Welcome!

Cloud Security Authors: Liz McMillan, Mark Ross-Smith, Peter Silva, Jim Hansen, LeanTaaS Blog

Related Topics: Microsoft Cloud, Cloud Security

Microsoft Cloud: Blog Feed Post

Working with Microsoft Security Tools

How many of us take for granted Microsoft’s family of tools that contribute to the security of your organization?

How many of us take for granted Microsoft’s family of tools that contribute to the security of your organization? The most commonly used and appreciated tools are:

  • Forefront Family
  • Microsoft Security Essentials
  • Windows Intune / Windows Update / Microsoft System Center Family
  • Windows Firewall (with Advanced Security)

Let’s take a look at all of these tools and their features. Then, we can look at other less popular tools offered by Microsoft — such as Microsoft Security Compliance Manager and Microsoft Security Assessment Tool.

  1. Forefront Family

Microsoft has spent a great amount of time trying to supply a manageable easy-to-use security solution for its products. The result of these efforts is the Forefront Family. It consists of several tools you can use to secure your Microsoft infrastructure. Also, it is designed to interact with other Microsoft tools, such as Active Directory, Group Policy and Windows Update.

Forefront Endpoint Protection is the enterprise-oriented product that delivers real-time, anti-virus, malware and spyware protection. Its integration with the System Center Family of managing products makes it extremely popular and easy for adoption.

Another product in the Forefront Family is Forefront Threat Management Gateway. It is the successor of the Internet Security and Acceleration (ISA) Server and provides advanced firewall functionalities, including URL filtering, intrusion prevention, HTTP/HTTPS inspection, and much more.

The two popular solutions for applications are Forefront protection for Exchange Server and Forefront protection for SharePoint. With the increasing popularity of cloud solutions, Forefront Online Protection for Exchange is used to secure the cloud-based version of Exchange – Exchange Online. All of these products can easily be managed through the Forefront Protection Server Management Console. It supports multiple servers and has great reporting capabilities.

Microsoft Forefront Identity Manager is a great tool that can help you manage access between heterogeneous systems, including Active Directory, Novell, Sun, IBM, Lotus Notes, Exchange, Oracle and SQL Server databases, SAP, and even flat file systems. It supports both password- and certificate-based access.
If you need to provide access to users outside your organization, such as partners or home-based employees, Forefront Unified Access Gateway is there to help you. It supports both VPN and Direct Access to your network and introduces policies and configurations over these connections.

  1. Microsoft Security Essentials

For end clients, who can’t afford to pay for the manageable Forefront client, Microsoft has delivered the free tool Microsoft Security Essentials, which uses the same definitions as Forefront, but lacks the manageability part.

Microsoft Security Essentials does provide antivirus, antispyware, and rootkit protection; it also supports Windows 7 and Windows Server 2008 R2; and it’s still using Dynamic Signature Service, which contributes to the daily definitions updates by detecting newly identified malware.

However, Microsoft Security Essentials doesn’t provide some of the handiest Forefront functionalities, such as Group Policy and External Device control; Network Access Protection integration (the Windows Server 2008 capability to granularly control network access based on who the client is and the groups to which the client belongs); and integrated host firewall management.

It also has the extremely useful capability of limiting processor usage during scans. Do youu ever encounter the problem of processor usage reaching 100% and the computer freezing with some other products? Microsoft promises that doesn’t happen with Microsoft Security Essentials.

  1. Updates

As keeping your system updated is a main part of its hardening, Microsoft has many tools that help you get important updates on time.

Your first option is to set your Windows Update feature to automatically download the updates from the Microsoft site. However, this way you don’t have much control over which updates get installed. You can set the feature to let you make a decision as to whether to install a particular update or not, but this then requires extra administrative efforts to achieve what is normally a simple task.

Another option is to use the Microsoft System Center Configuration Manager (SCCM) or Windows Intune to centrally manage the updates on all your clients’ computers. Both of these products offer a considerable amount of functionalities, including keeping computers up to date. While SCCM is a hosted application and needs to be installed on a local machine to work, Windows Intune is an entirely cloud-based Microsoft solution that can help you manage your network. All you need is a web browser. And with that, you can make sure your computers all over the world are properly updated.

  1. Windows Firewall (with Advanced Security)

Windows Firewall (In Windows Server 2008, it is called Windows Firewall with Advanced Security) can contribute to your current security configuration, providing a defense-in-depth mechanism for end users. If you haven’t purchased Forefront protection, then you can use the built-in Windows Firewall to specify rules regarding your inbound and outbound traffic.

  1. Microsoft Security Compliance Manager

Microsoft Security Compliance Manager includes various baseline security policies — both for client and server Windows systems and applications. The policies are based on industry practices and let you reduce the security threats your systems are exposed to. You can easily compare your existing policies with these baseline security policies for reference, or deploy the baseline policies to be sure your infrastructure is secured.

  1. Microsoft Security Assessment Tool

Microsoft Security Assessment Tool is a product that can help you secure your entire IT infrastructure by asking you various questions with a Yes/No answer. Questions are based on the ISO 17799 and NIST-800.x standards. Your answers are compared to the best practices that Microsoft has developed. Then a summary with lots of recommendations and relevant online topics is delivered to you. It can be very useful after your initial setup is completed.

If your infrastructure is now secured, take the time to set monitoring on your main servers. You can do that very easily with Monitis.

Read the original blog entry...

More Stories By Hovhannes Avoyan

Hovhannes Avoyan is the CEO of PicsArt, Inc.,

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@ThingsExpo Stories
SYS-CON Events announced today that Cloud Academy will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Cloud Academy is the industry’s most innovative, vendor-neutral cloud technology training platform. Cloud Academy provides continuous learning solutions for individuals and enterprise teams for Amazon Web Services, Microsoft Azure, Google Cloud Platform, and the most popular cloud computing technologies. Ge...
The best way to leverage your Cloud Expo presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering Cloud Expo and @ThingsExpo will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at Cloud Expo. Product announcements during our show provide your company with the most reach through our targeted audiences.
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
SYS-CON Events announced today that Outlyer, a monitoring service for DevOps and operations teams, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Outlyer is a monitoring service for DevOps and Operations teams running Cloud, SaaS, Microservices and IoT deployments. Designed for today's dynamic environments that need beyond cloud-scale monitoring, we make monitoring effortless so you...
Have you ever noticed how some IT people seem to lead successful, rewarding, and satisfying lives and careers, while others struggle? IT author and speaker Don Crawley uncovered the five principles that successful IT people use to build satisfying lives and careers and he shares them in this fast-paced, thought-provoking webinar. You'll learn the importance of striking a balance with technical skills and people skills, challenge your pre-existing ideas about IT customer service, and gain new in...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend @CloudExpo | @ThingsExpo, June 6-8, 2017, at the Javits Center in New York City, NY and October 31 - November 2, 2017, Santa Clara Convention Center, CA. Learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
SYS-CON Events announced today that CrowdReviews.com has been named “Media Sponsor” of SYS-CON's 20th International Cloud Expo, which will take place on June 6–8, 2017, at the Javits Center in New York City, NY. CrowdReviews.com is a transparent online platform for determining which products and services are the best based on the opinion of the crowd. The crowd consists of Internet users that have experienced products and services first-hand and have an interest in letting other potential buyers...
With 10 simultaneous tracks, keynotes, general sessions and targeted breakout classes, Cloud Expo and @ThingsExpo are two of the most important technology events of the year. Since its launch over eight years ago, Cloud Expo and @ThingsExpo have presented a rock star faculty as well as showcased hundreds of sponsors and exhibitors! In this blog post, I provide 7 tips on how, as part of our world-class faculty, you can deliver one of the most popular sessions at our events. But before reading the...
While not quite mainstream yet, WebRTC is starting to gain ground with Carriers, Enterprises and Independent Software Vendors (ISV’s) alike. WebRTC makes it easy for developers to add audio and video communications into their applications by using Web browsers as their platform. But like any market, every customer engagement has unique requirements, as well as constraints. And of course, one size does not fit all. In her session at WebRTC Summit, Dr. Natasha Tamaskar, Vice President, Head of C...
TechTarget storage websites are the best online information resource for news, tips and expert advice for the storage, backup and disaster recovery markets. By creating abundant, high-quality editorial content across more than 140 highly targeted technology-specific websites, TechTarget attracts and nurtures communities of technology buyers researching their companies' information technology needs. By understanding these buyers' content consumption behaviors, TechTarget creates the purchase inte...
In the enterprise today, connected IoT devices are everywhere – both inside and outside corporate environments. The need to identify, manage, control and secure a quickly growing web of connections and outside devices is making the already challenging task of security even more important, and onerous. In his session at @ThingsExpo, Rich Boyer, CISO and Chief Architect for Security at NTT i3, will discuss new ways of thinking and the approaches needed to address the emerging challenges of securit...
As cloud adoption continues to transform business, today's global enterprises are challenged with managing a growing amount of information living outside of the data center. The rapid adoption of IoT and increasingly mobile workforce are exacerbating the problem. Ensuring secure data sharing and efficient backup poses capacity and bandwidth considerations as well as policy and regulatory compliance issues.
Almost two-thirds of companies either have or soon will have IoT as the backbone of their business. Though, IoT is far more complex than most firms expected with a majority of IoT projects having failed. How can you not get trapped in the pitfalls? In his session at @ThingsExpo, Tony Shan, Chief IoTologist at Wipro, will introduce a holistic method of IoTification, which is the process of IoTifying the existing technology portfolios and business models to adopt and leverage IoT. He will delve in...
SYS-CON Events announced today that Conference Guru has been named “Media Sponsor” of SYS-CON's 20th International Cloud Expo, which will take place on June 6–8, 2017, at the Javits Center in New York City, NY. A valuable conference experience generates new contacts, sales leads, potential strategic partners and potential investors; helps gather competitive intelligence and even provides inspiration for new products and services. Conference Guru works with conference organizers to pass great dea...
SYS-CON Events announced today that LeaseWeb USA, a cloud Infrastructure-as-a-Service (IaaS) provider, will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. LeaseWeb is one of the world's largest hosting brands. The company helps customers define, develop and deploy IT infrastructure tailored to their exact business needs, by combining various kinds cloud solutions.
Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at Cloud Expo, Ed Featherston, a director and senior enterprise architect at Collaborative Consulting, discussed the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
WebRTC defines no default signaling protocol, causing fragmentation between WebRTC silos. SIP and XMPP provide possibilities, but come with considerable complexity and are not designed for use in a web environment. In his session at @ThingsExpo, Matthew Hodgson, technical co-founder of the Matrix.org, discussed how Matrix is a new non-profit Open Source Project that defines both a new HTTP-based standard for VoIP & IM signaling and provides reference implementations.
The Internet of Things is clearly many things: data collection and analytics, wearables, Smart Grids and Smart Cities, the Industrial Internet, and more. Cool platforms like Arduino, Raspberry Pi, Intel's Galileo and Edison, and a diverse world of sensors are making the IoT a great toy box for developers in all these areas. In this Power Panel at @ThingsExpo, moderated by Conference Chair Roger Strukhoff, panelists discussed what things are the most important, which will have the most profound e...
We all know that data growth is exploding and storage budgets are shrinking. Instead of showing you charts on about how much data there is, in his General Session at 17th Cloud Expo, Scott Cleland, Senior Director of Product Marketing at HGST, showed how to capture all of your data in one place. After you have your data under control, you can then analyze it in one place, saving time and resources.
SYS-CON Events announced today that Linux Academy, the foremost online Linux and cloud training platform and community, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Linux Academy was founded on the belief that providing high-quality, in-depth training should be available at an affordable price. Industry leaders in quality training, provided services, and student certification passes, its goal is to c...