際際滷

際際滷Share a Scribd company logo
4/21/2010




          QU N TR M NG

 WINDOWS SERVER 2003

                      Bi 4
      CHNH SCH H TH NG




    Ch鱈nh s叩ch ti kho n ng動 i d湛ng
Windows l棚n DC c坦 2 c担ng c m i l
Domain Controller Sercurity Policy v
Domain Sercurity Policy
Domain Controller Sercurity Policy: C叩c tu畛
ch nh trong ny ch t叩c ng l棚n m叩y DC m
th担i
Domain Sercurity Policy: C叩c tu畛 ch nh trong
ny s t叩c ng l棚n ton b user tr棚n domain
L動u 箪: Sau khi tu畛 ch nh   th c thi c叩c thay  ib n
ph i vo Start ch n Run nh p l nh gpupdate /force ho c
ti n hnh logoff m叩y ho c Restart m叩y




                                                                1
4/21/2010




   Ch鱈nh s叩ch ti kho n ng動 i d湛ng
Account Policy 動 c d湛ng    ch nh c叩c
th担ng s v ti kho n ng動 i d湛ng
 C担ng c c u h狸nh: Start    Programs
 Administrative Tools   Domain Security
 Policy (domain) ho c Local Security Policy
 (ch動a n但ng c p domain, l nh t t secpol.msc)




        Ch鱈nh s叩ch ti kho n
          ng動 i d湛ng (t.t)
Ch鱈nh s叩ch m t kh u (Password Policies)
 Password Policies nh m m b o an ton cho
 ti kho n c a ng動 i d湛ng.
 Password Policies cho ph辿p qui nh  di,
     ph c t p c a m t kh u




                                                      2
4/21/2010




            Ch鱈nh s叩ch m t kh u (t.t)
   C叩c ch鱈nh s叩ch m t kh u m c               nh
       Ch鱈nh s叩ch                         M担 t               M c     nh
                            S l n t m t kh u kh担ng 動 c
Enforce Password History                                        24
                            tr湛ng nhau
                            Quy nh s ngy nhi u nh t m
Maximum Password Age                                            42
                            m t m達 ng動 i d湛ng c坦 hi u l c
                            Quy s ngy t i thi u tr動 c khi
Minimum Password Age        ng動 i d湛ng c坦 th thay i m t          1
                            m達.
Minimum Password            Chi u di ng n nh t c a m t m達       7
Length

Passwords Must Meet     M t kh u ph i c坦   ph c t p nh動:     Cho ph辿p
Complexity Requirements c坦 k箪 t hoa, th動 ng, c坦 k箪 s .

Store Password Using        M t m達 ng動 i d湛ng 動 c l動u d動 i   Kh担ng cho
Reversible Encryption for   d ng m達 h坦a                        ph辿p
All Users in the Domain




     Ch鱈nh s叩ch ti kho n ng動 i d湛ng (t.t)
   Ch鱈nh s叩ch kho叩 ti kho n (Account
   Lockout Policy)
      Account Lockout Policy quy                     nh c叩ch th c
      v th i i m kho叩 ti kho n.




                                                                                 3
4/21/2010




         Ch鱈nh s叩ch kho叩 ti kho n (t.t)
  C叩c ch鱈nh s叩ch kho叩 ti kho n m c                     nh
   Ch鱈nh s叩ch              M担 t                    Gi叩 tr m c   nh
Account Lockout   Quy nh s l n c g ng       0 (ti kho n s kh担ng b kh坦a)
Threshold          ng nh p tr動 c khi ti
                  kho n b kh坦a

Account Lockout   Quy nh th i gian kh坦a     L 0, nh動ng n u Account
Duration          ti kho n                 Lockout Threshold 動 c thi t
                                            l p th狸 gi叩 tr ny l 30 ph炭t


Reset Account     Quy nh th i gian m        L 0, nh動ng n u Account
Lockout Counter   l i s l n ng nh p        Lockout Threshold 動 c thi t
After             kh担ng thnh c担ng          l p th狸 gi叩 tr ny l 30 ph炭t




                  Ch鱈nh s叩ch c c b
  Local Policies cho ph辿p thi t l p c叩c ch鱈nh
  s叩ch gi叩m s叩t c叩c i t動 ng tr棚n m ng
      Ch鱈nh s叩ch ki m to叩n (Audit Policies) gi炭p
      gi叩m s叩t v ghi nh n c叩c s ki n di n ra trong
      h th ng




                                                                                   4
4/21/2010




                  Ch鱈nh s叩ch ki m to叩n
   C叩c l a ch n trong ch鱈nh s叩ch ki m to叩n
    Ch鱈nh s叩ch                                 M担 t
Audit Account         Ki m to叩n nh ng s ki n khi ti kho n ng nh p, h
Logon Events          th ng s ghi nh n khi ng動 i d湛ng logon, logoff ho c t o
                      m t k t n i m ng
Audit Account         H th ng s ghi nh n khi ti kho n ng動 i d湛ng ho c
Management            nh坦m c坦 s thay i th担ng tin hay c叩c thao t叩c qu n tr
                      li棚n quan n ti kho n ng動 i d湛ng
Audit Directory       Ghi nh但n vi c truy c p c叩c d ch v th動 m c
Service Access
Audit Logon Events    Ghi nh但n c叩c s ki n li棚n quan n qu叩 tr狸nh logon nh動
                      thi hnh m t logon script ho c truy c p n m t roaming
                      profile
Audit Object Access Ghi nh n vi c truy c p c叩c t p tin, th動 m c, v m叩y tin

Audit Policy Change Ghi nh n c叩c thay     i trong ch鱈nh s叩ch ki m to叩n




                  Ch鱈nh s叩ch ki m to叩n
   C叩c l a ch n trong ch鱈nh s叩ch ki m to叩n (t.t)
    Ch鱈nh s叩ch                                 M担 t
Audit privilege use   H th ng s ghi nh n l i khi b n b n thao t叩c qu n tr
                      tr棚n c叩c quy n h th ng nh動 c p ho c x坦a quy n c a
                      m t ai 坦
Audit process         Ki m to叩n ny theo d探i ho t     ng c a ch動董ng tr狸nh hay
tracking              h i u hnh
Audit system event    H th ng s ghi nh n m i khi b n kh i      ng l i m叩y
                      ho c t t m叩y




                                                                                       5
4/21/2010




         Ch鱈nh s叩ch c c b
Quy n h th ng c a ng動 i d湛ng (User
Rights Assignment)
 L quy n c p cho user th c thi m t s t叩c v
 tr棚n h th ng t c l m t s quy n m user
   動 c s d ng tr棚n server.
 C坦 2 c叩ch c p quy n h th ng cho ng動 i
 d湛ng l gia nh p ti kho n ng動 i d湛ng vo
 nh坦m t o s n (built-in) ho c d湛ng c担ng c
 User Rights Assignment      g叩n t ng quy n
 r i r c cho ng動 i d湛ng
     th棚m, b t quy n ch c n add hay remove




         Ch鱈nh s叩ch c c b
Quy n h th ng c a ng動 i d湛ng (User
Rights Assignment)




                                                     6
4/21/2010




                         Quy n h th ng
                         c a ng動 i d湛ng
   M t s quy n h th ng cho ng動 i d湛ng v nh坦m
          Quy n                                 M担 t
Access This Computer      Cho ph辿p ng動 i d湛ng truy c p m叩y t鱈nh th担ng
from the Network          qua m ng. M c nh m i ng動 i u c坦 quy n ny.
Allow log on locally      Cho ph辿p ng動 i d湛ng ng nh p c c b vo
                          server
Bypass Traverse Checking Cho ph辿p ng動 i d湛ng duy t qua c u tr炭c th動 m c
                         n u ng動 i d湛ng kh担ng c坦 quy n xem (list) n i
                         dung th動 m c ny.
Back Up Files and         Cho ph辿p ng動 i d湛ng sao l動u d ph嘆ng (backup)
Directories               c叩c t p tin v th動 m c b t ch p c叩c t p tin v th動
                          m c ny ng動 i 坦 c坦 quy n kh担ng.
Change the System Time    Cho ph辿p ng動 i d湛ng thay      i gi h th ng c a
                          m叩y t鱈nh.
Deny Access to This       Cho ph辿p b n kh坦a ng動 i d湛ng ho c nh坦m kh担ng
Computer from the          動 c truy c p n c叩c m叩y t鱈nh tr棚n m ng.
Network




                         Quy n h th ng
                         c a ng動 i d湛ng
   M t s quy n h th ng cho ng動 i d湛ng v nh坦m (t.t)
          Quy n                                 M担 t
Deny Logon Locally        Cho ph辿p b n ngn c n nh ng ng動 i d湛ng v
                          nh坦m truy c p n m叩y t鱈nh c c b .
Load and unload device    Cho ph辿p ng動 i d湛ng ci      t ho c g b driver
drivers                   c a thi t b
Log On Locally            Cho ph辿p ng動 i d湛ng logon t i m叩y t鱈nh Server.
Restore Files and         Cho ph辿p ng動 i d湛ng ph c h i t p tin v th動
Directories               m c, b t ch p ng動 i d湛ng ny c坦 quy n tr棚n file
                          v th動 m c ny hay kh担ng.
Shut Down the System      Cho ph辿p ng動 i d湛ng shut down c c b m叩y
                          Windows 2003.
Take Ownership of Files or Cho ng動 i d湛ng t動 c quy n s h u c a m t         i
Other Objects              t動 ng h th ng.




                                                                                      7
4/21/2010




                    Ch鱈nh s叩ch c c b
  C叩c l a ch n b o m t (Security Options)
      Cho ph辿p qu n tr khai b叩o th棚m th担ng s nh m tng
      t鱈nh b o m t cho h th ng




                C叩c l a ch n b o m t
  C叩c l a ch n b o m t th担ng d ng
             T棚n l a ch n                                M担 t
Shutdown: allow system to be shut        Cho ph辿p ng動 i d湛ng shutdown h
down without having to log on            th ng m kh担ng c n logon.
Audit : audit the access of global       Gi叩m s叩t vi c truy c p c叩c    i t動 ng
system objects                           h th ng ton c c.
Network security: force logoff when      T     ng log off kh i h th ng khi
logon hours expires.                     ng動 i d湛ng h t th i gian s d ng
                                         ho c ti kho n h t h n.
Interactive logon: do not require        Kh担ng y棚u c u n ba ph鱈m
CTRL+ALT+DEL                             CTRL+ALT+DEL khi logon.
Interactive logon: do not display last   Kh担ng hi n th t棚n ng動 i d湛ng 達
user name                                logon tr棚n h p tho i Logon.
Account: rename administrator            Cho ph辿p i t棚n ti kho n
account                                  Administrator thnh t棚n m i
Account: rename guest account            Cho ph辿p i t棚n ti kho n Guest
                                         thnh t棚n m i




                                                                                        8
4/21/2010




          IP Security (IPSec)
IP Security l giao th c h tr c叩c k t n i
an ton d a tr棚n IP.
IPSec l ho t    ng t ng th 3 (Network)
    s d ng IPSec b n t o ra c叩c quy t c
(rule), m t quy t c IPSec l s k t h p
gi a b l c (IPSec) v c叩c quy t叩c ng
(action)




          IP Security (IPSec)
C叩c t叩c    ng b o m t
  Block transmissons: ch c nng ngn ch n
  nh ng g坦i d li u 動 c truy n
  Encrypt transmissions: Ch c nng m達 h坦a
  nh ng g坦i tin truy n i
  Sign transmissions: Ch c nng k箪 t棚n vo g坦i
  d li u truy n nh m tr叩nh gi m u
  Permit transmissions: Ch c nng l cho ph辿p
  d li u truy n qua, d湛ng    t o ra c叩c quy t t
  h n ch m t s i u v kh担ng h n ch m t s
   i u kh叩c




