Hands-On Microsoft Windows Server 20081 Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.

Slides:



Advertisements
Similar presentations
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 7: Troubleshoot Security Settings and Local Security.
Advertisements

Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Lesson 17: Configuring Security Policies
Chapter 13 Securing Windows Server 2008
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
Chapter 8 Chapter 8: Managing Accounts and Client Connectivity.
Hands-On Microsoft Windows Server 2003 Administration Chapter 4 Managing Group Policy.
12.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
Chapter 6: Configuring Security. Options for Managing Security Configurations LGPO (Local Group Policy Object) –Used if Computer is not part of a domain.
11 SUPPORTING LOCAL USERS AND GROUPS Chapter 3. Chapter 3: Supporting Local Users and Groups2 SUPPORTING LOCAL USERS AND GROUPS  Explain the difference.
10.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
© N. Ganesan, Ph.D., All rights reserved. Active Directory Nanda Ganesan, Ph.D.
Corso referenti S.I.R.A. – Modulo 2 Local Security 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.
Module 8: Implementing Administrative Templates and Audit Policy.
11 SYSTEMS ADMINISTRATION AND TERMINAL SERVICES Chapter 12.
70-270: MCSE Guide to Microsoft Windows XP Professional Chapter 5: Users, Groups, Profiles, and Policies.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Securing Windows Servers Using Group Policy Objects
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.
Hands-On Microsoft Windows Server 2008 Chapter 10 Securing Windows Server 2008.
CH 12 Securing Windows Server Objectives Understand the security enhancements included in Windows Server 2008 Understand how Windows Server 2008.
Windows Server 2008 Chapter 10 Last Update
1 Chapter Overview Understanding Group Policies Implementing Group Policies Using Security Policies Troubleshooting Group Policy Problems.
Corso referenti S.I.R.A. – Modulo 2 07 – Group Policy 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Using Group Policy to Manage User Environments. Overview Introduction to Managing User Environments Introduction to Administrative Templates Assigning.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory Chapter 9: Active Directory Authentication and Security.
September 18, 2002 Introduction to Windows 2000 Server Components Ryan Larson David Greer.
Hands-On Microsoft Windows Server 2008
Guide to Operating System Security Chapter 4 Account-based Security.
Module 6: Designing Active Directory Security in Windows Server 2008.
Module 10: Configuring Windows XP Professional to Operate in Microsoft Networks.
C HAPTER 6 NTFS PERMISSIONS & SECURITY SETTING. INTRODUCTION NTFS provides performance, security, reliability & advanced features that are not found in.
Designing Active Directory for Security
Section 7: Implementing Security Using Group Policy Exploring the Windows Security Architecture Securing User Accounts Exploring Security Policies Hardening.
Windows Server 2003 Overview 1 Windows 2003 Server Overview Ayaz
Troubleshooting Windows Vista Security Chapter 4.
Fall 2011 Nassau Community College ITE153 – Operating Systems Session 22 Local Security Polcies 1.
Module 14: Configuring Server Security Compliance
Securing AD DS Module A 3: Securing AD DS
Module 7: Fundamentals of Administering Windows Server 2008.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
1 Chapter Overview Configuring Account Policies Configuring User Rights Configuring Security Options Configuring Internet Options.
8.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 8: Planning.
Chapter 13 Users, Groups Profiles and Policies. Learning Objectives Understand Windows XP Professional user accounts Understand the different types of.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Understanding Group Policy James Michael Stewart CISSP, TICSA, CIW SA, CCNA, MCSE NT & W2K, iNet+
© Wiley Inc All Rights Reserved. MCSE: Windows Server 2003 Active Directory Planning, Implementation, and Maintenance Study Guide, Second Edition.
Introduction to Microsoft Management Console (MMC) MMC is a common console framework for management applications. MMC provides a common environment for.
Implementing Group Policy. Overview What is Group Policy Introduction to Group Policy Group Policy Structure How Group Policy Settings Are Applied in.
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
Some overlap exists between the settings of the MMC and the settings of the registry. The MMC is extensible. Policies and properties can be edited via.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 14: Windows Server 2003 Security Features.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Module 7: Implementing Security Using Group Policy.
NetTech Solutions Security and Security Permissions Lesson Nine.
Administering Microsoft Windows Server 2003 Chapter 2.
Week 4 Objectives Overview of Group Policy Group Policy Processing Implementing a Central Store for Administrative Templates.
Module 10: Implementing Administrative Templates and Audit Policy.
Chapter 4- Part3. 2 Implementing User Profiles A local user profile is automatically created at the local computer when you log on with an account for.
Privilege Management Chapter 22.
Chapter 7 Server Management Policies –User accounts –Groups Rights and permissions Examples.
4.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 12: Implementing Security.
Unit 8 NT1330 Client-Server Networking II Date: 2?10/2016
Configuring the User and Computer Environment Using Group Policy Lesson 8.
Configuring Windows Firewall with Advanced Security
Chapter 8: Managing Accounts and Client Connectivity
Presentation transcript:

Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack surface of the kernel through Server Core –Expanded group policy –Windows Firewall –Network Access Protection –Security Configuration Wizard –User Account Control –BitLocker Drive Encryption

Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 (continued) Server Core is a good solution for a Web or other server in the demilitarized zone of a network Demilitarized zone (DMZ) –A portion of a network that is between two networks, such as between a private network and the Internet New group policy categories include: –Power management –Assigning printers by location –Delegation of printer driver installation –Security settings –Internet Explorer settings

