Auditing Microsoft Active Directory

Slides:



Advertisements
Similar presentations
COMP091 OS1 Active Directory. Some History Early 1990s Windows for Workgroups introduced peer-to-peer networking based on SMB over netbios (tcp/ip still.
Advertisements

Sandia is a multiprogram laboratory operated by Sandia Corporation, a Lockheed Martin Company, for the United States Department of Energy’s National Nuclear.
Module 5: Creating and Configuring Group Policy
Managing User Settings with Group Policy
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Chapter 6 Introducing Active Directory
Hands-On Microsoft Windows Server 2003 Administration Chapter 4 Managing Group Policy.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
MIS Chapter 91 Ch. 9 – Implement and Use Group Policy MIS 431 – created Spring 2006.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
By Rashid Khan Lesson 4-Preparing to Serve: Understanding Microsoft Networking.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 1: Introduction to Windows Server 2003.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Understanding Active Directory
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
Guide to MCSE , Enhanced 1 Activity 9-1: Creating a Group Policy Object Using the MMC Objective: To create a GPO using the Group Policy Object Editor.
Group Policy in Microsoft Windows Active Directory.
Module 16: Software Maintenance Using Windows Server Update Services.
9.1 © 2004 Pearson Education, Inc. Lesson 9: Implementing Group Policy in Windows 2000 Server Exam Microsoft® Windows® 2000 Directory Services Infrastructure.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Corso referenti S.I.R.A. – Modulo 2 07 – Group Policy 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Using Group Policy to Manage User Environments. Overview Introduction to Managing User Environments Introduction to Administrative Templates Assigning.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory Chapter 12: Deploying and Managing Software with Group Policy.
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
Module 6: Designing Active Directory Security in Windows Server 2008.
Module 13: Maintaining Software by Using Windows Server Update Services.
Section 2: Using Group Policy Management Tools Local vs. Domain Policies Editing Local Policies Managing Domain Policies Understanding Group Policy Refresh.
Designing Active Directory for Security
Section 1: Introducing Group Policy What Is Group Policy? Group Policy Scenarios New Group Policy Features Introduced with Windows Server 2008 and Windows.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
Managing User Desktops with Group Policy
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 1: Introduction to Windows Server 2003.
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
September 18, 2002 Windows 2000 Server Active Directory By Jerry Haggard.
Active Directory Administration Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Creating Users, Computers, and Groups Automate creation.
Module 6: Configuring User Environments Using Group Policy.
Module 7 Configure User and Computer Environments By Using Group Policy.
Active Directory Harikrishnan V G 18 March Presentation titlePage 2 Agenda ► Introduction – Active Directory ► Directory Service ► Benefits of Active.
Implementing Group Policy. Overview What is Group Policy Introduction to Group Policy Group Policy Structure How Group Policy Settings Are Applied in.
Module 5: Configuring Internet Explorer and Supporting Applications.
GPO - WINDOWS SERVER AGENDA: Introduction Group Policy Overview Types of Group Policies/Objects Associated Technologies How to implement.
4. Managing the Desktop Thomas Lee Chief Technologist – QA plc.
Section 11: Implementing Software Restriction Policies and AppLocker What Is a Software Restriction Policy? Creating a Software Restriction Policy Using.
Module 5: Implementing Group Policy
Module 5: Creating and Configuring Group Policies.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Administering Group Policy Chapter Eleven. Exam Objectives in this Chapter  Plan a Group Policy strategy using Resultant Set of Policy Planning mode.
Week 4 Objectives Overview of Group Policy Group Policy Processing Implementing a Central Store for Administrative Templates.
Module 10: Implementing Administrative Templates and Audit Policy.
OVERVIEW OF ACTIVE DIRECTORY
Introduction to Active Directory
Module 6: Configuring User Environments Using Group Policies.
Module 6 Creating and Configuring Group Policy. Module Overview Overview of Group Policy Configuring the Scope of Group Policy Objects Evaluating the.
Windows Server 2003 群組原則設定與管理 林寶森
GROUP POLICY. Group Policy is a hierarchical infrastructure which allows systems administrators to configure computer and user settings from a central.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Overview Microsoft Windows XP Pro (SP2) Microsoft Windows Server 2003 User accounts and groups File sharing and file permissions Password/Lockout Policy.
Microsoft Installing & Configuring Windows Server Exam Questions Answers Powered By:
1.1 Microsoft® Windows® 2003 Server Group Policy Management Prof. Abdul Hameed.
Implementing Active Directory Domain Services
Objectives Differentiate between the different editions of Windows Server 2003 Explain Windows Server 2003 network models and server roles Identify concepts.
Utilize Group Policy Terminal Server Settings
Windows Server 2008 Administration
Windows Active Directory Environment
Presentation transcript:

Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature

What is Active Directory A central component of the Windows platform, Active Directory directory service provides the means to manage the identities and relationships that make up network environments. Resources – Computers & Printers Services – E-Mail, Policies, DNS, etc. Users – Accounts and security groups

Primary Items of Importance Business Continuity Is Active Directory backed up? Are there multiple Domain Controllers? Security Who has access to change Active Directory? What settings in Active Directory affect security? (passwords, etc.) Policies What environment is created from AD Polices?

