Windows Server 2008 Managing the user experience, Keeping it all safe and secure
September 23rd, 2008Windows Server 2008 includes an impressive array of new security applications and features that further enhance enterprise deployments, particularly within hostile environments or under potentially threatening scenarios. Today’s Internet is a brightly illuminated world that casts shadows, and from those shadows arise criminal aspirations that seek to infiltrate, pilfer, and undermine Internet-accessible businesses. Microsoft has stepped up its Windows Server 2008 defenses to better serve the computing public that can’t always defend against unforeseen, persistent, or stealthy attack.
The following paragraphs briefly summarize some of the new and newly enhanced security features of the Windows Server 2008 family:
- BitLocker Drive Encryption is a security feature of both Windows Vistaand Windows Server 2008 (again sharing a common base) to providestrong cryptographic protection over stored sensitive data within theoperating system volume. BitLocker encrypts all data stored in theWindows volume and any relevant configured data volumes, whichincludes hibernation and paging files, applications, and application data.Furthermore, BitLocker works in conjunction with Trusted PlatformModule (TPM) frameworks to ensure the integrity of protected volumesfrom tampering, even — and especially — while the operating systemisn’t operational (like when the system is turned off).
- Windows Service Hardening turns Internet-facing servers into bastions resistant to many forms of network-driven attack. This restricts critical Windows services from performing abnormal system activities within the file system, registry, network, or other resources that may be leveraged to install malware or launch further attacks on other computers.
- Microsoft Forefront Security Technologies is a comprehensive solution that provides protection for the client operating system, application servers, and the network edge. In the Forefront Client Security role, you may provide unified malware protection for business notebooks, workstations, and server platforms with easier management and control. Server security can fortify Microsoft Exchange messaging environments or protect Office SharePoint Server 2007 services against viruses,worms, and spam.
- Internet Security and Acceleration (ISA) Server provides enterpriseworthy firewall, virtual private network (VPN), and Web caching solutions to protect IT environments against Internet-based threats. Microsoft’s Intelligent Application Gateway is a remote-access intermediary that provides secure socket layer (SSL) application access and protectionwith endpoint security management.
- User Account Control (UAC) enables cleaner separation of duties to allow non-administrative user accounts to occasionally perform administrative tasks without having to switch users, log off, or use the Run As command. UAC can also require administrators to specifically approve applications that make system-wide changes before allowing those applications to run. Admin Approval Mode (AAM) is a UAC configuration that creates a split user access token for administrators, to further separateadministrative from non-administrative tasks and capabilities. Read the rest of this entry »
Bookmark and ShareClose this Window Bookmark and Share This PageCopy HTML:If you like this then please subscribe to the RSS Feed.
![[del.icio.us]](http://www.dongengan.info/wp-content/plugins/bookmarkify/delicious.png)
![[Digg]](http://www.dongengan.info/wp-content/plugins/bookmarkify/digg.png)
![[Google]](http://www.dongengan.info/wp-content/plugins/bookmarkify/google.png)
![[StumbleUpon]](http://www.dongengan.info/wp-content/plugins/bookmarkify/stumbleupon.png)
![[Windows Live]](http://www.dongengan.info/wp-content/plugins/bookmarkify/windowslive.png)
![[Yahoo!]](http://www.dongengan.info/wp-content/plugins/bookmarkify/yahoo.png)
![[Email]](http://www.dongengan.info/wp-content/plugins/bookmarkify/email.png)