabled','Set-Service wlindsvc -StartupType Disabled','Set-Service NgcSvc -StartupType Disabled','Set-service NgcCtnrSvc -StartupType Disabled','Set-Service Ncbsesrvice -StartupType Disabled','Set-Service phoneSvc -StartupType Disabled','Set-Service PcaSvc -StartupType Disabled','Set-Service QWAVE -StartupType Disabled','Set-Service RmSvc -StartupType Disabled','Set-Service SensorDataService -StartupType Disabled','Set-Service SensrSvc -StartupType Disabled','Set-Service SensorService -StartupType Disabled','Set-Service ShellHWDetection -StartupType Disabled','Set-Service ScDeviceEnum -StartupType Disabled','Set-Service SSDPSRV -StartupType Disabled','Set-Service WiaRpc -StartupType Disabled','Set-Service SSDPSRV -StartupType Disabled','Set-Service OneSyncSvc -StartupType Disabled','Set-Service TabletInputService -StartupType Disabled','Set-Service upnphost -StartupType Disabled','Set-Service UserDataSvc -StartupType Disabled','Set-Service UnistoreSvc -StartupType Disabled','Set-Service WalletService -StartupType Disabled','Set-Service Audiosry -StartupType Disabled','Set-Service AudioEndpointBuilder -StartupType Disabled','Set-Service FrameServer -StartupType Disabled','Set-Service stisvc -StartupType Disabled','Set-Service wisvc -StartupType Disabled','Set-Service icssvc -StartupType Disabled','Set-Service WpnService -StartupType Disabled','Set-Service WpnUserService -StartupType Disabled','Set-Service PrintNotify -StartupType Disabled','Set-Service Spooler -StartupType Disabled','Set-Service XblGameSave -StartupType Disabled','Get-NetFirewallRule | Where { $_.Enabled -eq "True" -and $_.Direction -eq "inbound" } | Disable-NetFirewallRule','Get-NetFirewallRule | Where {$_.DisplayName -Like "Remote Desktop*" -and $_.Direction -eq "inbound" } | Enable-NetFirewallRule','Get-NetFirewallRule | Where {$_.DisplayName -Like "Ping*" -and $_.Direction -eq "inbound" } | Enable-NetFirewallRule'
14:46