Business Continuity Active Directory Backups – Critical Data How often? Where are they stored? see Backing up an Active Directory Server doc Multiple Domain Controllers Should have the global catalog show where in Sites and Services

Questions

Active Directory Security Who can access Active Directory? What can they change? Is auditing turned on for Active Directory?

Access to Active Directory Active Directory Boundaries Physical Security Domain Forests & Trusts

Permissions to Change AD Groups of Interest Enterprise Admins Schema Admins Administrators Domain Admins Server Operators Account Operators Backup Operators DS Restore Mode Administrator

Questions

Group Policy in Microsoft Windows Active Directory

What is Active Directory Group Policy? The Group Policy management solution in Microsoft® Windows Server™ 2003 allows administrators to define configurations for both servers and user machines. Local policy settings can be applied to all machines, and for those that are part of a domain, an administrator can use Group Policy to set policies that apply across a given site, domain, or range of organizational units (OUs) in the Active Directory® directory service. Support for Group Policy is available on machines running Microsoft Windows 2000 Server, Microsoft Windows 2000 Professional, Microsoft Windows® XP Professional, and Windows Server 2003.

Overview Control Internet Explorer Settings Control Computer/User Settings Software Distribution Windows Updates Much, Much More…..

Getting Started Windows 2003 Active Directory Group Policy Manager Plug-in

Choose an Organizational Unit Creating a Policy Create and Link GPO Choose an Organizational Unit

Assigning a Policy Policies Linked to this OU Policies Inherited Delegation of this OU

Defining Internet Explorer Control the Functionality of IE Plug-Ins Menus Empty Temp Folder Control the Security of IE Active X .NET Block Sites

Configuring an IE Policy Define your Zones Internet Intranet Trusted Restricted Define your Settings Apply Policy to an OU ZONES 1 – Intranet 2 – Trusted 3 – Internet 4 - Restricted

Control User/Computer Settings Configure the Desktop Hide icons/menus Dictate wallpaper Control Software Installation or Use Prohibit software from being installed or uninstalled Prohibit software from being run Lockdown Administrator Functions Network or security settings Configure Windows Firewall

Configure a Desktop Policy

Software Distribution Automatically Install Software at Logon Publish Software Remove Software Update Software

Configure a Software Install Policy Install a Software Package on Logon The software will be installed when the user logs on Publish a Software Package The software will be available through “Add/Remove Programs” Redeploy a Software Package The package will be redeployed (Update or New Version) Uninstall a Software Package The software will be removed Install Path to MSI File

Managing Windows Updates Create a policy to use the Windows Update Services server Assign WSUS Server Assign WSUS Groups Install and Configure WSUS

Windows System Update Server Updates for Windows, Office, Exchange Server, and SQL Server, with additional product support over time Automatic download of specific updates Automated actions for updates, determined by administrator approval Ability to determine the applicability of updates before installing them Targeting Reporting

How WSUS Works Downloads selected updates to central update server Release updates to specified groups Report on status of updates

Computer Name Operating System Last Status Report Computer Group

Install Detect only Not Approved Update Type Release Date Update Name Approval

Reporting Computer Name Installed Needed Not Needed Unknown Failed Last Updated Update Title Status Type

Questions

Tools GPResult Admx Group Policy Manager

True Last Logon http://www.dovestones.com/products/True_Last_Logon.asp

What AD Policies am I getting? GPRESULT Open a command window Type gpresult

Export Group Policy Settings AdmX.exe: ADM File Parser Category The ADM File Parser (AdmX) is a command-line tool that enables an administrator to export Group Policy settings to a tab-delimited text file. The administrator can then use the text produced by ADM File Parser (AdmX) to find changes for the policy settings between different versions of the operating systems. AdmX is for use only with policies based on administrative templates. Version compatibility The AdmX.exe tool runs on Windows 2000, Windows Server 2003, and Windows XP Professional. AdmX.exe also requires the Microsoft .NET Framework 1.0.

Group Policy Manager

Questions