RE: tighten security...question for Patrick Rouse

From: Paul Young (anonymous_at_discussions.microsoft.com)
Date: 03/27/04


Date: Sat, 27 Mar 2004 05:17:22 -0800

Patrick,

Thank you for your reply.

This is for a test build of a TS that will shortly be
implemented in a production environment. I am also
following KB278295 for further lockdown. Do not fret, I
am not going to lock out the Administrator account. I am
aware of Authenticated Users needing to be changed to some
security group that I create.

I really appreciate your time ( and your web site ).

Paul

>-----Original Message-----
>Paul, I only recommend making these changes to a new
build or a test system, as they may break programs you've
already installed. I have a base Server OS build that I
use that has these settings, then I relax security on
specific files or directories as needed by specific
applications. Doing this in reverse order may cause
unexpected results.
>
>I use these settings for C:\ & C:\Program Files:
>
>Local Administrators Group, CREATOR OWNER, & System -
Full Control <Not Inherited>(This Folder, Subfolders &
Files)
>Authenticated Users - Read & Execute <Not Inherited>
(This Folder, Subfolders & Files)
>
>********************
>I do NOT, NOT, NOT "Replace permission entries on all
child objects..." which would definitely break the OS.
>********************
>
>Windows 2000 & 2003 have different default permission
sets, where in 2000 Everyone has "Full Control" by
Default, in 2003 this is NOT the default. In my opinion
if Microsoft ever wants to make Windows secure they won't
let you logon interactively with an admin account, i.e.
you'd only be able to use the "Run as" or "Add/Remove
Programs" (which prompts for Administrative credentials)
and the spread of spyware/malware and most viruses would
decrease significantly
>
>Patrick Rouse
>Microsoft MVP - Terminal Server
>http://www.workthin.com
>
> ----- Paul Young wrote: -----
>
> Patrick,
>
> I have seen several of your posts where you share
with the
> NewsGroup how to secure the Terminal Server with
NTFS
> permissions.
>
> You have stated that you lock down the C:\ and the
> C:\Program Files directories with Administrators,
System
> and Creator/Owner ( Full Control ) and Authenticated
Users
> ( Read and Execute ). Assumption is that this is on
a
> Terminal Server running on a WIN2000 Member Server.
>
> I have three questions for you:
>
> A) on the C:\ - are these permissions for This
folder and
> files or for This folder, sub-folders and files?
>
> B) I am sure that the Adminsitrators is the local
> Administrators group. How about the Authenticated
Users
> and System? There is a Domain account (
mydomain\system )
> as well as a local account ( termserv\system ). My
guess
> is that both are the local account.
>
> C) on the C:\Program Files - these permissions would
have
> to be for This folder, sub-folder and files? I
should
> remove the default permissions and manually enter
what you
> have suggested.
>
> Thank you,
>
> Paul
>
>.
>



Relevant Pages

  • Re: Help with configuration
    ... to redirect their My Documents folder to a share on the fileserver. ... GPo, if it is already redirecting by default? ... account profile is blank, also). ... Your GPO settings do not apply to your Terminal Server. ...
    (microsoft.public.windows.terminal_services)
  • Re: Program Problems for non-administrators
    ... The user cant burn CDs because the media player absolutely wont function in her account but switch it to an administrator and all is well. ... User accounts will say they have an older version of a program but the administrators account says everything is up to speed. ... Quite simply, the installation routine for this application doesn't "know" how to handle individual user profiles, or the application tries to make changes to "off-limits" sections of the registry or protected Windows system folders. ... you can make this software available to other users by _copying_ the Start Menu folder and Desktop folder shortcuts from the user profile from which the software was installed in the corresponding folders in the user profilein which you'd like the software to be accessible. ...
    (microsoft.public.windowsxp.general)
  • Re: How to prevent ownership change by users with admin rights?
    ... I also have my private account on the ... > other private account is a member of the "Administrators" group. ... > I have created a private folder on the machine that has its security ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Help with configuration
    ... Users should logon to the workstation using their domain account ... Your GPO settings do not apply to your Terminal Server. ... Folder under "All Users" on the TS. ... local workstation profile, which includes application ...
    (microsoft.public.windows.terminal_services)
  • Blitzed administrator, cant get account back
    ... I've tanked my in-laws computer by creating a guest ... account. ... Console Root folder was empty. ... I can't do a system restore or open the administrators ...
    (microsoft.public.windowsxp.security_admin)

Loading