<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Business and Information Technology Tangents &#187; Server Tangents</title>
	<atom:link href="http://bittangents.com/category/server-tangents/feed/" rel="self" type="application/rss+xml" />
	<link>http://bittangents.com</link>
	<description>Business and Information Technology Tangents is dedicated to providing quality content while informing the world about technology.</description>
	<lastBuildDate>Fri, 27 Apr 2012 21:02:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='bittangents.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Business and Information Technology Tangents &#187; Server Tangents</title>
		<link>http://bittangents.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://bittangents.com/osd.xml" title="Business and Information Technology Tangents" />
	<atom:link rel='hub' href='http://bittangents.com/?pushpress=hub'/>
		<item>
		<title>Nested User Groups (Groups in Groups) / Built-in Local Groups Issue</title>
		<link>http://bittangents.com/2010/07/13/nested-user-groups-groups-in-groups-built-in-local-groups-issue/</link>
		<comments>http://bittangents.com/2010/07/13/nested-user-groups-groups-in-groups-built-in-local-groups-issue/#comments</comments>
		<pubDate>Tue, 13 Jul 2010 21:19:35 +0000</pubDate>
		<dc:creator>brentblawat</dc:creator>
				<category><![CDATA[Server Tangents]]></category>

		<guid isPermaLink="false">https://brentblawat.wordpress.com/2010/07/13/nested-user-groups-groups-in-groups-built-in-local-groups-issue/</guid>
		<description><![CDATA[By: Brenton Blawat “Broken By Design” UPDATED! After hours of conference calls with Microsoft, and multiple tiers of support, we come to the conclusion that Nested Local Groups in Built-in Groups are “broken by design”. What does this really mean? When you nest a Local Group into a Built-in Local Group, the effective permission set [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bittangents.com&#038;blog=4066351&#038;post=486&#038;subd=brentblawat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>By: Brenton Blawat</strong></p>
<p><strong>“Broken By Design”</strong></p>
<p><strong>UPDATED!</strong> After hours of conference calls with Microsoft, and multiple tiers of support, we come to the conclusion that Nested Local Groups in Built-in Groups are “broken by design”. What does this really mean? When you nest a Local Group into a Built-in Local Group, the effective permission set for the Users within that Local Group is reduced to <strong>Guest</strong>.<strong> </strong>This remains true unless the Users are specifically added into the Built-in Local Groups, which will result in proper permissions being passed to the Users. </p>
<p>&#160;</p>
<h2>Nesting Issue Explained</h2>
<p><a href="http://brentblawat.files.wordpress.com/2010/07/coregroups_small.jpg"><img style="display:inline;border-width:0;" title="coregroups_small" border="0" alt="coregroups_small" src="http://brentblawat.files.wordpress.com/2010/07/coregroups_small_thumb.jpg?w=410&h=297" width="410" height="297" /></a> </p>
<p>Lets take the above graphic, where we created a new local group called ‘Geeks’ which contains users named “Brenton B” and “Jason P”. From there, we added the ‘Geeks’ local to the Built-in ‘Administrators’ local group. From that hierarchy, we should assume any users in the ‘Geeks’ Local Group, should obtain Administrative privileges by traversing through the security pathway. Unfortunately, this is <em>not</em> the case.</p>
<p>Note: This issue is for all of the <strong>Built-in</strong> Groups on the system including, but not limited to, Administrators, Backup Operators, Power Users, and Users. I used the Administrators Group, as it’s easiest to work with.</p>
<p>&#160;</p>
<p><a href="http://brentblawat.files.wordpress.com/2010/07/coregroupserr_fulljpg.jpg"><img style="display:inline;border-width:0;" title="coregroupserr_fulljpg" border="0" alt="coregroupserr_fulljpg" src="http://brentblawat.files.wordpress.com/2010/07/coregroupserr_fulljpg_thumb.jpg?w=451&h=323" width="451" height="323" /></a> </p>
