Group Policy Central

Posts tagged ‘Security Compliance Manager’

Out Now: Security Compliance Manager v2.5 Beta

imageMicrosoft has just released Security Compliance Manager v2.5 beta https://connect.microsoft.com/site715/program2682 along with a heap of new security baseline for you to use to compare against your environment. In case you are not familiar with SCM then it is a great product from Microsoft that consolidates all the best practice for their software with in-depth explanation for each setting.

Notably this new version has security baselines for Exchange Server 2010 and 2007. These baseline are also customised for the specific role of the server. Also interesting is the baseline settings not only include group policy computer settings but also Powershell command to configured aspects of the product that are not as simply to make as a registry key change.

image

As you can see from the image below the PowerShell script to perform the required configuration is listed in the detail pain…

image

As yet I can only assume you need to copy the PS command and make you own script for you to run again your exchange server. Still better than nothing… and the software is still beta so we are likely to see more improvements soon… 

Video: Security & Compliance Manager 2 (SCM) Overview

I just came across a video on TechNet Edge about Security Compliance Manager v2 with Jose & Jeff who work on this product. This video talks about the evolution of the product and has some great demo’s of the product.

image

Video Source at http://technet.microsoft.com/en-us/edge/Video/hh559198

If you would like to know more then check out one of my many SCM blog posts at http://www.grouppolicy.biz/tag/security-compliance-manager/ or learn more at http://microsoft.com/scm

Out Now: Microsoft Security Compliance Manager v2

imageMicrosoft has made available the final version Microsoft Security Compliance Manager v2 available for download. In case you don’t already know SCM is a great security analysis tool for your Microsoft products that works great with Group Policy but also with SCCM Desired Configuration Management (DCM) and Security Content Automation Protocol (SCAP).

image

If you want to learn more about SCM v2 then here is a list of my blog post on the product:

Out Now- Security Compliance Manager v2 Beta

Introducing Microsoft Security Compliance Manager v2

SCM v2 Beta: LocalGPO Rocks!

and here are some other links that are relevant.

TechEd Video- Security Configurations Simplified with the Microsoft Security Compliance Manager v2

TechNet Edge- Security Compliance Manager

The good news is that you can apply the RTM version as an upgrade if you already have the beta version installed.

So go forth, download and install it now from  Security Compliance Manager 2.

Out Now: Security Compliance Manager v2 Beta

imageA new version of the super awesome Security Compliance Manager v2 has now been released to the public on the connect web site. If you may remember Microsoft released the CTP version of this product back in march which had some of the new features:

  • Ability to Import GPO’s into Custom Baseline Templates
  • Ability to install without having to install SQL Express Instance

Well the new version is now out and besides being a lot more stable it has a super new look and feel with a few more  features…

New Look

Well the new beta is out sporting a fantastic new interface with more more features making it much easier to use with a great new (and useful) home screen. As you can see below the new layout is very different to the previous v1 and v2 CTP and has a more horizontal layout that makes it much easier for it to find the setting you are trying to find.

SO PRETTY!!!!

image

Attachments and Guidelines

Another new feature you might notice is that there is now a section called Attachments and Guidelines that has a lot of support documentation that relate to the Security baseline. This section also allows you to add your own supporting documentation to your custom baseline templates.

image

New Security Baseline Templates

You will also find that there are 4 long awaited security (beta) baseline template being released with the  SCM v2 beta, they are:

  1. Internet-Explorer-9-Security-Compliance-Baseline-Beta
  2. Windows-Server-2003-SP2-Security-Compliance-Baseline-Beta
  3. Windows-Server-2008-R2-SP1-Security-Compliance-Baseline-Beta
  4. Windows-Server-2008-SP2-Security-Compliance-Baseline-Beta

image

SCM Settings Library

One of the under the hood features that you might not necessarily notice straight away is that SCM has has its own settings database about all the Group Policy Setting. This “Settings Library” is where the additional information such as “Risk’s” and “Mitigations” is stored and matched to the Group Policy Setting in the baseline templates or imported GPO’s. This “Settings Library” can also be update when any new guidance comes out around any of the settings or when new settings are added to support future OS’s such as “Codename” Windows 8.

image

LocalGPO

LocalGPO is a tool that  allows you to do a whole bunch of stuff like import,export the local GPO setting to and from a Domain Based GPO backup. This feature is great if you want to apply a domain based policy to a non-domain computer. It also allows you to export the local settings so that you can then import and compare it against a baseline in SCM v2.

A super cool new feature of this tool is the “GPOPack” options that allows you to create a self contained/extracting file that you can use to apply security setting to a computer. This can be very useful if you want to apply a security baseline during the build of a computer using WDS or a SCCM Task Sequence.

image

Note: you will need to manual install this program from “C:\Program Files (x86)\Microsoft Security Compliance Manager\LGPO” after you have install the SCM v2 beta.

Note2: I cant seem to get the /GPOPack option to work. I have submitted a bug and will update when I get confirmation.

Update: To make the /GPOPack option to work you also need to use the /path and /export switch (see image below).

LocalGPO.wsf /path:”c:\GPOPack” /export

image

Now you have exported the GPOPack you can apply it via a SCCM Operating System Task Sequence using the command line option. This is a great way to apply a security baseline to a computer if it is not destined to be domain joined…

GPOPack.wsf /silent

image

Summary

Needless to say the product is beta and it may still have a few bugs… however if you can put up with the fact that it may have some issues the reports that it can generate can be really valuable. So check out the beta by Registering Here and then download it at SCM v2 Beta Download .

TechEd Video: Security Configurations Simplified with the Microsoft Security Compliance Manager