                                                         9
4/21/2010




          IP Security (IPSec)
C叩c b l c (Filter) IPSec
  Filter d湛ng   th ng k棚 c叩c i u ki n  quy
  t c ho t ng.
  Gi i h n t m t叩c d ng c a c叩c t叩c ng l棚n
  m t ph m vi m叩y t鱈nh no 坦.
  B l c IPSec d a tr棚n c叩c y u t :
   a ch IP, subnet ho c t棚n DNS c a m叩y ngu n.
   a ch IP, subnet ho c t棚n DNS c a m叩y 鱈ch.
   Theo s hi u c ng (port) v ki n c ng (TCP, UDP,
    ICMP)




          IP Security (IPSec)
Tri n khai IPSec tr棚n Windows Server 2003




                                                            10
4/21/2010




    Tri n khai IPSec tr棚n Windows
             Server 2003
C叩c ch鱈nh s叩ch IPSec t o s n
 Client (Respond Only): ch鱈nh s叩ch quy nh
 m叩y t鱈nh b n kh担ng ch         ng d湛ng IPSec tr
 khi nh p y棚u c u d湛ng IPSec t m叩y i t叩c.
 Server (Request Security): quy nh m叩y
 server c a b n ch        ng kh i t o IPSec m i
 khi thi t l p k t n坦i t i m叩y kh叩c
 Secure Server (Require Security): quy nh
 kh担ng cho ph辿p b t k畛 cu c trao i d li u
 no v i Server hi n t i kh担ng d湛ng IPSec
 VD: t o ch鱈nh s叩ch IPSec m b o k t n i m達
 h坦a




                                                        11

More Related Content

Similar to Bai 04 chinh sach he thong (20)

Bao cao thuc tap
Bao cao thuc tapBao cao thuc tap
Bao cao thuc tap
H狸nh V担
Bao cao thuc tap athena chinh sua
Bao cao thuc tap athena chinh suaBao cao thuc tap athena chinh sua
Bao cao thuc tap athena chinh sua
H狸nh V担
際際滷 C叩c k畛 thu畉t b畉o tr狸 ph畉n m畛m
際際滷 C叩c k畛 thu畉t b畉o tr狸 ph畉n m畛m際際滷 C叩c k畛 thu畉t b畉o tr狸 ph畉n m畛m
際際滷 C叩c k畛 thu畉t b畉o tr狸 ph畉n m畛m
Nguy畛n Anh
Gpo
GpoGpo
Gpo
it
Ql chi phi dtxd cong trinh
Ql chi phi dtxd cong trinhQl chi phi dtxd cong trinh
Ql chi phi dtxd cong trinh
tuyenximangxuanthanh
De cuong mang may tinh 3f-hedspi.net
De cuong mang may tinh   3f-hedspi.netDe cuong mang may tinh   3f-hedspi.net
De cuong mang may tinh 3f-hedspi.net
Tonachi Shika
Bc th畛c t畉p nghi棚n c畛u, ph叩t tri畛n x但y d畛ng h畛 th畛ng gi叩m s叩t m畉ng b畉ng ph畉n ...
Bc th畛c t畉p nghi棚n c畛u, ph叩t tri畛n x但y d畛ng h畛 th畛ng gi叩m s叩t m畉ng b畉ng ph畉n ...Bc th畛c t畉p nghi棚n c畛u, ph叩t tri畛n x但y d畛ng h畛 th畛ng gi叩m s叩t m畉ng b畉ng ph畉n ...
Bc th畛c t畉p nghi棚n c畛u, ph叩t tri畛n x但y d畛ng h畛 th畛ng gi叩m s叩t m畉ng b畉ng ph畉n ...
nataliej4
Gpedit.msc
Gpedit.mscGpedit.msc
Gpedit.msc
laonap166
Gioi thieu phan mem quan ly nhan su tien luong comtek.hrm v2
Gioi thieu phan mem quan ly nhan su tien luong comtek.hrm v2Gioi thieu phan mem quan ly nhan su tien luong comtek.hrm v2
Gioi thieu phan mem quan ly nhan su tien luong comtek.hrm v2
Snoozeloop AF
Bai 03 quan ly tai khoan nguoi dung
Bai 03   quan ly tai khoan nguoi dungBai 03   quan ly tai khoan nguoi dung
Bai 03 quan ly tai khoan nguoi dung
Van Pham
Lecture chinhsachhethong
Lecture chinhsachhethongLecture chinhsachhethong
Lecture chinhsachhethong
Nguyen Cuong
C担ng ngh畛 y棚u c但u requirements engineering (re)
C担ng ngh畛 y棚u c但u requirements engineering (re)C担ng ngh畛 y棚u c但u requirements engineering (re)
C担ng ngh畛 y棚u c但u requirements engineering (re)
nataliej4
Tkh.畛ng d畛ng tin h畛c trong ho畉t 畛ng ki畛m to叩n nguy畛n 狸nh h畛u[bookbooming...
Tkh.畛ng d畛ng tin h畛c trong ho畉t 畛ng ki畛m to叩n   nguy畛n 狸nh h畛u[bookbooming...Tkh.畛ng d畛ng tin h畛c trong ho畉t 畛ng ki畛m to叩n   nguy畛n 狸nh h畛u[bookbooming...
Tkh.畛ng d畛ng tin h畛c trong ho畉t 畛ng ki畛m to叩n nguy畛n 狸nh h畛u[bookbooming...
bookbooming1
13.chap13 distributed systems
13.chap13 distributed systems13.chap13 distributed systems
13.chap13 distributed systems
Linh Nguy畛n Thanh
Chuong 10 multi user
Chuong 10   multi userChuong 10   multi user
Chuong 10 multi user
Hung Pham Thai
Chuy棚n 畛 group policy
Chuy棚n 畛 group policyChuy棚n 畛 group policy
Chuy棚n 畛 group policy
B狸nh Tr畛ng n
BI GI畉NG QTHT WEB-MAIL SERVER.ppt
BI GI畉NG QTHT WEB-MAIL SERVER.pptBI GI畉NG QTHT WEB-MAIL SERVER.ppt
BI GI畉NG QTHT WEB-MAIL SERVER.ppt
ssuser95e69d
Lecture chinhsachnhom
Lecture chinhsachnhomLecture chinhsachnhom
Lecture chinhsachnhom
L達 畉t
Khoa.pptx
Khoa.pptxKhoa.pptx
Khoa.pptx
HongHoi11
Bao cao thuc tap
Bao cao thuc tapBao cao thuc tap
Bao cao thuc tap
H狸nh V担
Bao cao thuc tap athena chinh sua
Bao cao thuc tap athena chinh suaBao cao thuc tap athena chinh sua
Bao cao thuc tap athena chinh sua
H狸nh V担
際際滷 C叩c k畛 thu畉t b畉o tr狸 ph畉n m畛m
際際滷 C叩c k畛 thu畉t b畉o tr狸 ph畉n m畛m際際滷 C叩c k畛 thu畉t b畉o tr狸 ph畉n m畛m
際際滷 C叩c k畛 thu畉t b畉o tr狸 ph畉n m畛m
Nguy畛n Anh
Gpo
GpoGpo
Gpo
it
De cuong mang may tinh 3f-hedspi.net
De cuong mang may tinh   3f-hedspi.netDe cuong mang may tinh   3f-hedspi.net
De cuong mang may tinh 3f-hedspi.net
Tonachi Shika
Bc th畛c t畉p nghi棚n c畛u, ph叩t tri畛n x但y d畛ng h畛 th畛ng gi叩m s叩t m畉ng b畉ng ph畉n ...
Bc th畛c t畉p nghi棚n c畛u, ph叩t tri畛n x但y d畛ng h畛 th畛ng gi叩m s叩t m畉ng b畉ng ph畉n ...Bc th畛c t畉p nghi棚n c畛u, ph叩t tri畛n x但y d畛ng h畛 th畛ng gi叩m s叩t m畉ng b畉ng ph畉n ...
Bc th畛c t畉p nghi棚n c畛u, ph叩t tri畛n x但y d畛ng h畛 th畛ng gi叩m s叩t m畉ng b畉ng ph畉n ...
nataliej4
Gpedit.msc
Gpedit.mscGpedit.msc
Gpedit.msc
laonap166
Gioi thieu phan mem quan ly nhan su tien luong comtek.hrm v2
Gioi thieu phan mem quan ly nhan su tien luong comtek.hrm v2Gioi thieu phan mem quan ly nhan su tien luong comtek.hrm v2
Gioi thieu phan mem quan ly nhan su tien luong comtek.hrm v2
Snoozeloop AF
Bai 03 quan ly tai khoan nguoi dung
Bai 03   quan ly tai khoan nguoi dungBai 03   quan ly tai khoan nguoi dung
Bai 03 quan ly tai khoan nguoi dung
Van Pham
Lecture chinhsachhethong
Lecture chinhsachhethongLecture chinhsachhethong
Lecture chinhsachhethong
Nguyen Cuong
C担ng ngh畛 y棚u c但u requirements engineering (re)
C担ng ngh畛 y棚u c但u requirements engineering (re)C担ng ngh畛 y棚u c但u requirements engineering (re)
C担ng ngh畛 y棚u c但u requirements engineering (re)
nataliej4
Tkh.畛ng d畛ng tin h畛c trong ho畉t 畛ng ki畛m to叩n nguy畛n 狸nh h畛u[bookbooming...
Tkh.畛ng d畛ng tin h畛c trong ho畉t 畛ng ki畛m to叩n   nguy畛n 狸nh h畛u[bookbooming...Tkh.畛ng d畛ng tin h畛c trong ho畉t 畛ng ki畛m to叩n   nguy畛n 狸nh h畛u[bookbooming...
Tkh.畛ng d畛ng tin h畛c trong ho畉t 畛ng ki畛m to叩n nguy畛n 狸nh h畛u[bookbooming...
bookbooming1
13.chap13 distributed systems
13.chap13 distributed systems13.chap13 distributed systems
13.chap13 distributed systems
Linh Nguy畛n Thanh
Chuong 10 multi user
Chuong 10   multi userChuong 10   multi user
Chuong 10 multi user
Hung Pham Thai
Chuy棚n 畛 group policy
Chuy棚n 畛 group policyChuy棚n 畛 group policy
Chuy棚n 畛 group policy
B狸nh Tr畛ng n
BI GI畉NG QTHT WEB-MAIL SERVER.ppt
BI GI畉NG QTHT WEB-MAIL SERVER.pptBI GI畉NG QTHT WEB-MAIL SERVER.ppt
BI GI畉NG QTHT WEB-MAIL SERVER.ppt
ssuser95e69d
Lecture chinhsachnhom
Lecture chinhsachnhomLecture chinhsachnhom
Lecture chinhsachnhom
L達 畉t
Khoa.pptx
Khoa.pptxKhoa.pptx
Khoa.pptx
HongHoi11

More from Van Pham (20)

Thi cong da hoa cuong o tphcm thien loc phat
Thi cong da hoa cuong o tphcm thien loc phatThi cong da hoa cuong o tphcm thien loc phat
Thi cong da hoa cuong o tphcm thien loc phat
Van Pham
C畛a hng b叩n 畛 ch董i xe m叩y 畛 TPHCM - Hong Ph炭c Decal
C畛a hng b叩n 畛 ch董i xe m叩y 畛 TPHCM - Hong Ph炭c DecalC畛a hng b叩n 畛 ch董i xe m叩y 畛 TPHCM - Hong Ph炭c Decal
C畛a hng b叩n 畛 ch董i xe m叩y 畛 TPHCM - Hong Ph炭c Decal
Van Pham
Giao trinh co so du lieu can ban
Giao trinh co so du lieu can banGiao trinh co so du lieu can ban
Giao trinh co so du lieu can ban
Van Pham
Avl tree
Avl treeAvl tree
Avl tree
Van Pham
Quy t畉c
Quy t畉cQuy t畉c
Quy t畉c
Van Pham
Lect15 cloud
Lect15 cloudLect15 cloud
Lect15 cloud
Van Pham
Session1
Session1Session1
Session1
Van Pham
172506 633746925739945000
172506 633746925739945000172506 633746925739945000
172506 633746925739945000
Van Pham
Bao cao thuc tap - i畛n to叩n 叩m m但y
Bao cao thuc tap - i畛n to叩n 叩m m但yBao cao thuc tap - i畛n to叩n 叩m m但y
Bao cao thuc tap - i畛n to叩n 叩m m但y
Van Pham
Bai 02 active directory
Bai 02   active directoryBai 02   active directory
Bai 02 active directory
Van Pham
Gioi thieu va cac lenh tren console
Gioi thieu va cac lenh tren consoleGioi thieu va cac lenh tren console
Gioi thieu va cac lenh tren console
Van Pham
Bai 08 quan ly in an
Bai 08   quan ly in anBai 08   quan ly in an
Bai 08 quan ly in an
Van Pham
Bai 07 tao quan ly thu muc
Bai 07   tao quan ly thu mucBai 07   tao quan ly thu muc
Bai 07 tao quan ly thu muc
Van Pham
Bai 06 quan ly dia
Bai 06   quan ly diaBai 06   quan ly dia
Bai 06 quan ly dia
Van Pham
Bai 01 gioi thieu cai dat
Bai 01   gioi thieu cai datBai 01   gioi thieu cai dat
Bai 01 gioi thieu cai dat
Van Pham
Bai12 too ls-kiemtra-ktrpm@softtesting-nntu
Bai12 too ls-kiemtra-ktrpm@softtesting-nntuBai12 too ls-kiemtra-ktrpm@softtesting-nntu
Bai12 too ls-kiemtra-ktrpm@softtesting-nntu
Van Pham
Bai11 quan ly-kiemtra-ktrpm@softtesting-nntu
Bai11 quan ly-kiemtra-ktrpm@softtesting-nntuBai11 quan ly-kiemtra-ktrpm@softtesting-nntu
Bai11 quan ly-kiemtra-ktrpm@softtesting-nntu
Van Pham
Bai10 lap tailieukiemtra-k-trpm@softtesting-nntu
Bai10 lap tailieukiemtra-k-trpm@softtesting-nntuBai10 lap tailieukiemtra-k-trpm@softtesting-nntu
Bai10 lap tailieukiemtra-k-trpm@softtesting-nntu
Van Pham
Bai09 kiem traextreme-k-trpm@softtesting-nntu
Bai09 kiem traextreme-k-trpm@softtesting-nntuBai09 kiem traextreme-k-trpm@softtesting-nntu
Bai09 kiem traextreme-k-trpm@softtesting-nntu
Van Pham
Bai08 ky thuatdebug-k-trpm@softtesting-nntu
Bai08 ky thuatdebug-k-trpm@softtesting-nntuBai08 ky thuatdebug-k-trpm@softtesting-nntu
Bai08 ky thuatdebug-k-trpm@softtesting-nntu
Van Pham
Thi cong da hoa cuong o tphcm thien loc phat
Thi cong da hoa cuong o tphcm thien loc phatThi cong da hoa cuong o tphcm thien loc phat
Thi cong da hoa cuong o tphcm thien loc phat
Van Pham
C畛a hng b叩n 畛 ch董i xe m叩y 畛 TPHCM - Hong Ph炭c Decal
C畛a hng b叩n 畛 ch董i xe m叩y 畛 TPHCM - Hong Ph炭c DecalC畛a hng b叩n 畛 ch董i xe m叩y 畛 TPHCM - Hong Ph炭c Decal
C畛a hng b叩n 畛 ch董i xe m叩y 畛 TPHCM - Hong Ph炭c Decal
Van Pham
Giao trinh co so du lieu can ban
Giao trinh co so du lieu can banGiao trinh co so du lieu can ban
Giao trinh co so du lieu can ban
Van Pham
Avl tree
Avl treeAvl tree
Avl tree
Van Pham
Quy t畉c
Quy t畉cQuy t畉c
Quy t畉c
Van Pham
Lect15 cloud
Lect15 cloudLect15 cloud
Lect15 cloud
Van Pham
Session1
Session1Session1
Session1
Van Pham
172506 633746925739945000
172506 633746925739945000172506 633746925739945000
172506 633746925739945000
Van Pham
Bao cao thuc tap - i畛n to叩n 叩m m但y
Bao cao thuc tap - i畛n to叩n 叩m m但yBao cao thuc tap - i畛n to叩n 叩m m但y
Bao cao thuc tap - i畛n to叩n 叩m m但y
Van Pham
Bai 02 active directory
Bai 02   active directoryBai 02   active directory
Bai 02 active directory
Van Pham
Gioi thieu va cac lenh tren console
Gioi thieu va cac lenh tren consoleGioi thieu va cac lenh tren console
Gioi thieu va cac lenh tren console
Van Pham
Bai 08 quan ly in an
Bai 08   quan ly in anBai 08   quan ly in an
Bai 08 quan ly in an
Van Pham
Bai 07 tao quan ly thu muc
Bai 07   tao quan ly thu mucBai 07   tao quan ly thu muc
Bai 07 tao quan ly thu muc
Van Pham
Bai 06 quan ly dia
Bai 06   quan ly diaBai 06   quan ly dia
Bai 06 quan ly dia
Van Pham
Bai 01 gioi thieu cai dat
Bai 01   gioi thieu cai datBai 01   gioi thieu cai dat
Bai 01 gioi thieu cai dat
Van Pham
Bai12 too ls-kiemtra-ktrpm@softtesting-nntu
Bai12 too ls-kiemtra-ktrpm@softtesting-nntuBai12 too ls-kiemtra-ktrpm@softtesting-nntu
Bai12 too ls-kiemtra-ktrpm@softtesting-nntu
Van Pham
Bai11 quan ly-kiemtra-ktrpm@softtesting-nntu
Bai11 quan ly-kiemtra-ktrpm@softtesting-nntuBai11 quan ly-kiemtra-ktrpm@softtesting-nntu
Bai11 quan ly-kiemtra-ktrpm@softtesting-nntu
Van Pham
Bai10 lap tailieukiemtra-k-trpm@softtesting-nntu
Bai10 lap tailieukiemtra-k-trpm@softtesting-nntuBai10 lap tailieukiemtra-k-trpm@softtesting-nntu
Bai10 lap tailieukiemtra-k-trpm@softtesting-nntu
Van Pham
Bai09 kiem traextreme-k-trpm@softtesting-nntu
Bai09 kiem traextreme-k-trpm@softtesting-nntuBai09 kiem traextreme-k-trpm@softtesting-nntu
Bai09 kiem traextreme-k-trpm@softtesting-nntu
Van Pham
Bai08 ky thuatdebug-k-trpm@softtesting-nntu
Bai08 ky thuatdebug-k-trpm@softtesting-nntuBai08 ky thuatdebug-k-trpm@softtesting-nntu
Bai08 ky thuatdebug-k-trpm@softtesting-nntu
Van Pham

