Click here to get back home

Security Configuration Editor versus Wizard for 2003 policy

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Security Configuration Editor versus Wizard for 2003 policy Marco Shaw 09-26-2005
Get Chitika Premium
Posted by Marco Shaw on September 26, 2005, 10:59 am
Please log in for more thread options
Writing up a new security policy for 2003 servers. 2003SP1 comes with SCW,
but there's the SCE (since 2000SP4) out there too. I realize they both do
some different things.

SCE is a bit less user-friendly than SCW which comes with a nice wizard.

These days, what are the risks of having run only SCW on a Windows 2003 web
server? Should I still run one of the 'high security' .inf templates from
SCE on these systems for a 'best effort' against break-ins?

I can't remember the last time we've had a Windows break in, since a trojan
management to get onto a unsecured NT4 box a few years ago.

Marco




Posted by Steven L Umbach on September 26, 2005, 7:29 pm
Please log in for more thread options
I have not used it much myself but SCW so far seems impressive in that it is
tailored to server role and can implement ipsec filtering policy to also
mange outbound access of a computer. The general .inf security templates are
not tailored to a server role. I understand that the SCW can do a rollback
which you can also do with secedit for some security settings but it must be
done manually before you apply the security template locally. I would take
advantage of SCW and then you can use the Security Configuration and
Analysis Tool to check the security settings of the server against a
security template to see if the security setting are what you expect. The
Windows 2003 Server Security Guide [ free at link below] can also be very
helpful in determining how to secure your server by role along with running
MBSA on it. -- Steve

http://www.microsoft.com/technet/security/prodtech/windowsserver2003/W2003HG/SGCH00.mspx

> Writing up a new security policy for 2003 servers. 2003SP1 comes with
> SCW,
> but there's the SCE (since 2000SP4) out there too. I realize they both do
> some different things.
>
> SCE is a bit less user-friendly than SCW which comes with a nice wizard.
>
> These days, what are the risks of having run only SCW on a Windows 2003
> web
> server? Should I still run one of the 'high security' .inf templates from
> SCE on these systems for a 'best effort' against break-ins?
>
> I can't remember the last time we've had a Windows break in, since a
> trojan
> management to get onto a unsecured NT4 box a few years ago.
>
> Marco
>
>




Similar ThreadsPosted
Error 0x800704b8 when applying policy with Security Configuration Wizard March 28, 2007, 6:30 pm
Security Configuration Wizard - Windows Server 2003 SP1 August 3, 2005, 6:56 am
Security Configuration Wizard: 2nd try August 2, 2006, 9:44 am
Security Configuration Wizard (SCW) March 1, 2007, 2:35 pm
Re: How to install security configuration wizard December 30, 2005, 2:24 pm
Security Configuration Wizard question December 12, 2007, 8:59 pm
Security Configuration Wizard: Catastrophic Failure October 7, 2005, 8:30 am
confusion about W2003 SP1 security configuration wizard July 28, 2006, 9:07 am
Windows security wizard Firewall configuration September 3, 2008, 9:07 am
Security configuration wizard: Parameter incorrect error September 26, 2007, 7:11 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap