Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


July 2007

Safely Deploy Security Templates

The Windows Server 2003 Security Guide gives you some powerful tools—use them wisely
RSS
Subscribe to Windows IT Pro | See More Active Directory (AD) Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Creating Override Policies
To resolve the problem with SMTP functionality that we looked at earlier, you can create a new GPO called an override policy that you apply only to the affected servers. The override policy contains just a few modifications to lower specific security requirements for the affected servers and leave the other configuration settings intact. The policy is then applied with a higher priority than the EC – Member Server policy to ensure that the modifications are implemented successfully. In the SMTP example, the override policy contains only the three settings that Table 2 shows.

Figure 2 shows how you can use the Group Policy Management screen's Group Policy Inheritance tab to link various GPOs in an order that ensures appropriate application of the settings. EC policies that you configure by using the Security Guide templates should have a higher precedence than Default policies, and override policies should have higher precedence than the EC policies.

Different policies apply depending on which organizational unit (OU) the server resides in. You can view all the GPOs that apply to an OU (either directly or by inheritance) by selecting the Group Policy Inheritance tab.

A More Secure System
Deploying the Security Guide templates requires a lot of planning and a preproduction lab environment where you can test functionality. However, using the security templates in combination with the SCW to create policies for your Windows servers gives you control over your security environment. You'll be able to make changes across many servers, comply with Microsoft's security best practices, and add reliability and stability to your environment. See "Do's and Don'ts of Using Security Templates," below, for tips to successfully use the security templates.

If Microsoft wants organizations to take security seriously, Exchange (and other servers and applications) should work out of the box with the EC security templates. At the very least, Microsoft should document the problems that this article identifies. This article summarizes the benefits and problems involved in using the security templates and the SCW; however, it's not a replacement for reading the documentation that comes with the guide.

Do's and Don't of Using Security Templates
DO: Incorporate security templates
in your Group Policy design from the very beginning.

Test all policies in a preproduction lab environment.

Use the SCW to configure start-up settings for system services.

Create a backup (including a system state backup) before deploying GPOs created from the templates in a production environment.

Consider using the templates in conjunction with Group Policy to secure and manage your environment.

Read the documentation that comes with the Windows Server 2003 Security Guide.

DON'T: Deploy a new GPO created from a security template and/or the SCW in your production environment without extensive testing and approval from system stakeholders.

Dismiss the risk to functionality of deploying security settings from a template en masse in a production environment.

Make changes to your production environment without a proven roll-back plan.


WINDOWS SERVER 2005 SECURITY CODE
Read the overview at http://www.microsoft.com/technet/security/prodtech/windowsserver2003/w2003hg/sgch00.mspx

Download the Security Guide and its tools at http://www.microsoft.com/downloads/details.aspx?FamilyId=8A2643C1-0685-4D89-B655-521EA6C7B4DB

End of Article

   Previous  1  2  [3]  Next  


Reader Comments
Link to download the Security Guide is dead.

ebraiter September 16, 2009 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
2009 Windows IT Pro Editors' Best and Community Choice Awards

Picking a favorite product from an impressive crowd of competitive offerings is never an easy task, and such was the case with our Editors' Best and Community Choice awards this year. ...

Is Microsoft Just Like IBM?

Microsoft has defined the way we do business from a technology perspective for years. But with a younger generation that lives in the clouds, is Microsoft's recent progress in cloud computing too little, too late? ...

Microsoft, News Corp. Discuss Locking Out Google

Microsoft and Rupert Murdoch's News Corp. recently discussed an alliance that would counter Google's fledgling online news service. ...


Active Directory (AD) Whitepapers Unleash the Power of Active Directory Groups

Meeting Compliance Objectives in SharePoint

Email Controls and Regulatory Compliance

Related Events Troubleshooting Active Directory

Deep Dive into Windows Server 2008 R2 presented by John Savill

Troubleshooting Group Policy, eLearning series

Check out our list of Free Email Newsletters!

Active Directory (AD) eBooks The Essentials Series: Active Directory 2008 Operations

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement