Security Configuration Editor versus Wizard for 2003 policy

From: Marco Shaw (marco_at_Znbnet.nb.ca)
Date: 09/26/05


Date: Mon, 26 Sep 2005 10:59:23 -0300

Writing up a new security policy for 2003 servers. 2003SP1 comes with SCW,
but there's the SCE (since 2000SP4) out there too. I realize they both do
some different things.

SCE is a bit less user-friendly than SCW which comes with a nice wizard.

These days, what are the risks of having run only SCW on a Windows 2003 web
server? Should I still run one of the 'high security' .inf templates from
SCE on these systems for a 'best effort' against break-ins?

I can't remember the last time we've had a Windows break in, since a trojan
management to get onto a unsecured NT4 box a few years ago.

Marco



Relevant Pages

  • Re: Issues with Windows Server 2003 SP1
    ... Actually I don't know how that can be, because the security policy I made ... with SCW was not applied, because it produced "Unspecified error" every time ... >> installation problems with DNS resolvement started. ...
    (microsoft.public.windows.server.general)
  • Re: Corporate Antivirus
    ... workstations and servers - not the group ware or client ware versions. ... I have found issues with SCE 10.2 on Windows 2003 Servers where profiles ... Calling an illegal alien an "undocumented worker" is like calling a ...
    (microsoft.public.security.virus)
  • Re: MS System Center Essentials 2007
    ... I just got this SMS duties and my Manager wanted to go with SCE 2007, ... bcuz it has options to monitor 30 servers. ... new box where we are installing MS Windows 2008. ...
    (microsoft.public.sms.admin)
  • Re: After installing SCW Exchange failed to start on reboot
    ... If after rolling back the problem is gone, than you are certain its the SCW. ... careful how you configure the security policy so as to avoid getting the ... Also have errors with CLSID codes that are not in ...
    (microsoft.public.exchange2000.general)
  • Re: Server Managament
    ... Or to put it another way, what makes you think SCE is to blame as opposed to a configuration error on those system that is preventing them from reporting back and would likely prevent other tools from working as well? ... I would suggest you explore your firewall settings and verify that WMI is reachable on the machines that aren't reporting back. ... MarcusB wrote: ... I am one system administrator working with 25 servers and 500 clients machines. ...
    (microsoft.public.windows.server.general)