Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.

Slides:



Advertisements
Similar presentations
Chapter 10 Securing Windows Server 2008 MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration.
Advertisements

Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Configuring Windows Vista Security Lesson 8. Skills Matrix Technology SkillObjective DomainObjective # Setting Up Users Configure and troubleshoot parental.
Paula Kiernan Senior Consultant Ward Solutions
Defense-in-Depth Against Malicious Software Jeff Alexander IT Pro Evangelist Microsoft Australia
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Chapter 9 Chapter 9: Managing Groups, Folders, Files, and Object Security.
Configuring Windows Vista Security Chapter 3. IE7 Pop-up Blocker Pop-up Blocker prevents annoying and sometimes unsafe pop-ups from web sites Can block.
Chapter 7 HARDENING SERVERS.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 10: Server Administration.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
Implementing Server Security on Windows 2000 and Windows Server 2003 Steve Lamb Technical Security Advisor
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
Maintaining and Updating Windows Server 2008
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 11 Managing and Monitoring a Windows Server 2008 Network.
1 Chapter Overview Managing Compression Managing Disk Quotas Increasing Security with EFS Using Disk Defragmenter, Check Disk, and Disk Cleanup.
Corso referenti S.I.R.A. – Modulo 2 Local Security 20/11 – 27/11 – 05/12 11/12 – 13/12 (gruppo 1) 12/12 – 15/12 (gruppo 2) Cristiano Gentili, Massimiliano.
Module 8: Implementing Administrative Templates and Audit Policy.
Group Policy in Microsoft Windows Active Directory.
Module 16: Software Maintenance Using Windows Server Update Services.
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.
Securing Windows Servers Using Group Policy Objects
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory Chapter 12: Deploying and Managing Software with Group Policy.
11 SECURITY TEMPLATES AND PLANNING Chapter 7. Chapter 7: SECURITY TEMPLATES AND PLANNING2 OVERVIEW  Understand the uses of security templates  Explain.
Hands-On Microsoft Windows Server 2008
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
Week #7 Objectives: Secure Windows 7 Desktop
Module 13: Maintaining Software by Using Windows Server Update Services.
Implementing Update Management
Configuring Encryption and Advanced Auditing
1 Objectives Audit Policies Update and maintain your clients using Windows Server Update Service Microsoft Baseline Security Analyzer Windows Firewalls.
Troubleshooting Windows Vista Security Chapter 4.
Module 14: Configuring Server Security Compliance
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
20411B 8: Installing, Configuring, and Troubleshooting the Network Policy Server Role Presentation: 60 minutes Lab: 60 minutes After completing this module,
Module 2: Installing and Maintaining ISA Server. Overview Installing ISA Server 2004 Choosing ISA Server Clients Installing and Configuring Firewall Clients.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
Module 5: Configuring Internet Explorer and Supporting Applications.
Module 8: Planning and Troubleshooting IPSec. Overview Understanding Default Policy Rules Planning an IPSec Deployment Troubleshooting IPSec Communications.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
Module 15 Managing Windows Server® 2008 Backup and Restore.
Section 11: Implementing Software Restriction Policies and AppLocker What Is a Software Restriction Policy? Creating a Software Restriction Policy Using.
Guide to MCSE , Second Edition, Enhanced1 The Windows XP Security Model User must logon with: Valid user ID Password User receives access token Access.
Module 6: Designing Security for Network Hosts
Module 14: Securing Windows Server Overview Introduction to Securing Servers Implementing Core Server Security Hardening Servers Microsoft Baseline.
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 11: Managing Access to File System Resources.
Configuring Network Access Protection
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 14: Windows Server 2003 Security Features.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
1 Chapter Overview Managing Object and Container Permissions Locating and Moving Active Directory Objects Delegating Control Troubleshooting Active Directory.
Administering Group Policy Chapter Eleven. Exam Objectives in this Chapter  Plan a Group Policy strategy using Resultant Set of Policy Planning mode.
Rob Davidson, Partner Technology Specialist Microsoft Management Servers: Using management to stay secure.
Module 7: Implementing Security Using Group Policy.
Managing Applications, Services, Folders, and Libraries Lesson 4.
Module 10: Windows Firewall and Caching Fundamentals.
Module 10: Implementing Administrative Templates and Audit Policy.
Understand Server Protection LESSON Security Fundamentals.
Implementing Server Security on Windows 2000 and Windows Server 2003 Fabrizio Grossi.
Windows Server 2003 群組原則設定與管理 林寶森
Module 8 Implementing Security Using Group Policy.
4.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 12: Implementing Security.
ITMT 1371 – Window 7 Configuration 1 ITMT Windows 7 Configuration Chapter 8 – Managing and Monitoring Windows 7 Performance.
Maintaining and Updating Windows Server 2008 Lesson 8.
Implementing Update Management
Configuring Windows Firewall with Advanced Security
Implementing Client Security on Windows 2000 and Windows XP Level 150
Designing IIS Security (IIS – Internet Information Service)
Presentation transcript:

Module 9 Configuring Server Security Compliance

Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview of Windows Server® Update Services (WSUS) Managing WSUS

Applying Defense-in-Depth to Increase Security Defense-in-depth provides multiple layers of defense to protect a networking environment Security documents, user education Policies, Procedures, & Awareness Physical Security OS hardening, authentication Firewalls Guards, locks Network segments, IPsec Application hardening, antivirus ACLs, encryption, EFS Perimeter Internal Network Host Application Data

Core Server Security Practices Apply the latest service pack and all available security updates Use the Security Configuration Wizard to scan and implement server security Use Group Policy and security templates to harden servers Restrict scope of access for service accounts Restrict who can log on locally to servers Restrict physical and network access to servers

What Is Encrypting File System? EFS: File contents are protected by a symmetrical key The symmetrical key is protected by asymmetrical encryption Enabled in the properties of a file Requires a user certificate Can be used on shared files Can be configured with a recovery agent in case user certificates are lost Encrypting File System (EFS) is a system for encrypting files

What Is BitLocker Drive Encryption? BitLocker Drive Encryption: Helps protect data on the operating system drive Helps protect the operating system from modification Access to the operating system drive is controlled by encryption keys BitLocker is a system that encrypts the entire operating system drive and potentially data volumes

Troubleshooting EFS Check the following items: Unable to Encrypt The volume is NTFS User has Write access to file Roaming user profiles generally required to encrypt remote files Unable to Decrypt File location is trusted for delegation Roaming profile is available User account cannot be delegated Certificate or Private Key problems Determine if the problem occurs when encrypting or decrypting files, and whether the files are local or remote

What Is Auditing? Auditing tracks user and operating system activities, and records selected events in security logs, such as: What occurred? Who did it? When? What was the result? Enable auditing to: Create a baseline Detect threats and attacks Determine damages Prevent further damage Audit access to objects, management of accounts, and users logging on and off

Types of Events to Audit (Audit Policy) Account Logon Account Management Directory Service Access Directory Service Changes Directory Service Replication Detailed Directory Service Replication Logon Object Access Policy Change Privilege Use Process Tracking System

Troubleshooting Audit Policy View Security Log in Event Viewer After you configure auditing, it may not work for the following reasons: A site, a domain, or an organizational unit policy setting overrides the audit policy that you configured A GPO that overrides the audit policy setting has a higher priority The site, the domain, or the organizational unit policy setting that contains the audit policy setting has not replicated to other computers Object Access Auditing Understand how inheritance affects file and folder auditing Test an audit rule for a file or folder Open and close the file or folder View the security log to ensure Event ID 4663 is logged

Lesson: Overview of Windows Server Update Services (WSUS) What Is Windows Server Update Services? Obtaining Updates Windows Server Update Services Process WSUS Deployment Considerations Server Requirements for WSUS Installing WSUS WSUS Group Policy Settings Automatic Updates Configuration

Obtaining Updates WSUS Windows Update WSUS

Windows Server Update Services Process Update Management Phase 1: Assess Set up a production environment that will support update management for both routine and emergency scenarios Phase 3: Evaluate and Plan Test updates in an environment that resembles, but is separate from, the production environment Determine the tasks necessary to deploy updates into production, plan the update releases, build the releases, and then conduct acceptance testing of the releases Phase 4: Deploy Approve and schedule update installations Review the process after the deployment is complete Phase 4: Deploy Approve and schedule update installations Review the process after the deployment is complete Phase 2: Identify Discover new updates in a convenient manner Determine whether updates are relevant to the production environment Identify Evaluate and Plan Deploy Assess

Server Requirements for WSUS Software requirements: Windows Server 2003 SP1 or Windows Server 2008 IIS 6.0 or later Windows Installer 3.1 or later Microsoft.NET Framework 2.0 SQL Server 2005 SP1 or later (optional) Microsoft Report Viewer Redistributable 2005 Windows Server 2003 SP1 or Windows Server 2008 IIS 6.0 or later Windows Installer 3.1 or later Microsoft.NET Framework 2.0 SQL Server 2005 SP1 or later (optional) Microsoft Report Viewer Redistributable 2005

Installing WSUS Considerations for installing the WSUS Server: Select Update Source Select the software used to manage the WSUS database Select the Web site that WSUS will use to point client computers to WSUS Select Update Source Select the software used to manage the WSUS database Select the Web site that WSUS will use to point client computers to WSUS The WSUS Administration Console: The WSUS 3.0 administration console can be used to manage any WSUS server that has a trust relationship with the administration console computer

WSUS Group Policy Settings Group Policy can specify: Which WSUS server to use Whether update notifications are displayed Frequency of checking for updates Auto-restart behavior WSUS computer group membership Whether computers should wake up to apply updates Which WSUS server to use Whether update notifications are displayed Frequency of checking for updates Auto-restart behavior WSUS computer group membership Whether computers should wake up to apply updates

Automatic Updates Configuration Configure Automatic Updates by using Group Policy Computer Configuration/Administrative Templates/ Windows Components/Windows Update Requires updated wuau.adm administrative template Requires: Windows Vista Windows Server 2008 Windows Server 2003 Windows XP Professional SP2 Windows 2000 Professional SP4, Windows 2000 Server/Advanced Server SP3 or SP4 Configure Automatic Updates by using Group Policy Computer Configuration/Administrative Templates/ Windows Components/Windows Update Requires updated wuau.adm administrative template Requires: Windows Vista Windows Server 2008 Windows Server 2003 Windows XP Professional SP2 Windows 2000 Professional SP4, Windows 2000 Server/Advanced Server SP3 or SP4

WSUS Administration Command-line tools for managing updates: Wuauclt.exe – controls the Windows Update Agent Wsusutil.exe – management of WSUS Wuauclt.exe – controls the Windows Update Agent Wsusutil.exe – management of WSUS

Approving Updates Approval options include: Install Decline Unapprove Removal Automate approval is also supported Approval options include: Install Decline Unapprove Removal Automate approval is also supported

Server Core Security Updates To enable Windows Update on Server Core: Cscript c:\Windows\system32\scregedit.wsf /au /4 To manually install updates onto Server Core: Wsua.exe.msu /quiet To manually remove updates from Server Core: In.xml, replace Install with Remove and save the file. pkgmgr /n:.xml In.xml, replace Install with Remove and save the file. pkgmgr /n:.xml