Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

36
Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature

Transcript of Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Page 1: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Auditing Microsoft Active Directory

Eric Dugger

Network Services Manager

Nevada Legislature

Page 2: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

What is Active Directory

A central component of the Windows platform, Active Directory directory service provides the means to manage the identities and relationships that make up network environments.

Resources – Computers & Printers

Services – E-Mail, Policies, DNS, etc.

Users – Accounts and security groups

Page 3: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.
Page 4: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Primary Items of Importance

Business Continuity •Is Active Directory backed up?•Are there multiple Domain Controllers?

Security•Who has access to change Active Directory?•What settings in Active Directory affect security? (passwords, etc.)

Policies•What environment is created from AD Polices?

Page 5: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Business Continuity

Active Directory Backups – Critical Data•How often?•Where are they stored?see Backing up an Active Directory Server doc

Multiple Domain Controllers•Should have the global catalogshow where in Sites and Services

Page 6: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Questions

Page 7: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Active Directory Security

Who can access Active Directory?

What can they change?

Is auditing turned on for Active Directory?

Page 8: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Access to Active Directory

Active Directory Boundaries

Physical Security

Domain Forests & Trusts

Page 9: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Permissions to Change AD

Enterprise AdminsSchema AdminsAdministratorsDomain AdminsServer OperatorsAccount OperatorsBackup OperatorsDS Restore Mode Administrator

Groups of Interest

Page 10: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Questions

Page 11: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Group Policyin Microsoft Windows Active Directory

Page 12: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

What is Active Directory Group Policy?

The Group Policy management solution in Microsoft® Windows Server™ 2003 allows administrators to define configurations for both servers and user machines. Local policy settings can be applied to all machines, and for those that are part of a domain, an administrator can use Group Policy to set policies that apply across a given site, domain, or range of organizational units (OUs) in the Active Directory® directory service. Support for Group Policy is available on machines running Microsoft Windows 2000 Server, Microsoft Windows 2000 Professional, Microsoft Windows® XP Professional, and Windows Server 2003.

Page 13: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Overview

Control Internet Explorer Settings Control Computer/User Settings Software Distribution Windows Updates Much, Much More…..

Page 14: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Getting Started

Windows 2003 Active Directory

Group Policy Manager Plug-in

Page 15: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Creating a Policy

Choose an Organizational Unit

Create and Link GPO

Page 16: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Assigning a Policy

Policies Linked to this OU

Policies Inherited to this OU

Delegation of this OU

Page 17: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Defining Internet Explorer

Control the Functionality of IE Plug-Ins Menus Empty Temp Folder

Control the Security of IE Active X .NET Block Sites

Page 18: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Configuring an IE Policy

Define your Zones Internet Intranet Trusted Restricted

Define your Settings Apply Policy to an OU

ZONES

1 – Intranet

2 – Trusted

3 – Internet

4 - Restricted

Page 19: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Control User/Computer Settings Configure the Desktop

Hide icons/menus Dictate wallpaper

Control Software Installation or Use Prohibit software from being installed or uninstalled Prohibit software from being run

Lockdown Administrator Functions Network or security settings

Configure Windows Firewall

Page 20: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Configure a Desktop Policy

Page 21: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Software Distribution

Automatically Install Software at Logon Publish Software Remove Software Update Software

Page 22: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Configure a Software Install Policy

Install a Software Package on Logon The software will be installed when the user logs

on Publish a Software Package

The software will be available through “Add/Remove Programs”

Redeploy a Software Package The package will be redeployed (Update or New

Version) Uninstall a Software Package

The software will be removed

Install Path to MSI File

Page 23: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Managing Windows Updates

Create a policy to use the Windows Update Services server Assign WSUS Server Assign WSUS Groups

Install and Configure WSUS

Page 24: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Windows System Update Server

Updates for Windows, Office, Exchange Server, and SQL Server, with additional product support over time

Automatic download of specific updates Automated actions for updates, determined by

administrator approval Ability to determine the applicability of updates before

installing them Targeting Reporting

Page 25: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

How WSUS Works

Downloads selected updates to central update server

Release updates to specified groups

Report on status of updates

Page 26: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Computer Name Operating SystemLast Status ReportComputer Group

Page 27: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Update Name Update TypeRelease DateApproval

Install

Detect only

Not Approved

Page 28: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

ReportingComputer Name

Status Type

InstalledNeededNot NeededUnknownFailedLast Updated

Update Title

Page 29: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Questions

Page 30: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Tools

GPResultAdmxGroup Policy Manager

Page 31: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.
Page 32: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

True Last Logonhttp://www.dovestones.com/products/True_Last_Logon.asp

Page 33: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

What AD Policies am I getting?

Open a command windowType gpresult

GPRESULT

Page 34: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Export Group Policy Settings

AdmX.exe: ADM File ParserCategoryThe ADM File Parser (AdmX) is a command-line tool that enables an administrator to export Group Policy settings to a tab-delimited text file. The administrator can then use the text produced by ADM File Parser (AdmX) to find changes for the policy settings between different versions of the operating systems. AdmX is for use only with policies based on administrative templates.

Version compatibilityThe AdmX.exe tool runs on Windows 2000, Windows Server 2003, and Windows XP Professional. AdmX.exe also requires the Microsoft .NET Framework 1.0.

Page 35: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Group Policy Manager

Page 36: Auditing Microsoft Active Directory Eric Dugger Network Services Manager Nevada Legislature.

Questions