Book Image

Least Privilege Security for Windows 7, Vista and XP

By : Russell Smith
Book Image

Least Privilege Security for Windows 7, Vista and XP

By: Russell Smith

Overview of this book

Least Privilege Security is the practice of assigning users and programs the minimum permissions required to complete a given task. Implementing this principle in different versions of Microsoft Windows requires careful planning and a good understanding of Windows security. While there are benefits in implementing Least Privilege Security on the desktop, there are many technical challenges that you will face when restricting privileges.This book contains detailed step-by-step instructions for implementing Least Privilege Security on the desktop for different versions of Windows and related management technologies. It will provide you with quick solutions for common technical challenges, Microsoft best practice advice, and techniques for managing Least Privilege on the desktop along with details on the impact of Least Privilege Security.The book begins by showing you how to apply Least Privilege Security to different categories of users. You will then prepare a desktop image with Least Privilege Security enabled from the start and deploy the new image while preserving users' files and settings. You will identify problems with applications caused by Least Privilege Security using the Application Compatibility Toolkit. This book will help you configure User Account Control on multiple computers using Group Policy and support Least Privilege user accounts using reliable remote access. Then, you will modify legacy applications for Least Privilege Security, achieving the best balance between compatibility and security by using Application Compatibility shims. You will install per-machine ActiveX Controls using the ActiveX Installer Service (AxIS). The book will help you implement best practices for working with ActiveX Controls in a managed environment. Finally, you will deploy default Software Restriction Policy (SRP) or AppLocker rules to ensure only programs installed in protected locations can run and blacklist applications using SRP or AppLocker.
Table of Contents (19 chapters)
Least Privilege Security for Windows 7, Vista and XP
Credits
About the Author
About the Reviewers
Preface
12
Provisioning Applications on Secure Desktops with Remote Desktop Services

Creating a Data Collection Package


After the Application Compatibility Manager has been configured, the next stage is to create a Data Collection Package to gather inventory and UAC compatibility data from PCs.

  1. 1. Select New in the File menu.

  2. 2. Name the package Least Privilege testing, and in the Evaluation compatibility when section, click Advanced.

  3. 3. Deselect Windows Compatibility Evaluators and click OK.

  1. 4. Under When to monitor application usage, set the Upload data every to 2 hours.

  1. 5. Select Save and Create Data Collection Package in the File menu.

  2. 6. Save the Least Privilege testing.msi package to your desktop and close the Data Collection Package window.

Note

UACCE supported user accounts

If you want to deploy the UACC Compatibility Evaluator, then you should be running Vista or Windows 7 using a standard user or protected administrator account. UACCE enables UAC logging and sends data from local event logs to ACT.

To begin collecting data, you need to install the Least Privilege testing...