Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


June 2004

Setting Up Windows Systems Securely


RSS
Subscribe to Windows IT Pro | See More Internet Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

I've heard that you shouldn't connect new Windows systems to the network until you complete the setup. Why?

When you install Windows, it configures itself with default settings, some of which are insecure even in Windows Server 2003. Additionally, a new Windows system usually lacks all security patches released since the OS was released. The only way to make sure new Windows systems are secure is to perform a slipstreamed installation of Windows, in which you copy the contents of the Windows CD-ROM to a server folder, then install service packs and updates on top of the Windows installation files.

To slipstream a service pack, note the folder to which you've copied the Windows CD-ROM, then run the service pack's update program and use the -s parameter to point to the Windows installation files. For example, if you copied your Windows CD-ROM to \\server1\windows, you'd change your current directory to the directory that contains your service pack and run the command

update -s \\server1\windows

The service pack will update the specified installation files.

A new Windows system is initially vulnerable to a host of risks from other systems on the network. If you connect the new system to the Internet, the risks are even higher—sometimes a new Windows system is hacked even before the administrator can lock it down. Consequently, you should install Windows while the system is disconnected from any network that attackers or malicious insiders could access.

For those who don't have an isolated setup-lab network with a server that hosts Windows setup files and application installation files, Microsoft provides a handy tool called the Security Readiness Kit (SRK) 4.1. The SRK contains the most recent service packs for Windows NT 4.0 and later, Microsoft SQL Server 7.0 and later, Microsoft Data Engine (MSDE) 1.0 and later, and SQL Server Desktop Engine 2000. The SRK lets you install service packs directly from the CD-ROM without having a network. The SRK also provides links to all post-service-pack security updates. To use this feature, you need to connect the computer to a network that provides Internet access, then download the updates from the Windows Update site.

End of Article



Reader Comments
The ideas presented were already know to me.

DonJuan64 August 02, 2004 (Article Rating: )


its a really useful article as in the sense, any administrators must know this.

Anonymous User February 04, 2005


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 9, 2009

An often irreverent look at some of the week's other news, including some more Windows 7 sales momentum, some Sophos stupidity, Microsoft's cloud computing self-loathing, more whining from the browser makers, Zoho's "Fake Office," and much, much more ...

Understanding File-Size Limits on NTFS and FAT

A general confusion about files sizes on FAT seems to stem from FAT32's file-size limit of 4GB and partition-size limit of 2TB. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events SQL Server Unleashed EMEA

WinConnections and Microsoft® Exchange Connections

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement