Re: SBS2003 and Terminal Services....

From: Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa_at_pacbell.net)
Date: 02/20/05


Date: Sun, 20 Feb 2005 15:14:18 -0800

SA loads so low in the TCP stack to not be an issue and protects the box
before the gunk hits there [Steve Riley/Jesper Johansson, Protecting
your Windows Network, Addison Wesley, Preorder now]

I'm NOT wacking off the Enhanced IE protection on a server and allowing
someone to surf like they need to do on IE and get that Domain
controller wacked by malware.

It's not more money dude.... geeze we ASKED Microsoft to be more secure
and then you guys want insecurity back. Nice going how much you care
about the security of your clients.

AND EXCUSE ME this is a family newsgroup and mind your language.

Here is the listing of recommended steps to lock down a TS box
1. Apply the Notssid.inf security template to TS running permissions
compatible with TS users.
2. Use the AppSec tool to limit which applications can be executed.
3. Do not enable remote control.
4. Do not enable application server mode on a domain controllers.
To connect to a terminal server from the network, users must have the
Log On Locally user right assigned. If you implement application server
mode on a domain controller, nonadministrators must be assigned the Log
On Locally user right at the domain controller. Because this user right
is typically assigned in Group Policy, it enables users to log on at the
console of any domain controller in the domain, greatly reducing security.
5. Implement the strongest available form of encryption between the TS
client and server
6. Choose the correct mode for your TS deployment [if you only need
remote administration, the only deploy that]
7. Install the latest service pack and security updates.

Don't want to do #1, nor #2, on our SBS boxes, and we clearly are in
violation of #4.

Page 393-394 Security Resource Kit.



Relevant Pages

  • Re: SBS 2003 and TS-App Mode
    ... It's not secure... ... functionality over security and now you want functionality back. ... open and easy to use...they want TS on a domain controller back. ... Do not enable application server mode on a domain controllers. ...
    (microsoft.public.windows.server.sbs)
  • Re: Microsoft Security & Configuration Tool (MSCT)
    ... > install into the server become problem. ... How to undo the security configuration that I had already applied ... basicsv.inf is the Domain Controller Security Policy, ...
    (microsoft.public.security)
  • Re: Security - Compromised!
    ... policy, no auditing/intrusion detection, etc. So I would say top things are ... to have properly configured firewall (test with external security scanner) ... Changes could have been made at domain or domain controller ... clean it would be time to run dcpromo on your new server. ...
    (microsoft.public.win2000.security)
  • Re: Unable to logon(Critical)
    ... chris made a post then I commented ... > Domain controller security policy also I configured as same ... Event log errors as well, on the client and on the server, and post the ID ...
    (microsoft.public.win2000.active_directory)
  • Re: Client performance problem windows 2003 server...
    ... >Subject: Re: Client performance problem windows 2003 server... ... >Deploying Active Directory for Branch Office Environments ... >results from not having a domain controller in a particular site. ... incorrectly applied site coverage will be bad for clients ...
    (microsoft.public.windows.server.networking)