How to Cheat at Securing SQL Server 2005

Frequently Asked Questions

The following Frequently Asked Questions, answered by the authors of this book, are designed to both measure your understanding of the concepts presented in this chapter and to assist you with real-life implementation of these concepts. To have your questions about this chapter answered by the author, browse to www.syngress.com/solutions and click on the "Ask the Author" form.

Q:

What functions are available when I raise my domain functional level?

Q:

Is there any way I can increase security in trusts between multiple forests?

Q:

I have several existing Windows NT domains, with trust relationships between them that I don't want to redo. What's going to happen to these when I upgrade to Windows Server 2003?

Q:

I'd like to secure the file permissions my server's hard drive as much as possible. What are the minimum permissions I can set on a Windows Server 2003 server without affecting how the server functions on the network?

Answers

Q:

The Windows Server 2003 domain functional level enables the following functions: domain rename tool update logon timestamp, Universal groups for both security and distribution groups, full group nesting and converting, and the use of the SID history to migrate security principals between domains.

Q:

When you create new users or computer objects in a domain, the domain SID is included in the security principal's SID to identify the domain where it was created. Outgoing external trusts use SID filtering to verify that incoming authentication requests only contain SIDs...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Operating System Software
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.