Printer Friendly Version      Send     
Click to Rate and Give Feedback
 Windows Administration: Secure Your...
Related Articles
Your users are complaining that a server is running poorly—do you know where to look to diagnose the problem? PerfMon can be an indispensible tool for this as it has numerous diagnostic capabilities. Get an overview of the key indicators you should use to diagnose a variety of common bottlenecks that can slow down your servers.

By Steven Choy (August 2008)
When you want to reduce the total cost of ownership of the desktop machines in your organization, application lockdown can be a great help, letting you limit IT issues related to unsupported applications. See how you can use software restriction policies and Group Policy to control the applications being run throughout your IT infrastructure.

By Chris Corio and Durga Prasad Sayana (June 2008)
Too many administrators underestimate the importance of having a well-designed Organizational Unit structure. Find out why having a sound OU strategy is important and determine the best OU structure for your organization.

By Ken St. Cyr (May 2008)
Many applications that rely on Active Directory define their own changes to the schema. But it's important that these changes don't impact other applications. Get an overview of extending the Active Directory through the classSchema and attributeSchema objects.

By Vikas Malhotra (May 2008)
More ...
Articles by this Author
ADM files are both necessary and often confusing. Don't let this slow your Group Policy efforts. This guided tour will help you better understand what's inside ADM files and the new ADMX format, which tools you can use to handle them, and how you can make the best use of these files.

By Jeremy Moskowitz (January 2008)
It's a common problem—how do you let users work with files stored on the network, when they have unreliable or no connectivity, and still avoid versioning issues? Such continuity is essential to providing a seamless experience. Discover how improvements in Windows Vista provide a better approach to working with offline files.

By Jeremy Moskowitz (November 2007)
USB thumb-disk keys and other removable devices can make your personal life easier but your professional life harder. For improved security, you need a way to control what hardware devices your users are installing on their work systems. Now you can use Group Policy to control which devices they can use and which ones they can’t.

By Jeremy Moskowitz (June 2007)
The Group Policy infrastructure has been overhauled, delivering new management features, new policy settings, support for multiple local GPOs, and much more. This article looks under the hood at the many changes Windows Vista brings to Group Policy.

By Jeremy Moskowitz (November 2006)


By Jeremy Moskowitz (October 2006)


By Jeremy Moskowitz (August 2006)
One of the most common requests I get at my Group Policy forum, GPanswers. com, is how to take machines and "lock them down. " People want to ensure their machines can’t be broken by Joe User or Harry Badguy.

By Jeremy Moskowitz (July 2006)


By Jeremy Moskowitz (May • June 2006)
More ...
Popular Articles
Is your infrastructure ready for virtualization? The Microsoft Assessment and Planning Toolkit, a network-wide infrastructure assessment tool, can help you better understand your IT infrastructure and determine whether your systems are ready for upgrade or migration to a variety of technologies, including virtualization.

By Jay Sauls and Baldwin Ng (October 2008)
Windows Vista SP1 and Windows Server 2008 introduce important changes to BitLocker, including support for data volumes and improved protection against cryptographic attacks. Byron Hynes explores the new features, demonstrates how to use BitLocker on a server, and discusses some of the recent media coverage affecting BitLocker.

By Byron Hynes (June 2008)
For every monitoring object you build, you must also decide what target to use. Choosing the correct target is critical, but knowing how to go about choosing the correct target is not always clear. Steve Rachui explores various options for correct targeting in OpsMgr and provides guidance for choosing the appropriate method for each scenario.

By Steve Rachui (November 2008)
System Center Virtual Machine Manager provides a consolidated interface for managing your virtual infrastructure. The latest version adds support for Windows Server 2008 Hyper-V, as well as for VMware virtual machines. Explore the new features and get an overview of using VMM to centralize your management tasks.

