Server Admin I Unit 8.6 Security Options Flashcards
Security Options
Subset of Group Policy that governs rules for security on computer.
Security Options Settings Categories (4)
- Accounts
- Devices
- Interactive Logon
- Network Security
Best Practices: Security Options: Accounts (3)
- Disable Administrator & Guest account.
- Rename accounts if unable to disable using the “Rename Administrator Account” or “Rename Guest Account” policies.
- Enable “Limit local account use of blank passwords to console logon only” policy.
Best Practices: Security Options: Interactive Logon (6)
- Disable: Display user information when session is locked.
- Enable: Do not display last user name.
- Disable: Do not require CTRL-ALT-DEL.
- Use: Message text for users attempting to log on.
- Enable: Prompt user to change password before expiration.
- Enable: Require Smart Card.
Best Practices: Security Options: Network Security (2)
- Enable: Force log off when logon hours expire.
2. Disable: Allow system to be shut down without having to log on.
User Account Control
UAC; System that insures that actions which affect the system configuration are approved by users with the necessary rights to perform those actions.
How to enable User Account Control
Enable “Run all adminstrators in Admin Approval Mode”
How many access tokens do Administrators get?
2; One Standard and One Administrator
User Account Control Settings in Control Panel (4)
- Always Notify
- Notify me only when programs try to make changes to my computer.
- Notify me when programs try to make changes to my computer ( do not dim the desktop).
- Never Notify
Secure Desktop
System that pauses all programs and darkens screen while displaying prompt for credentials or prompt for consent.
How long will Secure Desktop display on screen?
150 seconds, after 150 seconds the prompt for consent/credentials is automatically denied.
Never Notify UAC Setting Rules(2)
- If logged on as Admin, all actions are executed without UAC prompts or Secure Desktop.
- If logged on as a standard user, all actions requiring priviledge elevation are automatically denied.
Group Policy Equivalant for : Always Notify
- Behavior of the elevation prompt for administrators in Admin Approval Mode is set to : Prompt for consent on the secure desktop.
- User Account Control: Switch to the secure desktop when prompting for elevation is : Enabled.
Group Policy Equivalent for : Notify me only when programs try to make changes to my computer.
- Behavior of the elevation prompt for administrators in Admin Approval Mode is set to: Prompt for consent from non-Windows binaries.
- User Account Control: Switch to secure desktop when prompting for elevation is : Enabled.
Group Policy Equivalent for: Notify me only when programs try to make changes to my computer.(do not dim desktop)
- Behavior of the elevation prompt for administrators in Admin Approval Mode is set to: Prompt for consent from non-Windows binaries.
- User Account Control: Switch to secure desktop when prompting for elevation is : Disabled.
- Behavior of the elevation prompt for standard users is set to: Prompt for credentials.