官术网_书友最值得收藏!

Baseline Security

To ensure the same level of security in your AD-throughout your organization, you need to have a security baseline for your AD and your Domain Controllers (DC). Whilst the security baseline has to be in line with your organizational security policy, there are several things that you should consider implementing.

Domain Policy

The default Domain Security Policy contains default values that are quite relaxed for most organizations. You should definitely change some of them.

As per Microsoft's recommendations (see: http://technet2.microsoft.com/windowsserver/en/library/cae0e49c-7929-4c94-be3a-ea6a63f09b6e1033.mspx for more information), you should at least change the password policy, the Account Lockout Policy, and the Kerberos Policy, all of which can be found in the Default Domain Security Settings under Account Policies, as shown in the following screenshot:

Domain Policy

Strengthening an AD through password and Kerberos settings might not seem directly related. However, with proper password, lockout, and expiry settings, you can impair brute force cracking quite a bit, and therefore prevent administrative access to your AD by unauthorized people.

Domain Controller Security Policy

In order to maintain a unified and strong AD, every DC should have the same security settings and much of the same configurations. Having multiple vendor servers acting as DCs is an acceptable risk factor (considering the fact that you have to trust multiple drivers in different scenarios). But you should always choose to use the latest stable drivers — which does not mean necessarily the newest ones, from your chosen vendor, in each location.

Another thing to ensure is that all DCs should have the same patch level and the same Service Pack level throughout your domain. This ensures that no new features are available on some DCs but others, and you won't run the risk of either incompatibility, or other errors appearing in your Event Logs.

The Microsoft Windows 2003 Security guide, Chapter 5 (http://www.microsoft.com/technet/security/prodtech/windowsserver2003/w2003hg/s3sgch05.mspx), shows the recommended settings for policies, specifically for DCs, and you may want to use some of these, whilst adjusting others to suit your needs.

主站蜘蛛池模板: 施秉县| 定兴县| 稻城县| 香格里拉县| 洛浦县| 霍城县| 上林县| 开平市| 东山县| 隆子县| 济南市| 彰化县| 常德市| 河北区| 武宁县| 平陆县| 鹰潭市| 洛宁县| 赤水市| 东港市| 常德市| 黄梅县| 华坪县| 乃东县| 高雄县| 三原县| 新晃| 通榆县| 灵璧县| 新兴县| 临桂县| 长汀县| 壶关县| 广灵县| 胶南市| 晋城| 镇远县| 恩平市| 阜新市| 务川| 潍坊市|