By Edwin Yuen (October 2008)
More ...
Read the Blog
The much-anticipated release of Windows Server 2008 introduced significant changes to the OS, adding powerful functionality such as server core, server roles,  read-only DCs, Hyper-V, Terminal Services Gateway, and enhancement support for Internet Protocol version 6 (IPv6). While these changes and new features are beneficial, they ...
Read more!
Virtualization is hot nowadays, but Terminal Services has been abstracting the presentation layer of remotely run applications and desktops for years. A lot has changed over the years, and with Windows Server 2008, Terminal Services has truly become a mature, robust presentation virtualization ...
Read more!
If you’re an OpsMgr 2007 administrator, chances are good that you’ll be creating custom monitoring objects (rules, groups, and so forth), and for each one you build, you have to decide what target to use. That’s a critical decision, but knowing how to go about choosing the correct target is not always clear. Steve ...
Read more!
The November 2008 issue of TechNet Magazine is now available online.   FEATURE ARTICLES                                                                   ...
Read more!
It's been about 8 years since Scott Culp published "The 10 Immutable Laws of Security." It is one of the best and most important essays on computer security ...
Read more!
As you might have guessed, October is virtualization month. TechNet Magazine is celebrating with a blockbuster issue,  there are launch events all over the country, and there are a slew of on-demand webcasts that let you explore the world of server virtualization. Here’s just ...
Read more!
More ...
New information has been added to this article since publication.
Refer to the Editor's Update below.


Windows Administration
Secure Your Desktops With The New Group Policy Settings In SP2
Jeremy Moskowitz
 
At a Glance:
  • Windows XP SP2 firewall
  • Securing access to the Internet
  • Internet Explorer policy settings
  • Setting file-level risk settings
Group Policy Admini- stration
Active Directory
Security
Windows XP SP2

The Group Policy mechanism built into Windows has always been the most effective and efficient way to immediately gain more control over your user, client, and server population. Once you deploy Windows XP Service Pack 2 (SP2), your control will get better. Let's examine some of the goodies that you'll be able to explore once the latest service pack is installed on your Windows® XP clients.
There are over six hundred new policy settings available for machines loaded with Windows XP SP2. Space prevents me from examining each one individually, but I will describe some of the categories of new features as well as some of the most useful policy settings so that you can get to work and put them to use right away.
[Editor's Update - 5/16/2005:The Group Policy snap-in for the Microsoft Management Console allows you to edit Group Policy Objects. To access this snap-in in Windows XP, go to Start | Run, and enter gpedit.msc. You can also find gpedit.msc in the %windir%\system32 directory.]

Controlling the Windows XP SP2 Firewall
Perhaps the biggest news for Windows XP SP2 is the built-in Windows Firewall. For the record, there was always a firewall built into Windows XP, but with Windows XP SP2, the firewall is turned on by default and is much more controllable via Group Policy. Before the release of Windows XP SP2, the firewall was turned off by default. The policies used to control the Windows Firewall can be found in two locations: Administrative Templates | Network | Network Connections | Windows Firewall | Domain Profile, and Administrative Templates | Network | Network Connections | Windows Firewall | Standard Profile. Inside each node, you'll find a number of new additions that will allow you to achieve fine-grained control. Take a look at Figure 1 to see all the new controls located within the Domain Profile node.
Figure 1 Windows XP SP2 Firewall Settings 
But what is the difference between the Domain Profile node and the Standard Profile node? The Domain Profile settings take effect when users are inside your home network, that is, when they're actively logged in by a Domain Controller. The Standard Profile is useful for when users are out of the office, perhaps in a hotel or on another public network where they cannot reach your company's Domain Controllers for authentication. In these situations, you might choose to handle firewall settings differently. For instance, your corporate policy might dictate that certain ports need to be opened on each desktop for a specific application or for administrative management, but that users should have an even tighter level of security when they are on the road.
Once a Windows XP SP2 computer receives the policy settings for both the Domain Profile and Standard Profile, that computer is ready to travel both in and out of the office. You can be sure that machine is employing your company's firewall security policy both in the office and on the road.
If you're interested in getting some more information about how a computer determines if it is supposed to use "Domain Profile" or "Standard Profile" policy settings, be sure to read "Determination Behavior for Network-Related Group Policy Settings" on the Microsoft® TechNet Web site.

