Protect you computer and your data


Windows Server 2003 Group Policy and Security - 70-291 (Part 2)

Recommended  Group  Policy  Settingsrecommend you audit the failures ofthe rest
of  the  items.
This is by no means a definitive list. We
will make some recommendations to youfor yourComputer Configuration: Windows Settings:
Group Policy settings. This could beSecurity  Settings:  Local  Policies:
considered a starter list. Youshould review
all of the Group Policy settings to see howSecurity  Options
they  fit  in  yourbusiness  requirements.
We recommend you set Accounts: Rename
There are three categories of group policyadministrator account to enabled andrename
settings  underneath  two  broad  groups:the administrator account to something else.
This will help increasesecurity by not giving
Computer Configuration and Usera potential hacker the username at the start.
Configuration.  Inside  those  are  Software
You should also consider setting Interactive
Settings, Windows Settings, andlogon: Do not display last username to
Administrative  Templates.Enabled. This will display a blank username
field at every boot - theuser will be
Policies you apply within Computerresponsible for remembering their username.
Configuration  apply  to  the  whole computerIf someone gains accessto the workstation
physically, they would need to know a
(and all of its users) while settings youusername  to  attempt  tologin.
apply within User Configuration applyto a the
specific  user.Computer Configuration: Administrative
Templates:  Windows  Components
We are offering these as recommendations. You
should review all group policychanges priorThe Administrative Templates section of Group
to  implementation.Policy allows you to set policiesfor the
Windows  operating system and its components.
Computer Configuration: Windows Settings:
Security  Settings:  Account  Policies:Computer Configuration: Administrative
Templates:  Windows  Components:  Internet
Password  Policy
Explorer
Group Policy Objects to Set: Enforce password
history; maximum password age;minimumIf you have a proxy or ISA server, you may
password age, minimum password length;want to set Make proxy settingsper-machine.
Password  must  meet  complexityrequirements.This policy will allow you to set the policy
settings for oneaccount and then every
By default, these policy objects are set. Inaccount that logs in will receive the proxy
our environment, password historyis set to '6settings.
passwords remembered'; maximum password age
is set at 45 days; andminimum password lengthComputer Configuration: Administrative
is  set  to  7  characters.Templates:  Windows  Components:  Internet
There are frequent questions surrounding theInformation  Services
minimum password age of '1 day' andwhy it is
important to have a minimum password age. IfIf you set Prevent IIS installation, you can
a user is forced tochange their passwordprevent rogue IIS servers frompopping up on
every 42 days (as in the default policy), thethe  network.
user couldsimply change their password the
required number of times to get back toComputer Configuration: Administrative
theiroriginal password. To prevent thisTemplates:  Windows  Components:  Windows
security issue, a minimum password age is
setso the user can only change theirMessenger
passwords  once  a  day.
We do not like the Windows Messenger (the MSN
Computer Configuration: Windows Settings:like  instant  messenger  application
Security  Settings:  Account  Policies:
Microsoft installs by default). We enable Do
Account  Lockout  Policynot allow Windows Messenger to berun and Do
not automatically start Windows Messenger
There are three policy settings in thisinitially.
category: account lockout duration;account
lockout threshold; reset account lockoutComputer Configuration: Administrative
counter after. We recommendsetting theTemplates:  Windows  Components:  Windows
Account lockout threshold to '5 invalid login
attempts.' This willautomatically set theUpdate
other  two  settings  to  30  minutes.
If you are using SUS or want the machines to
This setting will lock a user account for 30perform automatic updates, you canconfigure
minutes if there are five invalidloginthose  options  in  this  section.
attempts. This helps stop hackers from using
automated password guessingsoftware on userUser Configuration: Windows Settings:
accounts.Internet  Explorer  Maintenance
Computer Configuration: Windows Settings:There are several configuration options for
Security  Settings:  Local  Policies:Internet Explorer. If you want toforce users
to have the same homepage or options, you can
Audit  Policyconfigure  theseoptions.
There are several security items you canThere are hundreds of policy settings you
audit under the audit policy. To auditincould potentially apply. We recommendcaution
Windows means to record the actions in theand to only apply policies that are
local logs. We recommend you audittheabsolutely necessary - leaving therest as
successes and failures of: account logon"Not Configured." This will make your user
events, account management, logonevents,community much happier.
policy change, and privilege use. We



1 A B C 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 96 97 98 99 100 101 102 103 104 105