Special OPS: Host and Network Security for Microsoft, UNIX, and Oracle

Chapter 6: Securing Active Directory
Chapter 10: Securing IIS
Windows 2000 and its increased functionality followed Windows NT 4.0's several years of development and growth. The platform's expanded capabilities arose from Microsoft's desire to develop their "Zero Admin Initiative," originally designed to improve interoperability, security, management, and ease of use both for system administrators and users. It incorporated a number of improvements to the former Windows NT 4.0 platform that were determined by users and developers to be needed for more security and stability. Among these, improvements were made in management tools, file security, operating system stability and expandability, and provision of network services for the enterprise or workgroup. Additionally, improvements were made to areas such as Plug and Play, memory management, and kernel protection, and a new directory service was added for incorporation of an object-oriented service that could be more closely controlled when configuring access to these objects. This new directory service allows closer control of resource access and has benefited those using the Windows platform with a potentially more secure system. Many of these changes have greatly improved the security of the previous NT 4.0 platform, but it has not made it a totally secure platform. System administrators and security professionals must be vigilant and aware of potential breach points to be successful in protecting systems using Windows 2000. During the course of this chapter, Windows 2000 changes and improvements will be covered, and the areas that are vulnerable to security problems will be...