Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


February 01, 2008

No More Giving Away the Master Key

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

You might not have heard of the Federal desktop core configuration (FDCC). But its ripple effect might reach you eventually. FDCC settings basically lock down desktops and laptops—eliminating users' administrative rights, disabling vulnerable services, and using the most secure versions of Windows components. (For more info see csrc.nist.gov and checklists.nist.gov.)

By today, Federal agencies have to provide a list to the Office of Management and Budget (OMB) of which desktops are running Windows Vista and Windows XP and whether those desktops are compliant with the FDCC settings. They also have to list which desktops aren’t yet compliant and when they might be. Also, software vendors that supply Windows apps to Federal agencies must show that their apps are FDCC compatible.

What does this mean if you don’t work in a Federal agency?

Well, for one thing, the example of an early adopter of the FDCC settings, the US Air Force, shows the advantages many have long known about standardizing the desktop configuration and limiting user privileges. According to SANS NewsBites, when the Air Force became FDCC compatible, it realized three benefits: few applications were negatively affected by the restriction of user privileges; security patches now took days to install rather than weeks; and user problems reported to the Help desk were less complicated to resolve.

For another thing, you might want to have some help if you’re going to follow the Feds and standardize your desktop configuration.

The Air Force used BeyondTrust Privilege Manager at multiple locations to enforce the standardization of its desktops to FDCC requirements. With Privilege Manager, users are able to log in to Windows without administrative privileges and run or install the applications they’re authorized to. Privilege Manager uses the concept of least privilege, originally developed by the Department of Defense 30 years ago.

“In the Windows world, admin rights is the master key,” says BeyondTrust CEO John Moyer. With least privilege, in contrast, the user is assigned only the rights needed to do the job--instead of the master key, a key to a copy room or the broom closet. However, some applications won't work unless the user has admin rights. BeyondTrust Privilege Manager addresses that problem.

With Privilege Manager, users log in as standard users. When an application’s process starts, Privilege Manager adds an administrative token to the list of security tokens associated with that application’s process that determine what a user can do with the app, so that the process is temporarily elevated (if it needs to be elevated). Privilege Manager uses Group Policy to deliver the rule that says what can and can’t be elevated. Privilege Manager doesn’t touch anything else in the Windows security process. “It’s an elegant solution,” Moyer says.

If you know what apps need admin rights and what don’t, you could implement least privilege using Privilege Manager and be done in weeks, he says. If you don’t know what’s on your network as far as apps and what rights they need, the process might take longer. Moyer says BeyondTrust has a policy monitor utility to discover what apps need what privileges. For more information about BeyondTrust Privilege Manager, go to beyondtrust.com.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.





Search Industry Bytes
 
Industry Bytes
AUGUST 2008
      1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31       
or

 Recently in Industry Bytes
SharePoint Goes to the Olympics
Make a Comment
Recently-Released System Center and MOM 2005 Utility Downloads
Make a Comment
The iPhone 3G Is Cool ... But Will It Blend?
Make a Comment
Microsoft Announces "Second Shot" Offer for IT Certification Exams
Make a Comment
Spam—It Gets Better All the Time
Make a Comment

More blogs about technology,
software, and Windows.

ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Deploying SharePoint! In-Person Event Series – 8 Cities
Discover best practices and tips for deploying the perfect SharePoint infrastructure. Early Bird Price of $99 through Aug 29th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

What’s up with your network? Find out with ipMonitor
Availability monitoring for servers, applications and networks – FREE trial

Agent-less Remote Backup Service, Free 30 Day Trial
Award winning remote backup service at a competitive price with no min GB/month. Sign up Now!

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound
IT Library Technical Resources Directory Connected Home Windows Excavator SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing