on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries,...

37
on Microsoft Based Platforms

Transcript of on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries,...

Page 1: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

on Microsoft Based Platforms

Page 2: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

The problem description

Some Windows security terminology Security Descriptor, Security Identifier, Discretionary Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service Accounts, Security Groups

Privileges, Access & Authorization

Active directory

Forefront Identity Manager 2010

Page 3: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 4: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 5: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 6: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

The problem description

Some Windows security terminology Security Descriptor, Security Identifier, Discretionary Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service Accounts, Security Groups

Privileges, Access & Authorization

Active directory

Forefront Identity Manager 2010

Page 7: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 8: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 9: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

Owner SID:

REDMOND\BillB

DACL

SACL

Header

REDMOND\DavidJo

Access Denied

RWX

REDMOND\MSTE

Access Allowed

RX

REDMOND\BillB

Access Allowed

WD

Access token for

BDEvent.doc

ACE

ACE

ACE

DACL

Page 10: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 11: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 12: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 13: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 14: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

Code, Data Code, Data Policy

Page 15: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 16: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

1. CAD

2. Collect Credential

3. Enter Credentials

Winlogon LSASS.EXE

NTLM

Credential Providers

Kerberos

Negotiate

Netlogon

4. LsaLogonUser

LSA Secrets Store

KDC + AD

Page 17: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

Admin

Process

Standard

User

Process ?

Page 18: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 19: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

• Change Time Zone

• Run Standard User Compliant

Applications

• Install Fonts

• Run MSN Messenger

• IE

Page 20: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 21: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

Impersonation

Page 22: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 23: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

The problem description

Some Windows security terminology Security Descriptor, Security Identifier, Discretionary Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service Accounts, Security Groups

Privileges, Access & Authorization

Active directory

Forefront Identity Manager 2010

Page 24: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 25: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 26: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 27: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 28: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

Microsoft Authorization Manager (AzMan) is part of Windows Server and allows role-based access control to provide separation-of-duties.

Separation of duties with Microsoft Authorization Manager

Page 29: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

The problem description

Some terminology SD, SID, DACL / SACL, ACE, MIC, Security boundaries, UAC, MSA, Security groups

Privileges, Access & Authorization

Active directory

Forefront Identity Manager 2010

Page 30: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 31: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 32: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service
Page 33: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

3

4

New auditing categories:

Directory Service Access

Directory Service Changes

Directory Service Replication

Detailed Directory Service

Replication

Page 34: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

The problem description

Some Windows security terminology Security Descriptor, Security Identifier, Discretionary Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service Accounts, Security Groups

Privileges, Access & Authorization

Active directory

Forefront Identity Manager 2010

Page 35: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

FIM group management provides the ability to perform the

following:

• Create and manage Security Groups

• Add and remove members from Groups

• Join and leave from Groups

• Perform extensive searches on groups

• View a history of actions taken on specific groups

• Workflows (delegation, escalation…)

• View request status as the requestor, or group owner

• Assign co-owners to assist in managing your Groups

• Dynamic (Calculated) groups based on attributes (query

builder or Xpath)

Page 36: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service

Manage the Identity Lifecycle

Page 37: on Microsoft Based Platforms - GSE Young …...Access Control List / System ACL, AC list Entries, Mandatory Integrity Check, Security boundaries, User Account Control, Managed Service