Re: General Group policy security question



One important thing to note is that if the network has to be really secure
it has to be a separate forest and not just a separate domain within the
same forest.

>From the Group Policy side, some good reading for you will be the Threats &
Countermeasures guide which include a bunch of extra GPO settings from MSS
that can tighten your DC builds.

Also be sure to configure the 'wait for network' settings so policy can't be
bypassed by pulling out the network cable just after logon!

http://www.microsoft.com/downloads/details.aspx?FamilyId=1B6ACF93-147A-4481-9346-F93A4081EEA8&displaylang=en

"Angryblack" <Angryblack@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:CCD72719-F88C-439A-8172-95343E8EBCFB@xxxxxxxxxxxxxxxx
>I am just sounding some info to see what responses I will receive. My
> company is creating a separate secure network for a project. With an
> emphasis on secure it's my task to create the ad infrastructure. I know
> the
> basics to lock down an ad environment (have been doing this for a few
> years)
> What I wanted to know is there anyone out there that has something similar
> and can share some experiences, especially working with group policy. The
> server will be 2003 and the workstations will be xp. Is there anything
> you
> guys think I should consider or just pay special attention to?


.



Relevant Pages

  • Academic Domains in Non Academic Forest?
    ... We have a kid's room at the office in which we want to put a separate ... network run on an academic version of Win2003 for the domain. ... or will we need to make it a separate forest? ... Prev by Date: ...
    (microsoft.public.windows.server.active_directory)
  • Re: What security package for SBS?
    ... I have a secure Windows network. ... I also have a secure MacMini and on occasion a secure Ubuntu. ... With a business class firewall stripping crap off all incoming traffic and properly implemented security policies in addition to giving your users absolutely no admin rights, there is no reason to believe you can't create a secure Microsoft Network. ...
    (microsoft.public.windows.server.sbs)
  • Re: Wifi Security
    ... Then add in good practices and secure those endpoints! ... I have changed the security to WPA2 with a 128bit ... and attempt to break into her wireless internet connection. ... part of her network cannot do WPA2 but you actually want her network to ...
    (microsoft.public.security)
  • RE: One computer two different networks
    ... Internet connection and one an internal secure connection tempts one ... You have a private network with no Internet for the reason that you ... in Information Security. ...
    (Security-Basics)
  • RE: Secure Network Design (DMZ, LAN, etc)
    ... You can't have separate subnets separated by a switch. ... is only because the firewall is going to be doing NAT in addition to ... > Subject: Re: Secure Network Design ...
    (Security-Basics)

Loading