<p>The issue has to do with second level security traversing with Built-in Groups. While the first level traversing is a trusted security relationship in the operating system, the second security relationship is not trusted. This means that the ’Geeks’ Local Group object is effectively a member of the ‘Administrators’ Group and it also means that Brenton B. and Jason P. are members of the ‘Geeks’ Local Group. It will not, however, traverse to the second level and grant Brenton B. and Jason P. group membership to Administrators.</p>
<h2>&#160;</h2>
<h2>What About Restricted Groups in Group Policies?</h2>
<p>&#160;</p>
<p><a href="http://brentblawat.files.wordpress.com/2010/07/restrictedlocation.jpg"><img style="display:inline;margin-left:0;margin-right:0;border-width:0;" title="RestrictedLocation" border="0" alt="RestrictedLocation" align="left" src="http://brentblawat.files.wordpress.com/2010/07/restrictedlocation_thumb.jpg?w=239&h=223" width="239" height="223" /></a> </p>
<p><a href="http://brentblawat.files.wordpress.com/2010/07/groupadded.jpg"><img style="display:inline;border-width:0;" title="groupadded" border="0" alt="groupadded" src="http://brentblawat.files.wordpress.com/2010/07/groupadded_thumb.jpg?w=714&h=77" width="714" height="77" /></a>&#160;</p>
<p>&#160;</p>
<p>&#160;</p>
<p>&#160;</p>
<p>&#160;</p>
<p>&#160;</p>
<p>This issue unfortunately is also present when you have Restricted Groups. <em>Restricted Groups </em>within Group Policies force group associations to the local groups in the Operating System. While you mandate the ‘TestAdmin’ Group as part of the Built-in Administrators Local Group, the permission lookup occurs on the Windows Operating System; thus the Nested Groups do not traverse.</p>
<h2>Can You Still Add Groups To Built-in Groups?</h2>
<p><a href="http://brentblawat.files.wordpress.com/2010/07/groups.jpg"><img style="display:inline;" title="groups" alt="groups" src="http://brentblawat.files.wordpress.com/2010/07/groups_thumb.jpg?w=425&h=368" width="425" height="368" /></a> </p>
<p>Yes, as shown above! While the GUI of Windows does not provide a method to directly add Groups within Built-in Groups, you can execute two commands that would provide for adding Groups in Groups.</p>
<p>Method 1 – Powershell</p>
<div style="border-bottom:silver 1px solid;text-align:left;border-left:silver 1px solid;line-height:12pt;background-color:#f4f4f4;width:97.5%;font-family:&#039;direction:ltr;max-height:200px;font-size:8pt;overflow:auto;border-top:silver 1px solid;cursor:text;border-right:silver 1px solid;margin:20px 0 10px;padding:4px;" id="codeSnippetWrapper">
<div style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;padding:0;" id="codeSnippet">
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum1">   1:</span> <span style="color:#008000;"># Obtain the Current Computer Name</span></pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum2">   2:</span> $cmpName = [System.Net.DNS]::GetHostName()</pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum3">   3:</span>&#160; </pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum4">   4:</span> <span style="color:#008000;"># Make the ADSI Call into the Computer</span></pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum5">   5:</span> $adsiCall = [ADSI] (<span style="color:#006080;">&quot;WinNT://$cmpName,computer&quot;</span>)</pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum6">   6:</span>&#160; </pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum7">   7:</span> <span style="color:#008000;"># Create the worker variable</span></pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum8">   8:</span> $objworker = $adsiCall.Create(<span style="color:#006080;">&quot;group&quot;</span>,<span style="color:#006080;">&quot;Geeks&quot;</span>)</pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum9">   9:</span> $objworker.put(<span style="color:#006080;">&quot;description&quot;</span>,<span style="color:#006080;">&quot;Geeks Local Group&quot;</span>)</pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum10">  10:</span>&#160; </pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum11">  11:</span> <span style="color:#008000;"># Create Object from worker variable</span></pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum12">  12:</span> $objworker.setinfo()</pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum13">  13:</span>&#160; </pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum14">  14:</span> <span style="color:#008000;"># Create the Group Association</span></pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum15">  15:</span> $adsistring = <span style="color:#006080;">&quot;$cmpName/Administrators,group&quot;</span></pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum16">  16:</span>&#160; </pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum17">  17:</span> <span style="color:#008000;"># Create the worker variable</span></pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum18">  18:</span> $group = [adsi] (<span style="color:#006080;">&quot;WinNT://$adsistring&quot;</span>)</pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum19">  19:</span>&#160; </pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum20">  20:</span> <span style="color:#008000;"># Add the group</span></pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum21">  21:</span> $group.add(<span style="color:#006080;">&quot;WinNT://$cmpName/Geeks&quot;</span>)</pre>
<p><!--CRLF--></div>
</div>
<p>Method 2 – NET Commands in BAT File</p>
<div style="border-bottom:silver 1px solid;text-align:left;border-left:silver 1px solid;line-height:12pt;background-color:#f4f4f4;width:97.5%;font-family:&#039;direction:ltr;max-height:200px;font-size:8pt;overflow:auto;border-top:silver 1px solid;cursor:text;border-right:silver 1px solid;margin:20px 0 10px;padding:4px;" id="codeSnippetWrapper">
<div style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;padding:0;" id="codeSnippet">
<pre style="text-align:left;line-height:12pt;background-color:white;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum1">   1:</span> net localgroup <span style="color:#006080;">&quot;Geeks&quot;</span> /Add</pre>
<p><!--CRLF--></p>
<pre style="text-align:left;line-height:12pt;background-color:#f4f4f4;width:100%;font-family:&#039;direction:ltr;color:black;font-size:8pt;overflow:visible;border-style:none;margin:0;padding:0;"><span style="color:#606060;" id="lnum2">   2:</span> net localgroup <span style="color:#006080;">&quot;Administrators&quot;</span> <span style="color:#006080;">&quot;Geeks&quot;</span> /Add</pre>
<p><!--CRLF--></div>
</div>
<p>* The above Methods add the ‘Geeks’ local Group, then add the ‘Geeks’ Local Group to the ‘Administrators’ Group</p>
<h2>&#160;</h2>
<h2>Resolution to the Issue</h2>
<p>The following can be performed to resolve the issue:</p>
<p>#1 Add the Users of the Geeks Group directly to the Built-in Administrators Group.</p>
<p>#2 Create a Domain Global Group named ‘Geeks’ and place the Domain Global Group ‘Geeks’ in the Local Administrators Restricted Group.</p>
<p>Supporting documents: According to Microsoft’s knowledge Base articles</p>
<p><a href="http://technet.microsoft.com/en-us/library/ee681621(WS.10).aspx">http://technet.microsoft.com/en-us/library/ee681621(WS.10).aspx</a> … “This is the expected behavior of the <strong>Computer Management</strong> snap-in.”</p>
<p>and</p>
<p><a href="http://support.microsoft.com/kb/974815">http://support.microsoft.com/kb/974815</a> … where we can quote directly “This behavior is by design. Windows does not support the nesting of local groups on domain clients or on workgroup clients.”</p>
<p>&#160;</p>
<p><strong>UPDATED! </strong>Let me explain this one a bit more – I received an email From Microsoft that explained the nesting functionality as follows:</p>
<blockquote>
<p>“The process of determining the security-groups a user belongs to is called group expansion, which is an integral part of user authentication. It is necessary that the group expansion accurately generates a list containing the groups that the user is a member of (directly or indirectly) in order to allow the user accesses to various resources. It is by design that group membership does not expand nested local groups.</p>
<p>Microsoft’s intention was to disallow nesting groups in group authoring experience (as in the case of the UI) to accurately reflect group expansion constraints. As your examples point out, there are several ways of nesting local groups, contrary to our intention. Our suggestion is to never nest local groups even when it is allowed by a group authoring tool like “net local group” because such nesting doesn’t reflect the group expansion constraints and the end results would be different from the expected results.”</p>
</blockquote>
<p>What Microsoft is saying in a formal way – Their design for group expansion model does not include the ability to look through multiple levels of local Nested Groups. It only provides the ability to look one level deep due to the way it was developed by Microsoft. By not knowing how large of an impact it would be to add the ability to nest local groups, I can only assume that Microsoft does not think it is advantageous to add this functionality due to the number of users that will be using the system in this way – which makes sense.</p>
<p>We were able to get the Local Groups to Accept “Global” and “Domain Local”* active directory groups. While this doesn’t help a stand alone system for nesting of groups, it does provide a work around for authentication. This means that if you were to make the ‘Geeks’ Group, from the first example above, a Active Directory Group, the local system will pass the authentication query to Active Directory which then has the mechanisms to traverse through nested groups.</p>
<p>** Be cautious when adding Domain Local Groups to the system as if you have any forests, or trusts, the security will not traverse through the forest or any trusts. ** </p>
<p>A special thanks to Jim Tan, Richard Leung, and Sunil Naik from Microsoft with their help on my issue!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/brentblawat.wordpress.com/486/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/brentblawat.wordpress.com/486/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/brentblawat.wordpress.com/486/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/brentblawat.wordpress.com/486/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/brentblawat.wordpress.com/486/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/brentblawat.wordpress.com/486/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/brentblawat.wordpress.com/486/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/brentblawat.wordpress.com/486/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/brentblawat.wordpress.com/486/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/brentblawat.wordpress.com/486/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/brentblawat.wordpress.com/486/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/brentblawat.wordpress.com/486/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/brentblawat.wordpress.com/486/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/brentblawat.wordpress.com/486/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bittangents.com&#038;blog=4066351&#038;post=486&#038;subd=brentblawat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bittangents.com/2010/07/13/nested-user-groups-groups-in-groups-built-in-local-groups-issue/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2fd28fc9e2db7e469f8237a6d55fba2b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">brentblawat</media:title>
		</media:content>

		<media:content url="http://brentblawat.files.wordpress.com/2010/07/coregroups_small_thumb.jpg" medium="image">
			<media:title type="html">coregroups_small</media:title>
		</media:content>

		<media:content url="http://brentblawat.files.wordpress.com/2010/07/coregroupserr_fulljpg_thumb.jpg" medium="image">
			<media:title type="html">coregroupserr_fulljpg</media:title>
		</media:content>

		<media:content url="http://brentblawat.files.wordpress.com/2010/07/restrictedlocation_thumb.jpg" medium="image">
			<media:title type="html">RestrictedLocation</media:title>
		</media:content>

		<media:content url="http://brentblawat.files.wordpress.com/2010/07/groupadded_thumb.jpg" medium="image">
			<media:title type="html">groupadded</media:title>
		</media:content>

		<media:content url="http://brentblawat.files.wordpress.com/2010/07/groups_thumb.jpg" medium="image">
			<media:title type="html">groups</media:title>
		</media:content>
	</item>
		<item>
		<title>Default Domain Policies Windows Server 2003 SP2 / Windows server 2008 R2</title>
		<link>http://bittangents.com/2010/02/03/default-domain-policies-windows-server-2003-sp2-windows-server-2008-r2/</link>
		<comments>http://bittangents.com/2010/02/03/default-domain-policies-windows-server-2003-sp2-windows-server-2008-r2/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 01:59:43 +0000</pubDate>
		<dc:creator>brentblawat</dc:creator>
				<category><![CDATA[Server Tangents]]></category>

		<guid isPermaLink="false">http://brentblawat.wordpress.com/2010/02/03/default-domain-policies-windows-server-2003-sp2-windows-server-2008-r2/</guid>
		<description><![CDATA[By: Brenton Blawat What would seem like a quick reference item to find on Google, seems to have been lost in the billions of web pages. This article is intended as a quick reference to what the Default Domain Policies are for Windows Server 2003 SP2 and Windows Server 2008 R2. Please note that while [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bittangents.com&#038;blog=4066351&#038;post=440&#038;subd=brentblawat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>By: Brenton Blawat</strong></p>
<p>What would seem like a quick reference item to find on Google, seems to have been lost in the billions of web pages. This article is intended as a quick reference to what the Default Domain Policies are for Windows Server 2003 SP2 and Windows Server 2008 R2. Please note that while some of the policies appear to be identical, the hierarchical structure behind the policies are different.</p>
<p><strong>Default Domain Policies: Windows Server 2003 SP2</strong></p>
<p>+ Computer Configuration &gt; Windows Settings &gt; Security Settings &gt; Account Policies &gt; Password Policy</p>
<blockquote><p>- Enforce Password History = 24 Passwords</p>
<p>- Maximum Password Age = 42 Days</p>
<p>- Minimum Password Age = 1 Days</p>
<p>- Minimum Password Length = 7 Characters</p>
<p>- Password must meet complexity requirements = Enabled</p>
<p>- Store Passwords using reversible encryption = Disabled</p>
</blockquote>
<p>+ Computer Configuration &gt; Windows Settings &gt; Security Settings &gt; Account Policies &gt; Account Lockout Policy</p>
<blockquote><p>- Account lockout threshold = 0 invalid logon attempts</p>
</blockquote>
<p>+ Computer Configuration &gt; Windows Settings &gt; Security Settings &gt; Account Policies &gt; Kerberos Policy</p>
<blockquote><p>- Enforce user logon restrictions = Enabled</p>
<p>- Maximum lifetime for service ticket = 600 minutes</p>
<p>- Maximum lifetime for user ticket = 10 hours</p>
<p>- Maximum lifetime for user ticket renewal = 7 days</p>
<p>- Maximum tolerance for computer clock synchronization = 5 minutes</p>
</blockquote>
<p>+ Computer Configuration &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; Security Options</p>
<blockquote><p>- Network Security: Force Logoff when logon hours expire = Disabled</p>
</blockquote>
<p>+ Computer Configuration &gt; Windows Settings &gt; Security Settings &gt; Public Key Policies &gt; Encrypting File System</p>
<blockquote><p>- Administrator Issued File Recovery Certificate</p>
</blockquote>
<p>+ User Settings &gt; Windows Settings &gt; Security Settings &gt; Public Key Policies &gt; Autoenrollment Settings</p>
<blockquote><p>- Enroll Certificates Automatically</p>
</blockquote>
<p>&#160;</p>
<p><strong>Default Domain Policies: Windows Server 2008 R2 64-bit</strong></p>
<p>+ Computer Configuration &gt; Policies &gt; Windows Settings &gt; Security Settings &gt; Account Policies &gt; Password Policy</p>
<blockquote><p>- Enforce Password History = 24 Passwords</p>
<p>- Maximum Password Age = 42 Days</p>
<p>- Minimum Password Age = 1 Days</p>
<p>- Minimum Password Length = 7 Characters</p>
<p>- Password must meet complexity requirements = Enabled</p>
<p>- Store Passwords using reversible encryption = Disabled</p>
</blockquote>
<p>+ Computer Configuration &gt; Policy &gt; Windows Settings &gt; Security Settings &gt; Account Policies &gt; Account Lockout Policy</p>
<blockquote><p>- Account lockout threshold = 0 invalid logon attempts</p>
</blockquote>
<p>+ Computer Configuration &gt; Policy &gt; Windows Settings &gt; Security Settings &gt; Account Policies &gt; Kerberos Policy</p>
<blockquote><p>- Enforce user logon restrictions = Enabled</p>
<p>- Maximum lifetime for service ticket = 600 minutes</p>
<p>- Maximum lifetime for user ticket = 10 hours</p>
<p>- Maximum lifetime for user ticket renewal = 7 days</p>
