Visitors to VTC.com will be able to view all introductory videos for each training course.
Free Trial Members will gain access to first three chapters for each training course.
Full Access Members have full access to VTC.com�s entire library of video tutorials.
There are many ways that we could apply the security templates settings. We can apply them through group policy by importing a policy. We will take a look at that later on. But the recommended way to apply these templates is to use the security configuration and an analysis tool. The reason that we should use this tool is that after we have applied it then we can compare the settings. We can make sure that we got what we expected to get. We do a quick comparison on a ** comparing one computer with another, only both computers are in the same computer comparing the current computer settings against a database, and then we are making sure that the changes that we think we made are the changes that we are making. So make all this sense let us go into the tools. What we are going to do is, let us go to console 1 and we are going to add another snap-in. So we are going to click on file and then add a new snap-in and then click on add, and then we are going to go down in alphabetical order in the list of snap-ins and we are going to get security configuration and analysis. We click on ok. Now, our security configuration and analysis is a tool that allows us to create a database and use that database to configure the computer or to make comparison. So the first thing we are going to do is we are going to configure this computer for high security domain controller. And the second thing we are going to do is, we are going to compare high security domain controller against my template that builds security sect. So I am going to right click on security configuration and analysis and click on open database and then we are going to call this high sect DC database. so I type high sect DC and press enter or click open. It say ok, what template did you want to use? So we say we are going to use high sect DC template and click on open, and it says ok well that is the database I have loaded now. Now what do you want to do with it? So we are going to right click on security configuration and analysis and we are going to configure computer now. It says ok, well while I do this if I have any errors I will put them write here; is that ok? So that is fine. It is going to show us on in GUI anyway. Click on ok and it quickly configures the computer with our settings. So now the computer is configured for high security domain controller. Let us take a look at what High security domain controller should be configured for. So I will click this high security domain controller template just for comparison say 24 password remembered maximum, password age 42 days minimum password age 2 days, and then we will take a look at what we are auditing, look at the audit policy, we are auditing everything except for auditing process tracking. So now let us late a look at what Bill's secure DC does. With password policies we got 10 passwords remembered maximum password age 42 days minimum password age 2 days. Since the password remembered is less if we look at the account policies. Account policies, are the same look is we look at audit policies are auditing less only auditing failure on directory services accounts, we are not auditing at all as far as for objects access. Notice these differences in order to see every single difference how in the world we will be able to do that. We will have to go through fine tooth comb. Well, the system can go through a fine tooth comb forced. What we are going to do now, close up security templates, we are going to right click on security configuration analysis and now we are going to click on open database. And this time we are going to call it Bill's secure DC. I can call it something else but it just makes it easier to call it the same thing as what the template is. I am going to use Bill secure DC template. Now that I click on open. Now what the system is doing it is loading the database and what we can do is we can analyze the current computer settings against the database. So currently the computer is set for high security domain controller. When we analyze it against the database of secure DC, so let us click on analyze computer now and click ok. It say ok, I am going to do that and If I have any errors I am going put them, that is fine, I will click on Ok. Now, if we open each of these we should be able to see what the system went through in compare with the fine tooth comb. So password policies 24 password remembered against that database, against that Bill's secure DC, high domain security controller is much better. Account lockout duration 30 minutes is computer database base setting but the computer is only set to zero. If we look at local policies, when we look at audit policy we can see that the differences show because the system is comparing against the database setting. But database settings being there is only failure audit it is for directory services access and computer setting is success and failure. So basically the same look. This may not be a problem, but it is a difference. But the in same token we could load in the Bill's secure DC into the computer and then compare it against the high security domain controller. What the system would do is to make thing stand out that might be a problem as there will be differences between database setting and computer setting. So that is the purpose of the tool, the security configuration and analysis tool. And this is the tool we should use to apply and to test security templates. As we said it also possible to do this through the group policy and how we decide to do it depends on a particular environment but you should know about this tool for the test. Another thing we should know about the test is the Principles of auditing. So in our next section we are going to talk about audit policy and about auditing in general. That is next.
| Course: | Microsoft Windows Server 2003 (70-290) |
| Author: | Bill Ferguson/Certified Instructor |
| SKU: | 33497 |
| ISBN: | 1932072918 |
| Release Date: | 2004-06-03 |
| Duration: | 8.5 hrs / 107 lessons |
| Captions: | No |
| Compatibility: |
Vista/XP/2000, OS X, Linux QuickTime 7, Flash 8 |