Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear.

Slides:



Advertisements
Similar presentations
Auditing Microsoft Active Directory
Advertisements

Establishing an OU Hierarchy for Managing and Securing Clients Base design on business and IT needs Split hierarchy Separate user and computer OUs Simplifies.
FDCC Implementation Efforts at Idaho National Laboratory Justin Hansen NLIT 2009.
Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear.
Module 5: Creating and Configuring Group Policy
Chapter 13 Securing Windows Server 2008
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Configuring Windows Vista Security Chapter 3. IE7 Pop-up Blocker Pop-up Blocker prevents annoying and sometimes unsafe pop-ups from web sites Can block.
Chapter 7 HARDENING SERVERS.
Hands-On Microsoft Windows Server 2003 Administration Chapter 4 Managing Group Policy.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
10.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 8: Implementing and Managing Printers.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
11 SYSTEMS ADMINISTRATION AND TERMINAL SERVICES Chapter 12.
Group Policy in Microsoft Windows Active Directory.
Module 16: Software Maintenance Using Windows Server Update Services.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
Module 2: Managing User and Computer Accounts
Microsoft ® Official Course Module 9 Configuring Applications.
Chapter 5 Roles and features. objectives Performing management tasks using the Server Manager console Understanding the Windows Server 2008 roles Understanding.
Introduction to Active Directory December 10th, pm Daniels 407.
70-270: MCSE Guide to Microsoft Windows XP Professional Chapter 5: Users, Groups, Profiles, and Policies.
Implementing and Configuring Microsoft ® Windows Server ® 2008 Terminal Services Nicola Ferrini
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
GROUP POLICY An overview of Microsoft Windows Group Policy.
Automated Computer Account Management in Active Directory June 2 nd, 2009 Bill Claycomb Systems Analyst Sandia National Laboratories Sandia is a multiprogram.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
IT:Network:Microsoft Server 2 Chapter 27 WINDOWS SERVER UPDATE SERVICES.
Module 4: Add Client Computers and Devices to the Network.
Hands-On Microsoft Windows Server 2008
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
Section 1: Introducing Group Policy What Is Group Policy? Group Policy Scenarios New Group Policy Features Introduced with Windows Server 2008 and Windows.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
Security Planning and Administrative Delegation Lesson 6.
Managing User Desktops with Group Policy
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
SMS 2003 Deployment and Managing Windows Security Rafal Otto Internet Services Group Department of Information Technology CERN 26 May 2016.
8.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 8: Planning.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
Module 7: Managing the User Environment by Using Group Policy.
Implementing Group Policy. Overview What is Group Policy Introduction to Group Policy Group Policy Structure How Group Policy Settings Are Applied in.
GPO - WINDOWS SERVER AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.
4. Managing the Desktop Thomas Lee Chief Technologist – QA plc.
Remote Administration Remote Desktop Remote Desktop Gateway Remote Assistance Windows Remote Management Service Remote Server Administration Tools.
Section 11: Implementing Software Restriction Policies and AppLocker What Is a Software Restriction Policy? Creating a Software Restriction Policy Using.
NT4 SP4 Security Jack Schmidt - Fermilab
Chapter 8 Configuring and Managing Shared Folder Security.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory, Enhanced Chapter 11: Group Policy for Corporate Policy.
Module 5: Creating and Configuring Group Policies.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
1 Group Policies (Week 11, Monday 3/19/2007) © Abdou Illia, Spring 2007.
Page 1 Printing & Terminal Services Lecture 8 Hassan Shuja 11/16/2004.
Module 7: Implementing Security Using Group Policy.
NetTech Solutions Security and Security Permissions Lesson Nine.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Module 8 Implementing Security Using Group Policy.
LM/NTLMv1 Retirement Hosted by LSP Services.
Federal Desktop Core Configuration FDCC NLIT 2008 May 2008 Stan Hall Cyber Technology Development Technical Project Manager Sandia is a multiprogram laboratory.
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
1.1 Microsoft® Windows® 2003 Server Group Policy Management Prof. Abdul Hameed.
Virtual Directory Services and Directory Synchronization May 13 th, 2008 Bill Claycomb Computer Systems Analyst Infrastructure Computing Systems Department.
Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear.
Unit 27: Network Operating Systems
Utilize Group Policy Terminal Server Settings
Security Planning and Administrative Delegation
Presentation transcript:

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL Federal Desktop Core Configuration and Sandia National Labs Stan Hall Cyber Technology Development NLIT 2009

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL What is the Federal Desktop Core Configuration (FDCC)? (Blah, Blah) The Federal Desktop Core Configuration (FDCC) is an OMB-mandated security configuration. The FDCC currently exists for Microsoft Windows Vista and XP operating system software. While not addressed specifically as the "Federal Desktop Core Configuration," the FDCC was originally called for in a 22 March 2007 memorandum from OMB to all Federal agencies and department heads and a corresponding memorandum from OMB to all Federal agency and department Chief Information Officers (CIO). Directly from:

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL How we (Sandia) started We started with a test organizational Unit (OU) in the internal Active Directory (AD) domain. We placed all the FDCC policies on the OU and put some test systems in to see the effects. The result was a bad experience as much did not work with the systems. We then pulled back setting after setting till we had a system that was functional again and determined what needed to be done for each setting that caused conflicts.

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL Vista Status Vista FDCC policies are currently running at about 93% compliant (not counting requested variances). Variances requested are: Account Policies (age, length, lockout), FIPS 140 Encryption, Remote Desktop, Remote Assist, Smart Card removal behavior, Terminal Server session timeout and Wireless configuration wizard’s, Administrative Rights, sharing of files and printers, Root certificate updates and screen saver

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL Next Steps Our Vista deployment was delayed so we needed to start looking at XP. We started with the base settings from the Vista configuration and tested them in a controlled rollout. As conflicts were identified we made a note and requested a variance.

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL XP Status XP FDCC policies are currently running at about 80% compliant (not counting requested variances). Variances requested are: Account Policies (age, length, lockout), FIPS 140 Encryption, Remote Desktop, Remote Assist, Smart Card removal behavior, Terminal Server session timeout and Wireless configuration wizard’s, Administrative Rights, sharing of files and printers, Root certificate updates and screen saver

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL Variances in Detail Account Policies (age, length, lockout) – Using DOE approved policy FIPS 140 Encryption- Conflicted with Oracle middleware Remote Desktop and Remote Assist - Help Desk Smart Card removal behavior-Prevented logging into more then one system at a time. Terminal Server session timeout – Affects Remote Desktop sessions. IE Security Zones: Use Only Machine Settings - Not set to enable viewing of sites that have been added to a zone.

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL Variances in Detail (Continued) Wireless configuration wizards – Makes it easier for help desk troubleshooting (Standard Menus). Administrative Rights – Not all provisions are in place for admin rights removal. Sharing of files and printers – Users share between desktop and laptop. Root certificate updates – We are not staffed to publish trusted certificates in to the store. Left the automatic system in place Screen saver – Has an effect on setting a system into presentation mode.

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL Additional Information Security Zones: Do not allow users to add/delete sites - We created an application to enable users to add Web Site addresses to the Trusted and Intranet zones. We were considering requesting a variance to this policy, but to enable this required many other variances then initially thought. Microsoft network client: Digitally sign communications (always)- This will have an effect on connecting to Samba servers that are not running at least version a or newer. These settings are also not enabled on Server 2000 or NT by default and will need to be enabled for clients to access shares on those systems.

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL Additional Information (Continued) Network security: Minimum session security for NTLM SSP based (including secure RPC) clients (Require NTLMv2 Session Security)- Will break connectivity to Samba servers that are not members of the Active directory domain and using Active Directory Service security (Security = ADS) If you are using GPO’s have separate GPO’s for Vista and XP and use that platform to make modifications to it’s related GPO. Never mix the two. Vista has a new feature called Point and Print restrictions that can be found under User Configuration > Administrative Templates > Control Panel > Printers This can be used to define printers the users can install without needing administrative rights.

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL Additional Information (Continued) Try to consolidate GPO’s after testing. The more GPO’s you use, the longer it takes to process. Even if you only have a few setting in the GPO. Disable User section or Computer section of the GPO if not used in that GPO. For Additional information on Sandia’s Vista deployment, please see Roman Selever’s presentation Tomorrow at 11:00 in the James Polk room.

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL Questions to the group Are you deploying the FDCC or making plans to? Where are you at with the FDCC? Are you locking down IE? Are you using any Security Content Automation Protocol (SCAP) reporting tools (If yes, name)? Who is your POC for the FDCC? What this information useful?

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear Security Administration under contract DE-AC04-94AL Questions? Stan Hall (505)