<p>- Maximum tolerance for computer clock synchronization = 5 minutes</p>
</blockquote>
<p>+ Computer Configuration &gt; Policy &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; Security Options</p>
<blockquote><p>- Network access: Allow anonymous SID/Name translation = Disabled</p>
<p>- Network security: Do not store LAN Manager hash value on next password change = Enabled</p>
<p>- Network Security: Force Logoff when logon hours expire = Disabled</p>
</blockquote>
<p>+ Computer Configuration &gt; Policy &gt; Windows Settings &gt; Security Settings &gt; Public Key Policies &gt; Encrypting File System</p>
<blockquote><p>- Administrator Issued File Recovery Certificate</p>
</blockquote>
<p>+ Computer Configuration &gt; Policy &gt; Windows Settings &gt; Security Settings &gt; Public Key Policies &gt; Trusted Root Certification Authorities</p>
<blockquote><p>- Allow users to select new root certification authorities (CAs) to trust = Enable</p>
<p>- Client computers can trust the following certificate stores = Third-Party Root Certification Authorities and Enterprise Root Certification Authorities</p>
<p>- To perform certificate-based authentication of users and computers, CAs must meet the criteria = Registered in Active Directory only</p>
</blockquote>
<p>&#160;</p>
<h1>Default Domain Policy Differences: Windows Server 2003 / Windows Server 2008</h1>
<p><strong>Default Domain Policies added to Windows Server 2008</strong></p>
<p>+ Computer Configuration &gt; Policy &gt; Windows Settings &gt; Security Settings &gt; Local Policies &gt; Security Options</p>
<blockquote><p>- Network access: Allow anonymous SID/Name translation = Disabled</p>
<p>- Network security: Do not store LAN Manager hash value on next password change = Enabled</p>
</blockquote>
<p>+ Computer Configuration &gt; Policy &gt; Windows Settings &gt; Security Settings &gt; Public Key Policies &gt; Trusted Root Certification Authorities</p>
<blockquote><p>- Allow users to select new root certification authorities (CAs) to trust = Enable</p>
<p>- Client computers can trust the following certificate stores = Third-Party Root Certification Authorities and Enterprise Root Certification Authorities</p>
<p>- To perform certificate-based authentication of users and computers, CAs must meet the criteria = Registered in Active Directory only</p>
</blockquote>
<p><strong>Removed from Windows Server 2008</strong></p>
<p>+ User Settings &gt; Windows Settings &gt; Security Settings &gt; Public Key Policies &gt; Autoenrollment Settings</p>
<blockquote><p>- Autoenrollment Settings: Enroll Certificates Automatically</p>
</blockquote>
<p><strong></strong></p>
<p><strong>** </strong>NOTE: All re-productions / digital copies of this content must be approved in writing by an authorized representative of BIT Tangents.**</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/brentblawat.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/brentblawat.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/brentblawat.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/brentblawat.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/brentblawat.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/brentblawat.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/brentblawat.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/brentblawat.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/brentblawat.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/brentblawat.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/brentblawat.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/brentblawat.wordpress.com/440/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/brentblawat.wordpress.com/440/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/brentblawat.wordpress.com/440/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bittangents.com&#038;blog=4066351&#038;post=440&#038;subd=brentblawat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bittangents.com/2010/02/03/default-domain-policies-windows-server-2003-sp2-windows-server-2008-r2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2fd28fc9e2db7e469f8237a6d55fba2b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">brentblawat</media:title>
		</media:content>
	</item>
	</channel>
</rss>
