Windows Server 2003 SP1 Technical Overview John Howard, IT Pro Evangelist, Microsoft UK

Slides:



Advertisements
Similar presentations
Desktop Value - Introducing Windows XP Service Pack 2 with Advanced Security Technologies Presenter: James K. Murray Title: Information Technologies Consultant.
Advertisements

Microsoft Windows XP SP2 Urs P. Küderli Strategic Security Advisor Microsoft Schweiz GmbH.
Chapter 10 Securing Windows Server 2008 MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration.
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Windows Server 2003 SP1. Windows Server™ 2003 Service Pack 1 Technical Overview Jill Steinberg: Added TM Jill Steinberg: Added TM.
1 of 5 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
Dan Stolts IT Pro Evangelist US DPE - North East Microsoft Corporation
Changes in Windows XP Service Pack 2
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 10: Server Administration.
Kalpesh Patel Ramprabhu Rathnam
1 of 3 Open Outlook On the Tools menu, click Account Settings. 1 Enable Outlook Anywhere 2 Click your Microsoft Exchange account, and then click.
1 of 3 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
Information for Developers Windows XP Service Pack 2 Information for Developers.
Implementing Server Security on Windows 2000 and Windows Server 2003 Steve Lamb Technical Security Advisor
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
Lesson 19: Configuring Windows Firewall
VMware vCenter Server Module 4.
Winter Consolidated Server Deployment Guide for Hosted Messaging and Collaboration version 3.5 Philippe Maurent Principal Consultant Microsoft.
Security of Communication & IT systems Bucharest, 21 st September 2004 Stephen McGibbon Chief Technology Officer, Eastern Europe, Russia & CIS Senior Director,
2851A_C01. Microsoft Windows XP Service Pack 2 Security Technologies Bruce Cowper IT Pro Advisor Microsoft Canada.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
Windows ® Powered NAS. Agenda Windows Powered NAS Windows Powered NAS Key Technologies in Windows Powered NAS Key Technologies in Windows Powered NAS.
Windows Vista: Volume Activation 2.0
Principles of Computer Security: CompTIA Security + ® and Beyond, Second Edition © 2010 Baselines Chapter 14.
Working with Applications Lesson 7. Objectives Administer Internet Explorer Secure Internet Explorer Configure Application Compatibility Configure Application.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
Module 1: Installing Windows XP Professional. Overview Manually Installing Windows XP Professional Automating a Windows XP Professional Installation Using.
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Hands-On Microsoft Windows Server 2008
Information for Developers Windows XP Service Pack 2 Information for Developers Tony Goodhew Product manager Developer Division Microsoft Corp
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Two Deploying Windows Servers.
Using Windows Firewall and Windows Defender
Implementing Network Access Protection
Module 14: Configuring Server Security Compliance
Section 1: Introducing Group Policy What Is Group Policy? Group Policy Scenarios New Group Policy Features Introduced with Windows Server 2008 and Windows.
OFC290 Information Rights Management in Microsoft Office 2003 Lauren Antonoff Group Program Manager.
C HAPTER 2 Introduction to Windows XP Professional.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
Migration from Software Update Services to Windows Server Update Services Jeff Alexander IT Pro Evangelist Microsoft Australia Scott Korman WSUS MVP SEC316.
Securing the Infrastructure Windows Server 2003 SP1 and Windows XP SP2 Ken Schaefer System Engineer, MVP Avanade.
DC440: Security (Part 2 of 2): Logons, permissions and views - how these systems work and how to manage them Pradeep GanapathyRaj Program Manager Project.
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
Module 5: Configuring Internet Explorer and Supporting Applications.
Module 14: Securing Windows Server Overview Introduction to Securing Servers Implementing Core Server Security Hardening Servers Microsoft Baseline.
ISA Server 2004 Introduction Владимир Александров MCT, MCSE, MCSD, MCDBA Корус, Управител
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Vulnerability Scanning Vulnerability scanners are automated tools that scan hosts and networks for known vulnerabilities and weaknesses Credentialed vs.
Windows XP Service Pack 2 Customer Awareness Workshop XP SP2 Technical Drilldown – Part 1 Craig Schofield Microsoft Ltd. UK September.
Principles of Computer Security: CompTIA Security + ® and Beyond, Third Edition © 2012 Principles of Computer Security: CompTIA Security+ ® and Beyond,
Rob Davidson, Partner Technology Specialist Microsoft Management Servers: Using management to stay secure.
Module 7: Implementing Security Using Group Policy.
Security Configuration Wizard Keith D Miller Microsoft European Support Readiness Manager.
Implementing Server Security on Windows 2000 and Windows Server 2003 Fabrizio Grossi.
Hands-On Microsoft Windows Server 2008 Chapter 5 Configuring Windows Server 2008 Printing.
Module 8 Implementing Security Using Group Policy.
Securing Tomorrow’s World Microsoft Security Roadmap Ed Gibson & Steve Lamb Microsoft Ltd.
Group Policy in Windows Vista. Group Policy Administration Group Policy with Windows Vista QoS Policies What Will We Cover?
NETWORK SECURITY LAB 1170 REHAB ALFALLAJ CT1406. Introduction There are a number of technologies that exist for the sole purpose of ensuring that the.
Welcome to Xandros Desktop Version 2.0. What is Xandros? The New Standard – Xandros is the award winning new standard for Desktop Operating System software.
11 DEPLOYING AN UPDATE MANAGEMENT INFRASTRUCTURE Chapter 6.
Securing the Network Perimeter with ISA 2004
Dynamic Web Page A dynamic web page is a kind of web page that has been prepared with fresh information (content and/or layout), for each individual viewing.
Session Objectives And Key Takeaways
Implementing Client Security on Windows 2000 and Windows XP Level 150
Designing IIS Security (IIS – Internet Information Service)
Windows XP SP2 & Windows Server 2003 SP1
Using Software Restriction Policies
Implementing Advanced Server and Client Security
Presentation transcript:

Windows Server 2003 SP1 Technical Overview John Howard, IT Pro Evangelist, Microsoft UK

Agenda Goals and Vision Security Enhancements Roadmap and Resources

Agenda Goals and Vision Security Enhancements Roadmap and Resources

Key Customer Challenges Security Securely configuring networks in a simplified way Coping with malicious hackers, viruses and network attacks Being prepared to face future security threats Reliability Minimise network downtime Performance Desire for increased performance

Some ways security is addressed in SP1 Support for “No Execute” hardware Windows Firewall & Boot Time Security Role based configuration and lockdown IIS 6.0 metabase auditing VPN Quarantine Internet Explorer

Agenda Goals and Vision Security Enhancements Roadmap and Resources

Hardware DEP Processor support required Software DEP Functional on any process supporting Windows Server 2003 Boot.ini “/noexecute=PolicyLevel” switch OptInOptOutAlwaysOnAlwaysOff GUI configuration through System Performance settings Security Enhancements Data Execution Prevention (DEP)

Security Enhancements Post Setup Security Updates (PSSU) Protects servers between first boot and application of most recent security updates Opens on first admin login if Windows Firewall was not explicitly enabled using unattend script or Group Policy Blocks inbound connections until customer clicks “Finish” on PSSU dialog box

Offers links to Windows Update Opportunity to configure Automatic Updates Re-opens if not completed before first restart Forced closure (ALT+F4) does not change firewall Tests to display PSSU again at next log on Security Enhancements Post Setup Security Updates (PSSU)

Invoked during Slipstreamed installation Not applied when Windows Firewall is enabled or disabled through Group Policy before PSSU is displayed Upgrade existing servers Security Enhancements Post Setup Security Updates (PSSU)

Security Enhancements Windows Firewall Enhancement to Internet Connection Firewall (ICF) Not on by default Except during PSSU Can be configured during installation Boot time security Global Configuration On with no exceptions Multiple profiles Integration with netsh command line utility

Windows Firewall Demo

Security Enhancements Security Configuration Wizard (SCW) Guided Attack Surface Reduction for Servers Security Coverage Roles-Based Metaphor Disables Unnecessary Services Disables Unnecessary IIS Web Extensions Blocks unused Ports, inlcuding multi-homed scenarios Helps Secure Ports that are left open using IPSEC Reduces protocol exposure (LDAP, NTLM, SMB) Configures Audit Setting with high Signal to Noise

Security Enhancements Security Configuration Wizard (SCW) Install Add/remove Windows Components Unattended setup Configuration saved to XML file Command line support Rollback capability Analysis capability

Security Configuration Wizard Demo

Security Enhancements Internet Explorer Feature parity with XP SP2 Zone elevation Add-on management Information bar Pop-up management Window restrictions Download security

RPC and DCOM Enhancements Dovetails with Windows XP SP2 RPC attack surface reduced New RPC registry keys Allow server applications to restrict access to the interface, typically through a security call back Enables application developers to more closely control access Additional DCOM access control restrictions Strengthening of DCOM authentication security model Overall reduction of risk of a successful network attack RPC and DCOM ports handled as a special case by Windows Firewall

Security Enhancements Access Based Directory Enumeration What it does Hides directories based on access rights InterfacesGUI Command line tool markShareforABDE.exe Whitepaper on microsoft.com

Access Based Directory Enumeration Demo

Agenda Goals and Vision Security Enhancements Roadmap and Resources

MajorRelease MajorReleaseMajorReleaseReleaseUpdateReleaseUpdate ~ 4 years ~ 2 years Mainstream Service Packs & Updates Extended Support At least 5 years At least 5 years from major release Release Cycle

► Windows Server 2003 Service Pack 1 ► Windows Server 2003 x64 Editions ► Windows Server Update Services ► Windows Server “Longhorn” Beta ► Windows Server 2003 “R2” ► Windows Storage Server “R2” ► Windows Server “Longhorn” Windows Server “Longhorn R2” Release Roadmap

Resources Windows Server 2003 Home Page Windows Server 2003 SP1 Home Page Technet TechCentre

Download locations Windows Update Download centre

Deployment Guidance Documents How to deploy Windows Server 2003 SP1 in an Enterprise Infrastructure How to configure and deploy Windows Firewall functionality centrally through Windows Server 2003 SP1 and Active Directory How to deploy role-based secure Servers with Windows Server 2003 SP1 and Security Configuration Wizard How to setup VPN Quarantine of users utilizing Windows Server 2003 SP1 How to deploy VPN Quarantine in an Enterprise Infrastructure utilizing Windows Server 2003 SP1 How to setup Secure Server Templates with Security Configuration Wizard in Windows Server 2003 SP1 How to deploy Security Configuration Wizard Server Templates with Active Directory utilizing Windows Server 2003 How to deploy Security Configuration Wizard Server Templates with Active Directory utilizing Windows Server 2003

Summary SP1 provides significant security enhancements as well as reliability and performance improvements Windows Server SP1 provides tools to reduce attack surface area To maximize security/performance Windows Server, begin evaluating SP1 today Exciting roadmap – complement to XP SP2, precursor to Windows Server 2003 R2 and Longhorn

© 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS SUMMARY.

Windows Server 2003 SP1 Technical Overview John Howard, IT Pro Evangelist, Microsoft UK