Windows Vista Configuration MCTS 70-620: User Account Security.

Slides:



Advertisements
Similar presentations
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Advertisements

Module 1: Installing Windows XP Professional
Operating System Customization
 Overview User Accounts Groups User Rights Permissions.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
CSCD 303 Essential Computer Security Fall 2010 Lecture 4 - Desktop Security Reading:
6.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Chapter 6: Configuring Security. Options for Managing Security Configurations LGPO (Local Group Policy Object) –Used if Computer is not part of a domain.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 8: Implementing and Managing Printers.
Chapter 5: Configuring Users and Groups. Windows Vista User Accounts User accounts are the primary means of authentication Built-in Accounts –Administrator:
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Lesson 10 Operating System Customization
Installing and Troubleshooting Hardware Device and Drivers Chapter 6 powered by dj.
Working with Drivers and Printers Lesson 6. Skills Matrix Technology SkillObjective DomainObjective # Understanding Drivers and Devices Install and configure.
Working with Workgroups and Domains
MCTS Guide to Configuring Microsoft Windows Server 2008 Active Directory Chapter 3: Introducing Active Directory.
Sharing Resources Lesson 6. Objectives Manage NTFS and share permissions Determine effective permissions Configure Windows printing.
© 2012 The McGraw-Hill Companies, Inc. All rights reserved. 1 Third Edition Chapter 6 Today’s Windows Windows Vista and Windows 7 McGraw-Hill.
1 Group Account Administration Introduction to Groups Planning a Group Strategy Creating Groups Understanding Default Groups Groups for Administrators.
Module 14: Configuring Print Resources and Printing Pools.
Managing Windows Server 2008 R2 Lesson 2. Objectives.
Managing User Accounts, Passwords and Logon Chapter 5 powered by dj.
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
Module 6: Designing Active Directory Security in Windows Server 2008.
Module 10: Configuring Windows XP Professional to Operate in Microsoft Networks.
Operation system(windows) User Accounts. What is a user account?  A collection of information that tells Windows which files and folders you can access,
© 2012 The McGraw-Hill Companies, Inc. All rights reserved. 1 Third Edition Chapter 5 Windows XP Professional McGraw-Hill.
Troubleshooting Windows Vista Security Chapter 4.
Module 7: Fundamentals of Administering Windows Server 2008.
Module 3: Configuring Hardware on a Computer Running Windows XP Professional.
IOS110 Introduction to Operating Systems using Windows Session 8 1.
DIT314 ~ Client Operating System & Administration CHAPTER 5 MANAGING USER ACCOUNTS AND GROUPS Prepared By : Suraya Alias.
Managing Groups, Folders, Files and Security Local Domain local Global Universal Objects Folders Permissions Inheritance Access Control List NTFS Permissions.
1 Chapter Overview Configuring Account Policies Configuring User Rights Configuring Security Options Configuring Internet Options.
70-270: MCSE Guide to Microsoft Windows XP Professional 1 Windows XP Professional User Accounts Designed for use as a network client for: Windows NT Windows.
Windows Vista Inside Out Ch 10: Ch 10: Security Essentials Last modified
Module 1: Installing Microsoft Windows XP Professional.
Module 3 Configuring File Access and Printers on Windows ® 7 Clients.
Module 3 Configuring File Access and Printers on Windows 7 Clients.
Working with Workgroups and Domains Lesson 9. Objectives Understand users and groups Create and manage local users and groups Understand the difference.
Module 3: Configuring File Access and Printers on Windows 7 Clients
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Core 3: Communication Systems. Network software includes the Network Operating Software (NOS) and also network based applications such as those running.
NetTech Solutions Security and Security Permissions Lesson Nine.
Understand Permissions LESSON Security Fundamentals.
Working with Users and Groups Lesson 5. Skills Matrix Technology SkillObjective DomainObjective # Introducing User Account Control Configure and troubleshoot.
CHAPTER 5 MANAGING USER ACCOUNTS & GROUPS. User Accounts Windows 95, 98 & Me do not need a user account like Windows XP Professional to access computer.
© 2012 The McGraw-Hill Companies, Inc. All rights reserved. 1 Third Edition Chapter 6 Today’s Windows Windows Vista and Windows 7 McGraw-Hill.
Chapter 7 Server Management Policies –User accounts –Groups Rights and permissions Examples.
1 Chapter Overview Using Group Objects Understanding Default Groups Creating Group Objects Managing Administrative Access.
Lesson 6: Controlling Access to Local Hardware and Applications
6/19/2016 أساسيات الأتصال و الشبكات Communication & Networks Fundamentals lab 4.
Labs. Session 1 Lab: Installing and Configuring Windows 7 Exercise 1: Migrating Settings by Using Windows Easy Transfer Exercise 2: Configuring a Reference.
Guide to Operating Systems, 5th Edition
Introducing, Installing, and Upgrading Windows 7
Nassau Community College
Lesson 6: Configuring Servers for Remote Management
Configuring Windows Firewall with Advanced Security
Lesson 10 Operating System Customization
Figure 6-9: Managing Users and Groups
Securing Windows 7 Lesson 10.
BACHELOR’S THESIS DEFENSE
Windows Server 2003 使用者群組管理
Designing IIS Security (IIS – Internet Information Service)
Network Locations in Windows 7
Presentation transcript:

Windows Vista Configuration MCTS : User Account Security

User Accounts and Groups Workstations can be configured as a member of a workgroup or domain. A domain is a logical group of computers that define a security boundary. A user account enables a user to log on to a computer or domain with an identity that can be authenticated and authorized for access to the resources of the computer or domain.

User Accounts Local user accounts Defined on a local computer and have access to the local computer only. Local Users and Groups is accessible through the Computer Management console. Domain user accounts Defined in the Active Directory. Can access resources throughout a domain/forest.

Default User Accounts Administrator Provides complete access to files, directories, services, and other facilities on the computer. This account cannot be deleted. Guest Designed for users who need one-time or occasional access. Has limited privileges. High risk of potential security problems.

Windows Vista Local Accounts Standard Account to use for everyday computing. Permission from an administrator is required if you want to make changes that affect other users or the security of the computer. Administrator Provides the most control over the computer. Can change security settings, install software and hardware, and access all files on the computer. Guest For people who need temporary access to the computer. Enables people to use your computer without having access to your personal files. Can’t install software or hardware, change settings, or create a password.

Domain Logon Names At symbol The full logon name for User1 in the Acme.com domain is Backslash symbol (\) The full logon name for User1 in the Acme domain is Acme\User1

Managing Local Logon Accounts

Giving Domain Accounts Local Access

User Accounts Console Change accounts Create and change passwords Remove local user accounts

Network Rights and Permissions When planning for how you assign the rights and permissions to the network resources, follow these two main rules: Give the rights and permissions for the user to do his job. Don’t give any additional rights and permissions that a user does not need.

User Account Control

User Account Privileges View system clock and calendar Change time zone Install Wired Equivalent Privacy (WEP) to connect to secure wireless networks Change display settings Change power management settings Install fonts Add printers and other devices that have the required drivers installed on computer or are provided by an IT administrator Create and configure a virtual private network connection Download and install updates using UAC-compatible installer

Tasks that will trigger a UAC prompt, if UAC is enabled: Changes to files in %SystemRoot% or %ProgramFiles% Installing and uninstalling applications Installing device drivers Installing ActiveX controls Installing Windows Updates Changing settings for Windows Firewall Changing UAC settings Configuring Windows Update Adding/removing user accounts Changing a user’s account type Configuring parental controls Running Task Scheduler Restoring backed-up system files Viewing/changing another user’s folders and files

UAC Messages Windows needs your permission to continue A program needs your permission to continue An unidentified program wants access to your computer This program has been blocked

Program Compatibility Some legacy applications will not run on Windows Vista because of compatibility problems. Windows includes a Program Compatibility Wizard to configure Windows to run a program under an older Windows environment. A fully compatible application will keep the system secure by requesting privilege elevation as necessary. The Run This Program as an Administrator option allows the application to use the UAC system to request privilege escalation.

UAC Message Behavior Administrators Elevate without Prompting Prompt for Credentials Prompt for Consent Standard Users Automatically Deny Elevation Requests Prompt for Credentials