Security Configuration Securing Windows 2000 Trough Security example essay topic

3,399 words
WINDOWS 2000 (MCSE) - CS 750 DESCRIPTIONS: This program is designed for candidates with a background in computers & who want to learn networking and prepare themselves for the MCSE exams. This is completely hands-on training to install, configure, and design Windows 2000 Professional, Server, Network and Directory Services Infrastructure. Program covers Microsoft Exams 70-210,215,216,217,219,221, and 222. WHO SHOULD ATTEND? Individuals who want to start a new career in Windows 2000 MCSE Certification, and possess extensive working knowledge of Windows and DOS, and also individuals who are working in different networks but wants to be familiar with the Windows 2000 network environment.

CLOCK HOURS: 300 Hrs PREREQUISITE: Working knowledge of DOS & Windows & 2 yrs of college education preferred or Completion of Aquarius CS-200 or CS-250. FEES: $4995.00 Introduction to Networking & Hardware An overview of the new operating System. Students are introduced to some of the new Features. Windows 2000 has to offer for compatibility, scalability, file management, and security compared to the previous versions of Microsoft operating systems. The module also introduces the basic network technologies as peer to peer and server based networks. Microsoft Windows 2000 program modules listed below: Modules Covered: MODULE 1: INSTALLING, CONFIGURING AND ADMINISTERING WINDOWS 2000 PROFESSIONAL Core Exam 70-210 40 Hours Installing Windows 2000 Professional The module starts with the pre-installation requirements and hardware compatibility of Windows 2000 Professional.

Then it goes through the entire installation and common troubleshooting process from CD-ROM and over the network. The students are given the chance to install Windows 2000 Professional on their computers as part of the exercise in the end of the module. Microsoft Management Console and Task Scheduler An introduction to the new administrative tools in Windows 2000. Module discusses the Microsoft Management console (MMC), creating custom consoles, console trees, managing snap-ins and defines the differences between Author and User mode and how customized Mmc are used for remote administration and troubleshooting. Further the students are introduced to another powerful administrative too the Microsoft Task scheduler and the exercise launching a program in specific time and creating customized consoles. Windows Control Panel Detailed explanation of how to configure Windows 2000 environment using the Control Panel.

Special attention is paid to using the System icon to configure environment variables, hardware profiles as well as various devices and services. The module also includes installing both Plug and Play and non Plug and play hardware trough Add / Remove Hardware Wizard. As exercise - the students configure their system trough Display Icon in Control Panel, add and change environment variables and change the size of the paging file. Windows 2000 Registry The module is a brief introduction to the Registry as a hierarchical database where most part of the system configuration is stored. It shows the usage of the Registry Editor witch the students are using in the followed exercise to search for specific keys, add and change variables.

Windows 2000 Disk Subsystem Presents the basic ideas of disk management and using Disk Management snap-in in Microsoft Management Console. The hands on practice includes creating a customized MMC with Disk Management snap-in and using the preconfigured Computer management Snap-in to upgrade a basic to dynamic disk, creating and mounting a new volume. Installing and Configuring Network Protocols The module discusses the supported by Windows 2000 network protocols. Installation and configuration of Transmission Control Protocol / Internet Protocol (TCP / IP), NWLink, NetBIOS Enhanced User Interface (NetBEUI), and Data Link Control (DLC) and configuration of network bindings. Students configure their own IP addresses, configure their computers to use DHCP (Dynamic Host Configuration Protocol) for automatic IP address configuration. Next they test the Automatic Private IP Configuration, Install NWLink and configure the network bindings.

Windows 2000 DNS Service Module discuses the process of resolution of host names to IP addresses trough Windows 2000 Domain Name System (DNS). It shows the differences with previous Microsoft Operating Systems. As exercise students install and configure their computers as DNS clients. Introducing Active Directory Services An Introduction to the new directory services in Windows 2000 as a core in the new operating System Setting Up a User account. Managing accounts Module discusses the basic concepts of how to effectively plan user accounts. Next it overviews the process of creation and configuration of user accounts.

Students create and modify various properties of accounts as a part of the exercise. Setting Up and Managing Groups Groups in Windows 2000 as part of the administration for easier assigning user permissions. Module explains and defines the local, global and built-in groups in Windows 2000. In the exercise students create local groups, add members in the process of creation and after the groups are created and move and delete members and groups. Installing and Configuring Network Printers An introduction to Windows 2000 printing as terminology and requirements. Common troubleshooting problems and printer installation.

In the hands on lab at the end of the module - students use Install Printer Wizard to install printers on their computers. Network Printers Administration Sets the basic concepts of managing printers and documents, assigning users permissions to shared network printers, setting a separator page, taking ownership and configuring printers settings. In the exercise the students change priority of a document, set a notification, print and cancel documents. Securing Resources with NTFS Permissions Brief introduction to NTFS file system built in security. Module continues with overview of NTFS permissions and assigning them to users and groups.

