Windows Server 2003 Group Policy and Security - 70-291 (Part 2)

Recommended Group Policy Settingsevents, account management, logonevents, policy
This is by no means a definitive list. We will makechange, and privilege use. We recommend you audit
some recommendations to youfor your Group Policythe failures ofthe rest of the items.
settings. This could be considered a starter list.Computer Configuration: Windows Settings: Security
Youshould review all of the Group Policy settings toSettings: Local Policies:
see how they fit in yourbusiness requirements.Security Options
There are three categories of group policy settingsWe recommend you set Accounts: Rename
underneath two broad groups:administrator account to enabled andrename the
Computer Configuration and User Configuration. Insideadministrator account to something else. This will help
those are Softwareincreasesecurity by not giving a potential hacker the
Settings, Windows Settings, and Administrativeusername at the start.
Templates.You should also consider setting Interactive logon: Do
Policies you apply within Computer Configuration applynot display last username to Enabled. This will display a
to the whole computerblank username field at every boot - theuser will be
(and all of its users) while settings you apply withinresponsible for remembering their username. If
User Configuration applyto a the specific user.someone gains accessto the workstation physically,
We are offering these as recommendations. Youthey would need to know a username to attempt
should review all group policychanges prior totologin.
implementation.Computer Configuration: Administrative Templates:
Computer Configuration: Windows Settings: SecurityWindows Components
Settings: Account Policies:The Administrative Templates section of Group Policy
Password Policyallows you to set policiesfor the Windows operating
Group Policy Objects to Set: Enforce passwordsystem and its components.
history; maximum password age;minimum passwordComputer Configuration: Administrative Templates:
age, minimum password length; Password must meetWindows Components: Internet
complexityrequirements.Explorer
By default, these policy objects are set. In ourIf you have a proxy or ISA server, you may want to
environment, password historyis set to '6 passwordsset Make proxy settingsper-machine. This policy will
remembered'; maximum password age is set at 45allow you to set the policy settings for oneaccount and
days; andminimum password length is set to 7then every account that logs in will receive the proxy
characters.settings.
There are frequent questions surrounding the minimumComputer Configuration: Administrative Templates:
password age of '1 day' andwhy it is important to haveWindows Components: Internet
a minimum password age. If a user is forced tochangeInformation Services
their password every 42 days (as in the default policy),If you set Prevent IIS installation, you can prevent
the user couldsimply change their password therogue IIS servers frompopping up on the network.
required number of times to get back to theiroriginalComputer Configuration: Administrative Templates:
password. To prevent this security issue, a minimumWindows Components: Windows
password age is setso the user can only change theirMessenger
passwords once a day.We do not like the Windows Messenger (the MSN like
Computer Configuration: Windows Settings: Securityinstant messenger application
Settings: Account Policies:Microsoft installs by default). We enable Do not allow
Account Lockout PolicyWindows Messenger to berun and Do not
There are three policy settings in this category:automatically start Windows Messenger initially.
account lockout duration;account lockout threshold;Computer Configuration: Administrative Templates:
reset account lockout counter after. WeWindows Components: Windows
recommendsetting the Account lockout threshold to '5Update
invalid login attempts.' This willautomatically set theIf you are using SUS or want the machines to perform
other two settings to 30 minutes.automatic updates, you canconfigure those options in
This setting will lock a user account for 30 minutes ifthis section.
there are five invalidlogin attempts. This helps stopUser Configuration: Windows Settings: Internet Explorer
hackers from using automated passwordMaintenance
guessingsoftware on user accounts.There are several configuration options for Internet
Computer Configuration: Windows Settings: SecurityExplorer. If you want toforce users to have the same
Settings: Local Policies:homepage or options, you can configure theseoptions.
Audit PolicyThere are hundreds of policy settings you could
There are several security items you can audit underpotentially apply. We recommendcaution and to only
the audit policy. To auditin Windows means to recordapply policies that are absolutely necessary - leaving
the actions in the local logs. We recommend youtherest as "Not Configured." This will make your user
auditthe successes and failures of: account logoncommunity much happier.