| IT Archive |
| Facilities Archive |
| Design Archive |
| Press Release Archive |
| Glossary |
| White Papers |
| What is a Data Center |
| Calculators |
| Standards |
| Poll Results |
| DataCenter.TV |
| Newsletter Subscribe |
| Analysts |
| Conference Providers |
| Trade Organizations |
| Tips for Making the Most of Longhorn’s Top Five Security Features: Deploying Windows Server 2008 |
|
|
| Written by Rich Getteau | |
| Wednesday, 11 June 2008 | |
|
With the release of Windows Server 2008 (WS08), code-named Longhorn, Microsoft has included a wealth of new features and added numerous enhancements. This particular update to Microsoft’s server operating system is an important one – mostly due to its improved security and improved remote manageability. There are five new security features that truly stand out above the rest, and of course, there are tricks to making the most of these in a functional IT environment.
#1 – Server Core
Before you go all out and start firing up Server Core installs, you should be aware of some Server Core restrictions. The first thing to note is that there is no Explorer shell with Server Core, only a command prompt. So if you are going to install an application or configure a setting, you should brush up on your scripting. Secondly, you cannot upgrade a machine to a server core install, so you will need to come up with another plan if you want to do an in-place upgrade of your 2003 file servers to the 2008 File Services role. Finally, since there is no Explorer shell, you will need to test your various management applications to see if they still install/run on Server Core. On the bright side, you can still use Remote Desktop Protocol (RDP) to connect to a Server Core box and you can still manage your applications remotely with Microsoft Management Consoles (MMCs). #2 – Read Only Domain Controller
Microsoft has addressed these concerns in WS08 with the Read Only Domain Controller (RDOC)/Read Only DNS Server. RDOCs are DCs that only contain the passwords for people at the remote location and, if configured as a DNS server, have a read-only copy of the DNS directory partitions. This way, if the server is ever stolen or compromised, the only passwords someone can get from the AD database are the passwords for the local users. A second feature of an RDOC is that it gives IT the ability to delegate administrative privileges for a particular server to the application owners without giving them the rights to modify the domain. To use RODCs, the domain/forest must be in Server 2003 mode, you must run the adprep command with the /rodcprep and the Primary Domain Controller (PDC) emulator for the domain must be running Server 2008. Once those requirements are met, you can deploy RODCs and make your remote/branch offices more secure. #3 – Bit Locker
To enable Bit Locker, your machine must have a Trusted Platform Module (TPM) installed at the hardware level. TPM allows the OS to do the integrity checks on the boot files as the OS starts-up. If your hardware does not support TPM, you can also store the encryption keys on a USB flash drive. Finally, you must have a separate, unencrypted, active/system partition for the WS08 boot files. Should you ever lose a server and need to recover the data after you install Bit Locker, Bit Locker requires that you provide a recover password during installation. If needed, the recovery password can also be stored in AD. When you combine Bit Locker with the other branch office solutions like RODCs, you increase your flexibility in unsecured remote locations. #4 – Password Policy Changes
Eventually I was able to show them that their new policy only affected the local user IDs on the computers in that OU and didn’t do anything for the AD user accounts. To get around this limitation, some companies set up multiple AD domains so they could vary the password options or they used complex password filters or even worse, they would turn off their password policies long enough to reset a password to something that wouldn’t work with the standard password policy. After years of asking, Microsoft finally gave us the ability to run multiple password policies. Now you can have that long, complex password policy for the end users and a short, non-complex password policy for the legacy applications. Unfortunately, setting the varying password policies is not as simple as creating a new GPO and applying it to your users. To create multiple password policies in WS08, the domain must be at WS08 functional level and you must be in the Domain Admins group. If you meet those requirements, you can create the Password Setting Objects (PSOs) in the directory. Once the PSO has been created and you have assigned a precedence value to it, you can link that PSO to global groups or user IDs in the domain. #5 – Active Directory Rights Management Services
In WS08, AD RMS comes with the OS and you can add it as a server role. It also gives you the ability to manage the RMS installation through an MMC interface versus the management website of the past. Since it supports Federation with Active Directory Federation Services (ADFS), companies can share protected documents amongst their federated partners. ADFS must, however, be setup before AD RMS and you must use the Vista RMS client or the RMS SP2 client. Additionally, installation is now easier because the AD RMS servers can “self sign” their server licensor certificate (SLC) rather than contacting Microsoft to get the SLC assigned. Delegated administration has been greatly improved with the addition of four new AD RMS groups that have different permissions based on the specific role being performed. Unfortunately, mobile devices still have issues with AD RMS if they are not running on Windows Mobile 6 and third party application support is still an issue without third party add-ons. The theme for Microsoft’s recent Windows Server 2008 launch in Los Angeles was “Heroes Happen {Here},” and assuring that the WS08 is deployed effectively with the security features mentioned will allow any IT organization to become the “hero” of their enterprise. To find our more information on any of the topics mentioned above, visit the Windows Server 2008 Reviews Guide and Microsoft TechNet. Both sources can provide full accounts of the new and improved features and functionality. About the Author: Rich Getteau is NetIQ's Domain Expert on Windows, AD and Messaging
Set as favorite
Bookmark
Hits: 899 Comments
(1)
You must be logged in to a comment. Please register if you do not have an account yet.
|
| Thu, Jan 21st, 2010, @5:30pm |
| Fri, Jan 29th, 2010, @8:00am |
| Thu, Feb 4th, 2010, @8:00am |
| Tue, Feb 23rd, 2010, @8:00am |
| Tue, Feb 23rd, 2010, @8:00am |
| Sun, Mar 7th, 2010, @8:00am |
| Thu, Mar 11th, 2010, @8:00am |
| Tue, Mar 23rd, 2010, @8:00am |