Common problems and troubleshooting are discussed further. In the followed exercise the students apply NTFS permissions on folders and individual files, discuss real business scenarios and practice with taking ownership and permission change with move and copy operations. Shared Folders Implementation and administration Explains basic network connectivity concepts using shared folders. Module focuses of securing files on FAT and FAT 32 volumes trough shared folder permissions. In the exercise students share folders, assign user and group permissions and the effects of stopping a folder share.

Module includes an optional exercise witch covers security issues achieved trough combination of share and NTFS permissions. Implementing Auditing of Resources and Events Introduction to Windows 2000 Local Security and Group Polices. More attention is paid on auditing feature of the polices that gives the administrators ability to track user activities and system events. Students practice with implementing an audit policy, configuring it and using Event viewer to monitor and manage the security log file. Configuring Group Policy and Local Security Policy Module continues with Local Security and Group policy focusing on Account polices and some of the other Security Options trough Local Security and Group Security Polices snap-in in MMC. In the two exercises provided students configure and test Minimum Password Length policy and three of the Security policy settings.

Managing Data Storage Module discusses the advantages of NTFS formatted volumes. They practice setting and configuring disk quotas, increasing security trough Encrypted File System (EFS), de fragmenting a disk, compressing files and folders, and the effects on compression trough move and copy operations. Back Up and Restore After discussing the basic concepts of the backup process, module focuses on the Windows 2000 Backup utilities and tools. Explains the five different types of backup - normal, copy, incremental, differential and daily copy and also different backup and restore strategies. Students exercise using the Backup Wizard to backup file from the hard drive and to schedule a backup job to take place after the business hours. Monitoring Access to Network Resources Module introduces the Shared Folders snap in and how it can be used to monitor network resources, disconnect users from a given resource and view currently opened files.

Exercise includes practice with Shared Folders snap in for all given examples and also creating a new share or stopping a shared one. Configuring Remote Access Defines the protocols used with remote access and the new protocols and features in Windows 2000 compared to previous Microsoft Operating Systems. Students exercise with establishing Dial up connection and configuring remote access protocols. Microsoft Windows 2000 Boot Process Overview Defines the different stages in Windows 2000 boot process on Intel Based Machines. The use of the Boot. ini file, boot disk creation and general troubleshooting problems. Deploying Windows 2000 Discusses Unattended Windows 2000 installation using Setup Manager for creating an Un attend. txt file and the new System Preparation tool to prepare disk images for future installations.

It also shows the way of remote Windows 2000 installation, creation and usage of boot disks, and the differences in Windows 2000 Professional and Server installations. Finally the module explains the steps required to perform an upgrade from previous versions of Windows to Windows 2000 and how to install service packs. Configuring Windows 2000 for Mobile Computers Module shows the new features in Windows 2000 like offline folders, power schemes, Advanced Power Management and the usage of Synchronization Manager for better mobile support. Implementing, Managing, and Troubleshooting Hardware Devices and Drivers Usage of Device Manager for managing and troubleshooting various devices and upgrading to multiple CPU systems, System Information Snap in and System File Checker Utilities.

Finally attention is paid to installing, configuring and troubleshooting various devices like fax support, digital cameras and other imaging hardware and pointer devices. MODULE 2: INSTALLING, CONFIGURING AND ADMINISTERING MICROSOFT WINDOWS 2000 SERVER Core Exam 70-215 40 Hours Microsoft Windows 2000 - Introduction Overview of the features of Windows 2000, system architecture and directory infrastructure compared to previous Microsoft operating systems Installing and Configuring Microsoft Windows 2000 Server Pre installation tasks, Installation of Windows 2000 Server, troubleshooting common installation problems and upgrading from previous versions of Windows Unattended Installations of Microsoft Windows 2000 Server Covers the knowledge required to successfully prepare and run unattended installation of Windows 2000 Server Microsoft Windows 2000 File Systems The Basics of Windows 2000 disk and file system and implementation of file and folder security Advanced Files System Features Distributed File System and File Replication Service overview Active Directory Services - Overview Planning, Implementation and administration of Active Directory Structure in Windows 2000 Microsoft Windows 2000 Server - General Administration Detailed explanation of MMC usage and extended review of user and group management and group policies Administering Windows 2000 Printing Process Review Windows 2000 Network Print Process and its roots in the Active Directory Windows 2000 Network Protocols and Services Extends the knowledge of network protocols with details about TCP / IP, DHCP, WINS and DNS usage in Windows 2000 Routing and Remote Access Service Overview of Routing and Remote Access Service (RAS) focusing on installation and configuration of RAS and Virtual Private Networking (VPN) Advanced Microsoft Windows 2000 Security Detailed explanation of Kerberos V 5 protocol security in Windows 2000 and it correlation with Windows 2000 auditing features. Reliability and Availability Reviews hardware device drivers management and expands backup knowledge with the basics of Windows 2000 disaster recovery. Advanced Network Monitoring and Optimization Introduces Simple Network Management Protocol (SNMP) and the usage of Performance console, Network Monitor and Task Manager. Microsoft Windows 2000 Application Servers Focuses on installation and configuration of Internet Information Server 5.0, Terminal and Telnet Services MODULE 3: IMPLEMENTING AND ADMINISTERING MICROSOFT WINDOWS 2000 NETWORK INFRASTRUCTURE Core Exam 70-216 40 Hours Designing a Windows 2000 Network Introduction to Windows 2000 network protocols and services Implementing TCP / IP Installation and configuration of TCP / IP in Windows 2000 Implementing NWLink Installation and configuration of NWLink - Microsoft 32 bit IPX / SPX compatible protocol stack - and it's link to Novell NetWare network operating system Monitoring Network Activity Using Network Monitor - the network-monitoring tool implemented in Windows 2000 Implementing IPSec Introduction of installation and support of IPSec - new protocol security in Windows 2000 Network Host Names Resolution Process Explains different methods available in Windows 2000 for TCP / IP name resolution Domain Name System (DNS) - Implementation Windows 2000 enhanced DNS and its use in public networks name resolution Windows 2000 Domain Name Service (DNS) Overview of Windows 2000 DNS zones, and configuring DNS zones for dynamic update. Configuration of Cache-only DNS Servers, and monitoring DNS Server performance Windows Internet Name Service (WINS) WINS basic concepts and major parts overview.

Installing, configuring and troubleshooting WINS in Windows 2000 Dynamic Host Connection Protocol (DHCP) DHCP basic concepts and major parts overview. Installing, configuring and troubleshooting DHCP in Windows 2000 Remote Access Service (RAS) RAS basic concepts and major parts overview. Remote client configuration and support, and Installing, configuring and troubleshooting RAS in Windows 2000 Network Address Translation (NAT) Introduction to network address translation protocol (NAT), and the basics of one Internet connection sharing. Certificate Services Implementation Explanation of Windows 2000 powerful security service - Public Key Infrastructure (PKI). Installation and configuration of certificates. Enterprise-Wide Network Security Implementing the highest level of security for enterprise use.

MODULE 4: IMPLEMENTING AND ADMINISTERING A MICROSOFT WINDOWS 2000 DIRECTORY SERVICES INFRASTRUCTURE Core Exam 70-217 40 Hours Introduction to Microsoft Windows 2000 Introduction of Windows 2000 architecture and directory service overview. Active Directory - Introduction Defines Active Directory (AD) major parts like objects, domains, forests, trees and Organizational Units (OUs). Discusses AD's core services like global catalog, replication paths, new DNS features and transitive trust relationships Active Directory Administration Tasks and Tools Configuring Active directory, managing Active Directory integrated user and group account, auditing and monitoring resources and the usage of Active Directory tool trough snap-ins of Microsoft Management Console (MMC) Active Directory - Implementation Discusses planning and actual installation of Active Directory, operation servers roles, designing and implementation of OU infrastructure DNS role in Active Directory Definition of DNS process of name resolution and zone architecture. Students practice with configuring DNS zones, setting replication and transfer. Also is paid attention to troubleshooting common DNS problems. Sites Configuration Defines the Active Directory physical layout trough site implementation.

Discusses the Inter and Intra site replication and common problems with site creation and replication. Administering User Accounts User account creation and administration in the Active Directory. Local versus Domain Accounts, user home folders and profiles, creating, renaming, deleting and unlocking user account also as managing account properties. Administering Group Accounts Planning a strategy for group implementation, Windows 2000 built in groups and managing administration trough group permissions. Securing Network Resources Securing the directory trough NTFS user and group permissions. Assigning NTFS permissions on folders and files, troubleshooting common problems.

Shared Folders - Administration The entire process of sharing folders, assigning permissions and providing access to shared folders trough Distributed File System (DFS) Active Directory - Administration Administering Active Directory trough assigning object permissions, moving objects in and between domains, delegating administrative rights to Organizational Units (OUs), backing up, restoring and troubleshooting the Active Directory (AD). Also provides instructions on navigation in AD as locating objects and performing various administrative tasks. Group Policy - Administering Group Policy concepts, implementation and planning. Module focuses on managing software and folders trough Group Policy Objects (GPOs) and general troubleshooting. Administering a Security Configuration Securing Windows 2000 trough security templates user rights, auditing and using Security Configuration and Analysis tool Active Directory Performance Management Discusses the built in tools for Active Directory monitoring, and performance optimization. Using Remote Installation Service (RIS) for Deploying Windows 2000 Introduction to RIS functionality and discusses RIS installation and configuration MODULE 5 (ADDITIONAL CORE): DESIGNING A MICROSOFT WINDOWS 2000 DIRECTORY SERVICES INFRASTRUCTURE Core Exam 70-219 35 Hours An Overview of Microsoft Windows 2000 Active Directory Services The Active Directory (AD), as Windows 2000 logical backbone structure Designing an Active Directory Naming Strategy Locating and identifying objects in Active Directory, Ads naming strategies and DNS deployment.

Planning for Delegation of Administrative Authority Securing the Active Directory trough proper planning of delegation of administrative authority Planning a Domain Structure Developing a successful plan for domain creation, OU implementation and delegation of administrative rights Implementing a Domain Structure Planning and creation of the forest root domain and managing OU and object infrastructure. Planning a Multiple-Domain Directory Multiple domain and multiple forest planning and creation Examining Active Directory Replication Introduction to Active Directory replication Process, its components and topology, measuring replication traffic and understanding directory synchronization. Using Active Directory Sites to Manage Replication Traffic Implementation of Active Directory Sites, Data recovery process, planning for Active Directory backup and disaster recovery. Deploying Active Directory Gathering Information about an organization Developing a logical design and developing a physical design. Preparing for Schema Modifications Introduction to Active Directory Schema, Schema components, process of Schema modification and planning a Schema modification policy Planning and Implementing the Active Directory Connector Installation and configuration of Active Directory Connector. It's Structure and function, Managing Directory Object Synchronization, Monitoring and troubleshooting.

Developing an Upgrade Strategy Planning an Upgrade from Windows NT, old versus new domain structure and native and mixed mode of a Windows 2000 domain. MODULE 6 (ADDITIONAL CORE): DESIGNING A MICROSOFT WINDOWS 2000 NETWORK SERVICES INFRASTRUCTURE Core Exam 70-221 40 Hours Windows 2000 Networking Overview Introduction to Windows 2000 networking services and management design Developing a TCP / IP Networking Strategy TCP / IP Management strategy and business goals Developing a DHCP Strategy Developing DHCP implementation and management strategy Developing a DNS Strategy Developing DNS implementation and management strategy Developing a WINS Strategy Developing WINS implementation and management strategy Developing a Remote Access Strategy Developing RAS implementation and management strategy Developing a RADIUS Strategy Developing RADIUS implementation and management strategy Developing a Connection Manager Strategy Developing Connection Manager implementation and management strategy Developing an IP Routing Strategy Developing implementation and management strategy for IP Routing Services Developing a Multicasting Strategy Developing Multicasting implementation and management strategy Developing a Demand-Dial Routing Strategy Developing Dial on Demand implementation and management strategy Developing a VPN Strategy Developing VPN implementation and management strategy Developing an IPSec Strategy Developing IPSec implementation and management strategy Developing Connection Sharing implementation and management strategy MODULE 7 (ADDITIONAL CORE): DESIGNING A MICROSOFT WINDOWS 2000 MIGRATION STRATEGY Core Exam 70-222 40 Hours Introduction to Developing a Migration Strategy Planning and developing a migration strategy. Upgrading versus restructuring. Choosing a Migration Path to Windows 2000 Active Directory Defining the goals of a migration and a migration path. Gathering network information and information required for restructuring the current network. Planning Active Directory Design.

Developing a Domain Upgrade Strategy Planning a domain upgrade and recovery strategy. Planning and analyzing Active Directory paths and design. Choosing single or multiple forest structure. Planning the upgrade of the domain controllers and potential switching to native mode. Minimizing the Impact on Network Operations During an Upgrade Planning an effective upgrade with NetBIOS Services, DHCP, RAS, WINS, System Policies, Logon Scripts and LAN Manager Clients Supported. Managing new trust relationships and Group Policy Objects (GPOs) Restructuring Domains Studding the current domain security settings and successfully implementing them in the new environment.

Planning and requirements for Inter and Intra-Forest restructure scenarios. Migration of users and groups, cloning users, global and universal groups on Domain Controllers. Moving computers, local accounts and domain controllers. Additional restructure tools. Developing a Domain Restructure Strategy Examining current domain environment and choosing a Domain Restructure Strategy, Methodology and preparing to deploy the restructure plan.

Identifying and documenting the existing security structures, and determine a strategy and the right order for implementing them in the new environment. Minimizing the Impact on Network Operations During a Domain Restructure Providing reliable NetBIOS Resolution Services, DHCP, WINS, DNS and RAS trough mixed environment. Migrating Logon Scripts and System policies. Minimizing authentication issues during restructure. Providing Reliable Service Account Operation Planning to Deploy a Migration Strategy Using Microsoft Project for creating migration Plan, Vision and Scope. Identify company requirements and migration teams.

Choosing an Installation strategy and documenting the steps. Planning for smooth transition to Windows 2000..