Recently uploaded (18)

Bi gi畉ng LS.pptx.pptx Bi gi畉ng LS.pptx.pptx
Bi gi畉ng LS.pptx.pptx Bi gi畉ng LS.pptx.pptxBi gi畉ng LS.pptx.pptx Bi gi畉ng LS.pptx.pptx
Bi gi畉ng LS.pptx.pptx Bi gi畉ng LS.pptx.pptx
2251010138
Bac gau den va hai chu tho co NGUYET.ppt
Bac gau den va hai chu tho co NGUYET.pptBac gau den va hai chu tho co NGUYET.ppt
Bac gau den va hai chu tho co NGUYET.ppt
LuPhm10
cd-van-6_-t47-b4-thtv-tu-dong-am-tu-da-nghia_11072023.pptx
cd-van-6_-t47-b4-thtv-tu-dong-am-tu-da-nghia_11072023.pptxcd-van-6_-t47-b4-thtv-tu-dong-am-tu-da-nghia_11072023.pptx
cd-van-6_-t47-b4-thtv-tu-dong-am-tu-da-nghia_11072023.pptx
ThyLinh936093
[PPT11] Bi 7 - 畛c - V t担i v畉n mu畛n m畉....ppt
[PPT11] Bi 7 - 畛c - V t担i v畉n mu畛n m畉....ppt[PPT11] Bi 7 - 畛c - V t担i v畉n mu畛n m畉....ppt
[PPT11] Bi 7 - 畛c - V t担i v畉n mu畛n m畉....ppt
phuonguyn2400
[PPT11] Bi 7 - 畛c - C Mau qu棚 x畛.pptx
[PPT11] Bi 7 - 畛c - C Mau qu棚 x畛.pptx[PPT11] Bi 7 - 畛c - C Mau qu棚 x畛.pptx
[PPT11] Bi 7 - 畛c - C Mau qu棚 x畛.pptx
phuonguyn2400
Gi叩o 叩n Ng畛 vn 10 KNTT B畛 2 NG働畛I C畉M QUY畛N....docx
Gi叩o 叩n Ng畛 vn 10 KNTT B畛 2 NG働畛I C畉M QUY畛N....docxGi叩o 叩n Ng畛 vn 10 KNTT B畛 2 NG働畛I C畉M QUY畛N....docx
Gi叩o 叩n Ng畛 vn 10 KNTT B畛 2 NG働畛I C畉M QUY畛N....docx
thanhyt004
373E879C-764F-11EF-AA2F-F5F8FA70038B.pdf
373E879C-764F-11EF-AA2F-F5F8FA70038B.pdf373E879C-764F-11EF-AA2F-F5F8FA70038B.pdf
373E879C-764F-11EF-AA2F-F5F8FA70038B.pdf
KimAnhDng
pppppp.pptxmmmmmmmmmmmmmmmmmoommmmmmmmmmmmmmmmm
pppppp.pptxmmmmmmmmmmmmmmmmmoommmmmmmmmmmmmmmmmpppppp.pptxmmmmmmmmmmmmmmmmmoommmmmmmmmmmmmmmmm
pppppp.pptxmmmmmmmmmmmmmmmmmoommmmmmmmmmmmmmmmm
ngPhan57
MICE Tr動畛ng Anh ng畛 IU Cebu Brochure 2025.pdf
MICE Tr動畛ng Anh ng畛 IU Cebu Brochure 2025.pdfMICE Tr動畛ng Anh ng畛 IU Cebu Brochure 2025.pdf
MICE Tr動畛ng Anh ng畛 IU Cebu Brochure 2025.pdf
Du h畛c MICE - Du h畛c ti畉ng Anh
bac-gau-den-va-hai-chu-tho-co-chu_02122022.ppt
bac-gau-den-va-hai-chu-tho-co-chu_02122022.pptbac-gau-den-va-hai-chu-tho-co-chu_02122022.ppt
bac-gau-den-va-hai-chu-tho-co-chu_02122022.ppt
LuPhm10
Cours 3 Les voyelles nasales semi voyelles.pptx
Cours 3 Les voyelles nasales semi voyelles.pptxCours 3 Les voyelles nasales semi voyelles.pptx
Cours 3 Les voyelles nasales semi voyelles.pptx
HaihuyDong
CHINH PH畛C L THUY畉T SINH H畛C B畉NG S 畛 T働 DUY.pdf
CHINH PH畛C L THUY畉T SINH H畛C B畉NG S 畛 T働 DUY.pdfCHINH PH畛C L THUY畉T SINH H畛C B畉NG S 畛 T働 DUY.pdf
CHINH PH畛C L THUY畉T SINH H畛C B畉NG S 畛 T働 DUY.pdf
Huyn804581
Bi gi畉ng TTHCM.pptx Bi gi畉ng TTHCMBi gi畉ng TTHCM
Bi gi畉ng TTHCM.pptx Bi gi畉ng TTHCMBi gi畉ng TTHCMBi gi畉ng TTHCM.pptx Bi gi畉ng TTHCMBi gi畉ng TTHCM
Bi gi畉ng TTHCM.pptx Bi gi畉ng TTHCMBi gi畉ng TTHCM
2251010138
Airport Vocabulary IN ENGLISH BBBHHBHBHBHB
Airport Vocabulary IN ENGLISH BBBHHBHBHBHBAirport Vocabulary IN ENGLISH BBBHHBHBHBHB
Airport Vocabulary IN ENGLISH BBBHHBHBHBHB
HBng40
Bac gau den va hai chu tho co NGUYET.ppt
Bac gau den va hai chu tho co NGUYET.pptBac gau den va hai chu tho co NGUYET.ppt
Bac gau den va hai chu tho co NGUYET.ppt
LuPhm10
GRAMMAR PRACTICE TEST 01 ANSWER KEY.docx
GRAMMAR PRACTICE TEST 01 ANSWER KEY.docxGRAMMAR PRACTICE TEST 01 ANSWER KEY.docx
GRAMMAR PRACTICE TEST 01 ANSWER KEY.docx
AnhDuc498595
Ch動董ng 3. 畛i l動u nhi畛t. h坦a h畛u c董 TDTU
Ch動董ng 3.  畛i l動u nhi畛t. h坦a h畛u c董 TDTUCh動董ng 3.  畛i l動u nhi畛t. h坦a h畛u c董 TDTU
Ch動董ng 3. 畛i l動u nhi畛t. h坦a h畛u c董 TDTU
ngKhi80
Nghi棚n c畛u sinh h畛c v畛 畛t bi畉n Nhi畛m s畉c th畛
