Re: Controlling server security -- to domain or not to domain?

From: S. Pidgorny (slavickp_at_yahoo.com)
Date: 12/11/03


Date: Thu, 11 Dec 2003 18:45:31 +1100

Definitely domain GPOs. Integration is better for management and isn't
compromising security, as securing domain - and maintaining security - will
be easier for one entity than for 25.

-- 
Svyatoslav Pidgorny, MVP, MCSE
-= F1 is the key =-
"sP" <littlechild_zu@yahoo.com> wrote in message
news:023f01c3be76$413b0070$a101280a@phx.gbl...
> I'm looking for a best practice.
>
> I have about 25 windows 2000 servers that I have been told
> to secure. They range from domain controllers, file/print,
> citrix, sqlservers and domino.
>
> What is the best practice to control group policy settings
> on these servers? Should I leave them off the domain and
> set them through local GP? Or is it better to add these
> servers to the domain and control group policy through
> Active Directory.
>
> The "do it the easy way" part of me says to add them to
> the domain and control the servers through active
> directory. This would allow me to secure and update the
> servers much more easily.
>
> However, the "keep it secure as possible" part of me says
> to keep servers off the domain that don't need to be. This
> would be a bit more work but makes since.
>
> Can anyone give any thoughts on this matter? Is my
> thinking wrong?


Relevant Pages

  • Re: [fw-wiz] I wonder, how to test..
    ... >responsible for security at our company, ... >of my head make me wonder how secure it all is. ... Internally locking down the servers: ... administrator's privileges if he managed to execute code with webserver ...
    (Firewall-Wizards)
  • Re: Anyone hear of ANSA (Asp.Net Security Analyser)??
    ... you if your servers that provide Asp.Net shared hosting ... ANSA (Asp.Net Security Analyser) is not a commercial ... results will tell us if your servers are secure or not. ...
    (comp.security.misc)
  • Re: How secure is software X?
    ... in my opinion a software can either be secure or not secure. ... to classify security like that would be to condemn every ... How in-depth a fuzzing to we apply for this standard? ... For example, SMTP servers have a pretty standard interface, ...
    (Bugtraq)
  • Re: How to access I/O port directly in VC6.0?
    ... several multinationals, worked with the research division in one case, and ... Their "security" as far as servers was a joke; ... servers, which WERE secure, including VPN access, but the corporate ...
    (microsoft.public.vc.mfc)
  • Ensuring that a sever and website are secure
    ... we would like to be as sure as possible that the servers and data on ... them are secure before we launch this service. ... Several people have recommended having a security audit done once our ... technical staff believe the website and servers are secure. ...
    (comp.security.misc)