Protect you computer and your data


Windows Server 2003 Group Policy and Security - 70-291 (Part 2)

Recommended Group Policy Settingsaccount logon events, account
This is by no means a definitive list.management, logonevents, policy change,
We will make some recommendations toand privilege use. We recommend you
youfor your Group Policy settings. Thisaudit the failures ofthe rest of the
could be considered a starter list.items.
Youshould review all of the Group PolicyComputer Configuration: Windows
settings to see how they fit inSettings: Security Settings: Local
yourbusiness requirements.Policies:
There are three categories of groupSecurity Options
policy settings underneath two broadWe recommend you set Accounts: Rename
groups:administrator account to enabled
Computer Configuration and Userandrename the administrator account to
Configuration. Inside those are Softwaresomething else. This will help
Settings, Windows Settings, andincreasesecurity by not giving a
Administrative Templates.potential hacker the username at the
Policies you apply within Computerstart.
Configuration apply to the wholeYou should also consider setting
computerInteractive logon: Do not display last
(and all of its users) while settingsusername to Enabled. This will display a
you apply within User Configurationblank username field at every boot -
applyto a the specific user.theuser will be responsible for
We are offering these asremembering their username. If someone
recommendations. You should review allgains accessto the workstation
group policychanges prior tophysically, they would need to know a
implementation.username to attempt tologin.
Computer Configuration: WindowsComputer Configuration: Administrative
Settings: Security Settings: AccountTemplates: Windows Components
Policies:The Administrative Templates section of
Password PolicyGroup Policy allows you to set
Group Policy Objects to Set: Enforcepoliciesfor the Windows operating system
password history; maximum passwordand its components.
age;minimum password age, minimumComputer Configuration: Administrative
password length; Password must meetTemplates: Windows Components: Internet
complexityrequirements.Explorer
By default, these policy objects areIf you have a proxy or ISA server, you
set. In our environment, passwordmay want to set Make proxy
historyis set to '6 passwordssettingsper-machine. This policy will
remembered'; maximum password age is setallow you to set the policy settings for
at 45 days; andminimum password lengthoneaccount and then every account that
is set to 7 characters.logs in will receive the proxy settings.
There are frequent questions surroundingComputer Configuration: Administrative
the minimum password age of '1 day'Templates: Windows Components: Internet
andwhy it is important to have a minimumInformation Services
password age. If a user is forcedIf you set Prevent IIS installation, you
tochange their password every 42 dayscan prevent rogue IIS servers
(as in the default policy), the userfrompopping up on the network.
couldsimply change their password theComputer Configuration: Administrative
required number of times to get back toTemplates: Windows Components: Windows
theiroriginal password. To prevent thisMessenger
security issue, a minimum password ageWe do not like the Windows Messenger
is setso the user can only change their(the MSN like instant messenger
passwords once a day.application
Computer Configuration: WindowsMicrosoft installs by default). We
Settings: Security Settings: Accountenable Do not allow Windows Messenger to
Policies:berun and Do not automatically start
Account Lockout PolicyWindows Messenger initially.
There are three policy settings in thisComputer Configuration: Administrative
category: account lockoutTemplates: Windows Components: Windows
duration;account lockout threshold;Update
reset account lockout counter after. WeIf you are using SUS or want the
recommendsetting the Account lockoutmachines to perform automatic updates,
threshold to '5 invalid login attempts.'you canconfigure those options in this
This willautomatically set the other twosection.
settings to 30 minutes.User Configuration: Windows Settings:
This setting will lock a user accountInternet Explorer Maintenance
for 30 minutes if there are fiveThere are several configuration options
invalidlogin attempts. This helps stopfor Internet Explorer. If you want
hackers from using automated passwordtoforce users to have the same homepage
guessingsoftware on user accounts.or options, you can configure
Computer Configuration: Windowstheseoptions.
Settings: Security Settings: LocalThere are hundreds of policy settings
Policies:you could potentially apply. We
Audit Policyrecommendcaution and to only apply
There are several security items you canpolicies that are absolutely necessary -
audit under the audit policy. To auditinleaving therest as "Not Configured."
Windows means to record the actions inThis will make your user community much
the local logs. We recommend youhappier.
auditthe successes and failures of:



1 A B C 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105