Re: Hardening Member Servers

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 05/27/05


Date: Thu, 26 May 2005 18:08:31 -0500

You could put those servers into an OU with it's own GPO and then configure
the user right for logon locally to contain only the groups/users that you
want to be able to logon to locally. Be very careful with security templates
and test them out thoroughly first on a test network or at least test OU as
too extreme security settings can break access that you want to have. Also
ipsec can be used to control access to your servers requiring that the
computer trying to access needs to authenticate with it via kerberos and be
compatible with it's ipsec policy. Ipsec policies need to be thoroughly
tested before implementing and domain controllers must be exempt from ipsec
ESP/AH traffic with domain members. --- Steve

"Rob" <Rob@discussions.microsoft.com> wrote in message
news:B23DB4AF-C391-4651-9482-82091B1B29DA@microsoft.com...
> Hello,
>
> I want to prevent unauthorized access to the member servers on our domain.
> I
> know windows 2k has some built in security templates but is there a good
> site
> or something for this info or better templates? I want to make sure only
> authorized users can logon locally etc. Any help is greatly appreciated.
>
> Thanks
>
> --
> Rob
> IT guy!



Relevant Pages

  • Re: Securing Communication Between Domain Members and their Domain Controllers
    ... look into using an ipsec tunnel into a gateway computer or ipsec endpoint device or ... > located stand alone servers. ... > integrte them into a single secure Active Directory Domain. ... > member servers to communicate this way, looking through the MS tech. support ...
    (microsoft.public.win2000.security)
  • Win2003 Servers hidden from Network Browse list when using IPSec
    ... computers in that OU to use IPSec. ... in the Domain Controllers OU, and are exempted completely from IPSec, ... IPSec where they are supposed to, and all show up in the Network ... My Windows 2003 Servers (member servers, ...
    (microsoft.public.windows.server.security)
  • OU GPO Corrupts 2003 Servers only??
    ... I setup a GPO on the Servers OU and began moving servers into it a ... connectivity to it, so I brought up the remote console through the iLo ... First error msg in the System eventlog was for IPSec. ... inbound and outbound TCP/IP network traffic that is not permitted by ...
    (microsoft.public.windows.group_policy)
  • Re: Preventing users from c onnecting to shares NOT on the domain..
    ... Are servers on same subnet as clients? ... Yes Kerberos is domain wide but IPSec policy can be OU, ... If you require this computers to communicate with other ... >> and your clients will not want to talk to them. ...
    (microsoft.public.win2000.security)
  • Re: Preventing users from c onnecting to shares NOT on the domain..
    ... Are servers on same subnet as clients? ... Yes Kerberos is domain wide but IPSec policy can be OU, ... If you require this computers to communicate with other ... >> and your clients will not want to talk to them. ...
    (microsoft.public.win2000.networking)