Securing Computer Access to the Internet
There are two areas containing Group Policy settings for securing Internet access, that will be of particular interest when you want even tighter control on outbound Internet communications. For instance, administrators in academic environments might want to restrict a specific set of computers from connecting to the Internet. Or, a corporate administrator might want to increase protection when it comes to their users downloading (and potentially executing) specific file types.
To locate these areas, first go to Administrative Templates | System | Internet Communication Management where you'll locate the Restrict Internet Communication policy setting. This setting can be used to disable Internet communications for specified machines. Additionally, if you go to Administrative Templates | System | Internet Communication Management and select Internet Communication settings, as seen in Figure 2, you'll find some additional lockdown options when Internet communication is involved. Most of the policy settings in this section are self-explanatory, but they are valuable additions for protecting both corporate and academic networks from adding unnecessary software or potentially misusing the computing resources.
Figure 2 Internet Communication Settings 
Next, go to User Configuration | Administrative Templates | Windows Components | Attachment Manager. You'll find multiple settings on how to process various file types when users attempt to open those files, as shown in Figure 3. As the name of the node suggests, the process that's being managed under the hood is called the "Attachment Manager." The Attachment Manager has some preassigned degrees of risk associated with file types. For instance, .bat, .vbs, and .reg would all be considered "High Risk." Files considered "Low Risk" are those with the .log and .txt extensions. To specify how Windows XP SP2 should handle file types of varying risk, you can use the policy setting named Default Risk Level for file attachments. You can also modify which file types should be considered high, moderate, and low risk using policy settings contained within the same node. If your anti-virus tool can register itself with Windows XP SP2, you can likely use the new "Notify antivirus programs when opening attachments" policy setting, which can tell the antivirus program to take additional action.
Figure 3 Attachment Manager 
To find out more information on the Windows XP SP2 Attachment Manager, read Knowledge Base article 883260, "Description of how the Attachment Manager works in Windows XP Service Pack 2".

Securing Browser Settings
It's no secret that Microsoft Internet Explorer in Windows XP SP2 has enhanced functionality to protect the home, corporate, and academic user. For instance, Internet Explorer now comes with a pop-up blocker, better control for handling ActiveX® add-ins, and other safety features.
Figure 4 Additional Internet Explorer Policy Settings 
Internet Explorer users now have a whopping 619 possible policy settings at their disposal. You'll find most of these settings at Administrative Templates | Windows Components | Internet Explorer | Internet Control Panel | Security Page. Figure 4 shows settings for the Internet Zone. You can also change settings for other zones: Intranet, Trusted Sites, Restricted Sites, Local Machine, and Locked-Down Local Machine. You can easily configure what the behavior should be for the new Internet Explorer features when you're within each zone. For instance, you might want to allow ActiveX downloads while in your intranet zone, but block the download of ActiveX controls when you're visiting a restricted site.

Locating the New Policy Settings
You can locate the new policy settings using the built-in filtering available while editing any GPO. Simply open the Group Policy Object editor, and go to User Configuration | Administrative Templates or Computer Configuration | Administrative Templates and select Filtering on the View menu. Once the Filtering dialog appears, as shown in Figure 5, select Filter by Requirements Information. Next, select which requirements you are interested in, such as "At least Microsoft Windows XP Professional with SP2." Once performed, you can easily see which policy settings are new for this operating system.
Figure 5 Filtering Policy Settings 
Because the text within the Group Policy Object editor is not searchable, I would suggest you download the Excel spreadsheet entitled "Group Policy Settings Reference for .adm Files Included with Windows XP Professional Service Pack 2".
Figure 6 The Group Policy Settings Reference Spreadsheet 
As you can see in Figure 6, this spreadsheet contains all policy settings and is easily configured to display only the new ones. Indeed, this spreadsheet contains worksheets which show just the new settings for regular, registry-based policy settings known as administrative (ADM) templates, as well as security settings (non-registry settings). All policy settings are searchable as well, making this a handy resource if you're looking for a specific policy setting but can't locate it in the Group Policy Object editor.

Conclusion
There are tons of new policy settings to help you control Windows XP SP2, so get out there and make your world even more secure! As with anything new, though, be sure to perform thorough tests on a test lab or small segment of users before rolling out into full production.

Jeremy Moskowitz (www.moskowitz-inc.com) is an MCSE and a Microsoft MVP in Group Policy. Jeremy is the author of Group Policy, Profiles and IntelliMirror (Sybex, 2004) . He runs www.GPanswers.com, a site for group policy information.
© 2008 Microsoft Corporation and CMP Media, LLC. All rights reserved; reproduction in part or in whole without permission is prohibited.
Page view tracker