Click here to get back home

Role-based security from Windows Server 2003 Security Guide gives problems

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Role-based security from Windows Server 2003 Security Guide gives problems Mikael Oskarsson 11-06-2006
Get Chitika Premium
Posted by Mikael Oskarsson on November 6, 2006, 8:00 am
Please log in for more thread options
Hello


I have an Ad-environment with 2 Windows 2003 SP1 eng server and some Windows
2003 SP1 eng member server.
I have applied some EC-server policy from Microsoft document from april
2006.


On Domain root I have applied EC-Domain.inf
On Domain Controller OU I have applied EC-Domain Controller.inf
On Member Server OU I have applied EC-Member Server Baseline.inf
On sub OU Web OU I have applied EC-IIS server.inf

I joined 2 new web-servers to the domain and put them in the default
Computer OU. Lets call them lt104 and lt135 as servername.

Now my problems starts

If I from DC run My Computer > Manage > Connect to another computer, select
server104 see errors in word file.

If I from a member server that lies in Web OU run MBSA against all server
in the domain I get errors from scanning lt104 se word file

If I move the server lt104 to Web OU, none of the above errors occur. But
the server lt104 needs to connect to a standalone server to get picture and
I cant connect to that standalone server if lt104 is in the Web OU but it
works if it lies in Computer OU.


Any ideers whats causing this problem

Regards

Mikael




Posted by Roger Abell [MVP] on November 10, 2006, 5:07 am
Please log in for more thread options
> Hello
>

Hi

>
> I have an Ad-environment with 2 Windows 2003 SP1 eng server and some
> Windows
> 2003 SP1 eng member server.
> I have applied some EC-server policy from Microsoft document from april
> 2006.
>

The templates only, or the settings from non-templated guidance also ?
You are aware (?) the templates are suggested settings to serve as starting
points for making working templates for a specific deployed infrastructure?

>
> On Domain root I have applied EC-Domain.inf
> On Domain Controller OU I have applied EC-Domain Controller.inf
> On Member Server OU I have applied EC-Member Server Baseline.inf
> On sub OU Web OU I have applied EC-IIS server.inf
>

Sensible. However, you could benefit by integrating some settings
from Bastion, particularly for Member, and sub-Member OUs.

> I joined 2 new web-servers to the domain and put them in the default
> Computer OU. Lets call them lt104 and lt135 as servername.
>
> Now my problems starts
>
> If I from DC run My Computer > Manage > Connect to another computer,
> select
> server104 see errors in word file.
>

Which errors specifically? (i.e. not what does not work, but precisely what
are you told of the problems?).

Is this so _only_ with 104 ? (i.e. you try 135 or any other in that OU and
OK?)

> If I from a member server that lies in Web OU run MBSA against all server
> in the domain I get errors from scanning lt104 se word file
>
> If I move the server lt104 to Web OU, none of the above errors occur. But

Did I miss a list of error messages?

> the server lt104 needs to connect to a standalone server to get picture
> and
> I cant connect to that standalone server if lt104 is in the Web OU but it
> works if it lies in Computer OU.
>
>
> Any ideers whats causing this problem
>

Mikael,

It sounds like you could fairly simply use the GPMC resultant policy
capability to get reports on the effective settings when in each of the
two locations and compare these for their differences.
www.microsoft.com/gp

Roger




Similar ThreadsPosted
Windows Server 2003 Security Guide 2.0 January 17, 2006, 10:24 am
Windows Server 2003 Security Guide for SP2? June 4, 2007, 7:03 pm
MSS tcp registry values in windows 2003 server security guide August 20, 2006, 7:23 am
Windows Server 2003 Security Guide: International versions? October 23, 2007, 1:51 pm
MSS tcp registry values in windwos 2003 server security guide August 21, 2006, 2:33 am
2003 Security Guide August 10, 2005, 12:30 pm
Windows 2003 server and VPN: Security(?) December 16, 2005, 4:20 pm
Windows server 2003 security. How to protect against 100's of invalid logons to the server?? August 12, 2005, 5:29 pm
Security on a stand-alone windows 2003 Server August 8, 2005, 11:42 am
Security Configuration Wizard - Windows Server 2003 SP1 August 3, 2005, 6:56 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap