Your trying to plug holes in a sinking ship or Swiss cheese. You can lock Windows down but then you lose functionality and usability.
No. You do not. There are ways to completely lock down Windows without losing one bit of functionality.
Microsoft Security itself will tell you that just because Windows Home and Pro ship with everything enabled, does not mean that they should be left enabled. Windows was designed and intended to have features and functionality that place the system at-risk to be disabled. Windows is a modular operating system. It is not optimized for security "out-of-the-box." It must be properly configured and managed - IF - digital (localhost) is a priority for the user.
The issue with system lock down - ALL default deny actually - is more about the user and what they can emotionally and mentally cope with. A lot of people cannot cope with anything being blocked. Ever. Even when it is malicious.
But most users live a thing called "I do what I want, mommy." So anything that prevents that is not acceptable. Hence we have a world filled with malware and threat actors who target the herd that wants to use stuff.
To be honest unless your a spook, work in the military industrial complex or work with top secret government departments then your wasting your time.
Full system lock down is the only effective insurance against highly effective, easily deployed exploits that you don't see coming. The ones such as Eternal Blue and Double Pulsar.
100% always-on system lock down along with not allowing users to make decisions is the only proven, highly effective speed bump in a post-exploitation environment.
It depends upon your belief system whether protecting against those kinds of scenarios are important.