Hands-On Microsoft Windows Server Introduction to Group Policy Group policy in Windows Server 2008 –Enables you to standardize the working environment of clients and servers by setting policies in Active Director Defining characteristics of group policy: –Group policy can be set for a site, domain, OU, or local computer –Group policy cannot be set for non-OU folder containers –Group policy settings are stored in group policy objects

Hands-On Microsoft Windows Server Introduction to Group Policy (continued) Defining characteristics of group policy: (continued) –GPOs can be local and nonlocal –Group policy can be set up to affect user accounts and computers –When group policy is updated, old policies are removed or updated for all clients

Hands-On Microsoft Windows Server Securing Windows Server 2008 Using Security Policies Security policies are a subset of individual policies –Within a larger group policy for a site, domain, OU, or local computer Security policies include: –Account Policies –Audit Policy –User Rights –Security Options –IP Security Policies

Hands-On Microsoft Windows Server Establishing Account Policies Account policies –Security measures set up in a group policy that applies to all accounts or to all accounts in a container when Active Directory is installed Password security –One option is to set a password expiration period, requiring users to change passwords at regular intervals –Some organizations require that all passwords have a minimum length

Hands-On Microsoft Windows Server Establishing Account Policies (continued) Specific password security options: –Enforce password history –Maximum password age –Minimum password age –Minimum password length –Passwords must meet complexity requirements –Store password using reversible encryption

Hands-On Microsoft Windows Server Account Lockout The operating system can employ account lockout –To bar access to an account (including the true account owner) after a number of unsuccessful tries The lockout can be set to release after a specified period of time –Or by intervention from the server administrator A common policy is to have lockout go into effect after five to 10 unsuccessful logon attempts

Hands-On Microsoft Windows Server Account Lockout (continued) Account lockout parameters –Account lockout duration –Account lockout threshold –Reset account lockout count after

Hands-On Microsoft Windows Server Account Lockout (continued) Kerberos security –Involves the use of tickets that are exchanged between the client who requests logon and network services access And the server or Active Directory that grants access Enhancements on Windows Server 2008 and Windows Vista –The use of Advanced Encryption Standard (AES) encryption –When Active Directory is installed, the account policies enable Kerberos

Hands-On Microsoft Windows Server Establishing Audit Policies Examples of events that an organization can audit are as follows: –Account logon (and logoff) events –Account management –Directory service access –Logon (and logoff) events at the local computer –Object access –Policy change –Privilege use –Process tracking –System events

Hands-On Microsoft Windows Server Configuring User Rights User rights enable an account or group to perform predefined tasks –The most basic right is the ability to access a server –More advanced rights give privileges to create accounts and manage server functions

Hands-On Microsoft Windows Server Configuring User Rights (continued) Some examples of privileges include the following: –Add workstations to domain –Back up files and directories –Change the system time –Create permanent shared objects –Generate security audits –Load and unload device drivers –Perform volume maintenance tasks –Shut down the system

Hands-On Microsoft Windows Server Configuring User Rights (continued) Examples of logon rights are as follows: –Access this computer from the network –Allow logon locally –Allow logon through Terminal Services –Deny access to this computer from the network –Deny logon as a service –Deny logon locally –Deny logon through Terminal Services

Hands-On Microsoft Windows Server Configuring Security Options Over 78 specialized security options, with many new ones added for Windows Server 2008 –Can be configured in the security policies Each category has specialized options

Hands-On Microsoft Windows Server Active Directory Rights Management Services Active Directory Rights Management Services (AD RMS) –A server role to complement the client applications that can take advantage of Rights Management Services safeguards Rights Management Services (RMS) –Security rights developed by Microsoft to provide security for documents, spreadsheets, , and other types of files created by applications –Uses security capabilities such as encryption, user authentication, and security certificates to help safeguard information

Hands-On Microsoft Windows Server Active Directory Rights Management Services (continued) General steps used in RMS security –A user creates a Word document, for example –In the process of protecting the document with RMS, Word encrypts the document using an AES key and an additional RSA key –The AD RMS server issues an identity license to the client who can access the document –Client shows the AD RMS server its license to access the document –The AD RMS server authenticates the client and determines the level of access

Hands-On Microsoft Windows Server Managing Security Using the Security Templates and Security and Configuration Analysis Snap-Ins This snap-in enables you to set up security to govern the following: –Account policies –Local policies –Event log tracking policies –Group restrictions –Service access security –Registry security –File system security

Hands-On Microsoft Windows Server Configuring Client Security Using Policies in Windows Server 2008 Customizing settings used by clients offers several advantages –Enhanced security and providing a consistent working environment in an organization The settings are customized by configuring policies on the Windows Server 2008 servers that the clients access –When the client logs on to the server or the network, the policies are applied to the client

Hands-On Microsoft Windows Server Manually Configuring Policies for Clients You can manually configure one or more policies that apply to clients –By using the Group Policy Object Editor snap-in –Or by using a customized snap-in, such as the Default Domain Policy console

Hands-On Microsoft Windows Server Resultant Set of Policy Resultant Set of Policy (RSoP) –Used to make the implementation and troubleshooting of group policies much simpler for an administrator –Can query the existing policies that are in place and then provide reports and the results of policy changes RSoP supports two modes: planning and logging