Nghi棚n c畛u sinh h畛c v畛 畛t bi畉n Nhi畛m s畉c th畛Nghi棚n c畛u sinh h畛c v畛 畛t bi畉n Nhi畛m s畉c th畛
Nghi棚n c畛u sinh h畛c v畛 畛t bi畉n Nhi畛m s畉c th畛
nguyenphuonguyen1412
Bi gi畉ng LS.pptx.pptx Bi gi畉ng LS.pptx.pptx
Bi gi畉ng LS.pptx.pptx Bi gi畉ng LS.pptx.pptxBi gi畉ng LS.pptx.pptx Bi gi畉ng LS.pptx.pptx
Bi gi畉ng LS.pptx.pptx Bi gi畉ng LS.pptx.pptx
2251010138
Bac gau den va hai chu tho co NGUYET.ppt
Bac gau den va hai chu tho co NGUYET.pptBac gau den va hai chu tho co NGUYET.ppt
Bac gau den va hai chu tho co NGUYET.ppt
LuPhm10
cd-van-6_-t47-b4-thtv-tu-dong-am-tu-da-nghia_11072023.pptx
cd-van-6_-t47-b4-thtv-tu-dong-am-tu-da-nghia_11072023.pptxcd-van-6_-t47-b4-thtv-tu-dong-am-tu-da-nghia_11072023.pptx
cd-van-6_-t47-b4-thtv-tu-dong-am-tu-da-nghia_11072023.pptx
ThyLinh936093
[PPT11] Bi 7 - 畛c - V t担i v畉n mu畛n m畉....ppt
[PPT11] Bi 7 - 畛c - V t担i v畉n mu畛n m畉....ppt[PPT11] Bi 7 - 畛c - V t担i v畉n mu畛n m畉....ppt
[PPT11] Bi 7 - 畛c - V t担i v畉n mu畛n m畉....ppt
phuonguyn2400
[PPT11] Bi 7 - 畛c - C Mau qu棚 x畛.pptx
[PPT11] Bi 7 - 畛c - C Mau qu棚 x畛.pptx[PPT11] Bi 7 - 畛c - C Mau qu棚 x畛.pptx
[PPT11] Bi 7 - 畛c - C Mau qu棚 x畛.pptx
phuonguyn2400
Gi叩o 叩n Ng畛 vn 10 KNTT B畛 2 NG働畛I C畉M QUY畛N....docx
Gi叩o 叩n Ng畛 vn 10 KNTT B畛 2 NG働畛I C畉M QUY畛N....docxGi叩o 叩n Ng畛 vn 10 KNTT B畛 2 NG働畛I C畉M QUY畛N....docx
Gi叩o 叩n Ng畛 vn 10 KNTT B畛 2 NG働畛I C畉M QUY畛N....docx
thanhyt004
373E879C-764F-11EF-AA2F-F5F8FA70038B.pdf
373E879C-764F-11EF-AA2F-F5F8FA70038B.pdf373E879C-764F-11EF-AA2F-F5F8FA70038B.pdf
373E879C-764F-11EF-AA2F-F5F8FA70038B.pdf
KimAnhDng
pppppp.pptxmmmmmmmmmmmmmmmmmoommmmmmmmmmmmmmmmm
pppppp.pptxmmmmmmmmmmmmmmmmmoommmmmmmmmmmmmmmmmpppppp.pptxmmmmmmmmmmmmmmmmmoommmmmmmmmmmmmmmmm
pppppp.pptxmmmmmmmmmmmmmmmmmoommmmmmmmmmmmmmmmm
ngPhan57
bac-gau-den-va-hai-chu-tho-co-chu_02122022.ppt
bac-gau-den-va-hai-chu-tho-co-chu_02122022.pptbac-gau-den-va-hai-chu-tho-co-chu_02122022.ppt
bac-gau-den-va-hai-chu-tho-co-chu_02122022.ppt
LuPhm10
Cours 3 Les voyelles nasales semi voyelles.pptx
Cours 3 Les voyelles nasales semi voyelles.pptxCours 3 Les voyelles nasales semi voyelles.pptx
Cours 3 Les voyelles nasales semi voyelles.pptx
HaihuyDong
CHINH PH畛C L THUY畉T SINH H畛C B畉NG S 畛 T働 DUY.pdf
CHINH PH畛C L THUY畉T SINH H畛C B畉NG S 畛 T働 DUY.pdfCHINH PH畛C L THUY畉T SINH H畛C B畉NG S 畛 T働 DUY.pdf
CHINH PH畛C L THUY畉T SINH H畛C B畉NG S 畛 T働 DUY.pdf
Huyn804581
Bi gi畉ng TTHCM.pptx Bi gi畉ng TTHCMBi gi畉ng TTHCM
Bi gi畉ng TTHCM.pptx Bi gi畉ng TTHCMBi gi畉ng TTHCMBi gi畉ng TTHCM.pptx Bi gi畉ng TTHCMBi gi畉ng TTHCM
Bi gi畉ng TTHCM.pptx Bi gi畉ng TTHCMBi gi畉ng TTHCM
2251010138
Airport Vocabulary IN ENGLISH BBBHHBHBHBHB
Airport Vocabulary IN ENGLISH BBBHHBHBHBHBAirport Vocabulary IN ENGLISH BBBHHBHBHBHB
Airport Vocabulary IN ENGLISH BBBHHBHBHBHB
HBng40
Bac gau den va hai chu tho co NGUYET.ppt
Bac gau den va hai chu tho co NGUYET.pptBac gau den va hai chu tho co NGUYET.ppt
Bac gau den va hai chu tho co NGUYET.ppt
LuPhm10
GRAMMAR PRACTICE TEST 01 ANSWER KEY.docx
GRAMMAR PRACTICE TEST 01 ANSWER KEY.docxGRAMMAR PRACTICE TEST 01 ANSWER KEY.docx
GRAMMAR PRACTICE TEST 01 ANSWER KEY.docx
AnhDuc498595
Ch動董ng 3. 畛i l動u nhi畛t. h坦a h畛u c董 TDTU
Ch動董ng 3.  畛i l動u nhi畛t. h坦a h畛u c董 TDTUCh動董ng 3.  畛i l動u nhi畛t. h坦a h畛u c董 TDTU
Ch動董ng 3. 畛i l動u nhi畛t. h坦a h畛u c董 TDTU
ngKhi80
Nghi棚n c畛u sinh h畛c v畛 畛t bi畉n Nhi畛m s畉c th畛
Nghi棚n c畛u sinh h畛c v畛 畛t bi畉n Nhi畛m s畉c th畛Nghi棚n c畛u sinh h畛c v畛 畛t bi畉n Nhi畛m s畉c th畛
Nghi棚n c畛u sinh h畛c v畛 畛t bi畉n Nhi畛m s畉c th畛
nguyenphuonguyen1412

