starman2heven The fundamental problem here is that the Windows Extended Protection feature makes changes to both servers to server and client to server communication. Technically, if you could make 100% sure that the traffic between clients and servers is going to be isolated, you could enable EP little by little. But because there are various reasons why both clients and servers might need to talk to server a client request, this is the approach that is even more complex (and we did not validate it). This is why we tried to make sure to get the script to check as many prerequisites as possible so EP can be turned on at one time, and if things do not go well, rollback should be pretty painless too.