Bai 04 chinh sach he thong

  • 1. 4/21/2010 QU N TR M NG WINDOWS SERVER 2003 Bi 4 CHNH SCH H TH NG Ch鱈nh s叩ch ti kho n ng動 i d湛ng Windows l棚n DC c坦 2 c担ng c m i l Domain Controller Sercurity Policy v Domain Sercurity Policy Domain Controller Sercurity Policy: C叩c tu畛 ch nh trong ny ch t叩c ng l棚n m叩y DC m th担i Domain Sercurity Policy: C叩c tu畛 ch nh trong ny s t叩c ng l棚n ton b user tr棚n domain L動u 箪: Sau khi tu畛 ch nh th c thi c叩c thay ib n ph i vo Start ch n Run nh p l nh gpupdate /force ho c ti n hnh logoff m叩y ho c Restart m叩y 1
  • 2. 4/21/2010 Ch鱈nh s叩ch ti kho n ng動 i d湛ng Account Policy 動 c d湛ng ch nh c叩c th担ng s v ti kho n ng動 i d湛ng C担ng c c u h狸nh: Start Programs Administrative Tools Domain Security Policy (domain) ho c Local Security Policy (ch動a n但ng c p domain, l nh t t secpol.msc) Ch鱈nh s叩ch ti kho n ng動 i d湛ng (t.t) Ch鱈nh s叩ch m t kh u (Password Policies) Password Policies nh m m b o an ton cho ti kho n c a ng動 i d湛ng. Password Policies cho ph辿p qui nh di, ph c t p c a m t kh u 2
  • 3. 4/21/2010 Ch鱈nh s叩ch m t kh u (t.t) C叩c ch鱈nh s叩ch m t kh u m c nh Ch鱈nh s叩ch M担 t M c nh S l n t m t kh u kh担ng 動 c Enforce Password History 24 tr湛ng nhau Quy nh s ngy nhi u nh t m Maximum Password Age 42 m t m達 ng動 i d湛ng c坦 hi u l c Quy s ngy t i thi u tr動 c khi Minimum Password Age ng動 i d湛ng c坦 th thay i m t 1 m達. Minimum Password Chi u di ng n nh t c a m t m達 7 Length Passwords Must Meet M t kh u ph i c坦 ph c t p nh動: Cho ph辿p Complexity Requirements c坦 k箪 t hoa, th動 ng, c坦 k箪 s . Store Password Using M t m達 ng動 i d湛ng 動 c l動u d動 i Kh担ng cho Reversible Encryption for d ng m達 h坦a ph辿p All Users in the Domain Ch鱈nh s叩ch ti kho n ng動 i d湛ng (t.t) Ch鱈nh s叩ch kho叩 ti kho n (Account Lockout Policy) Account Lockout Policy quy nh c叩ch th c v th i i m kho叩 ti kho n. 3
  • 4. 4/21/2010 Ch鱈nh s叩ch kho叩 ti kho n (t.t) C叩c ch鱈nh s叩ch kho叩 ti kho n m c nh Ch鱈nh s叩ch M担 t Gi叩 tr m c nh Account Lockout Quy nh s l n c g ng 0 (ti kho n s kh担ng b kh坦a) Threshold ng nh p tr動 c khi ti kho n b kh坦a Account Lockout Quy nh th i gian kh坦a L 0, nh動ng n u Account Duration ti kho n Lockout Threshold 動 c thi t l p th狸 gi叩 tr ny l 30 ph炭t Reset Account Quy nh th i gian m L 0, nh動ng n u Account Lockout Counter l i s l n ng nh p Lockout Threshold 動 c thi t After kh担ng thnh c担ng l p th狸 gi叩 tr ny l 30 ph炭t Ch鱈nh s叩ch c c b Local Policies cho ph辿p thi t l p c叩c ch鱈nh s叩ch gi叩m s叩t c叩c i t動 ng tr棚n m ng Ch鱈nh s叩ch ki m to叩n (Audit Policies) gi炭p gi叩m s叩t v ghi nh n c叩c s ki n di n ra trong h th ng 4
  • 5. 4/21/2010 Ch鱈nh s叩ch ki m to叩n C叩c l a ch n trong ch鱈nh s叩ch ki m to叩n Ch鱈nh s叩ch M担 t Audit Account Ki m to叩n nh ng s ki n khi ti kho n ng nh p, h Logon Events th ng s ghi nh n khi ng動 i d湛ng logon, logoff ho c t o m t k t n i m ng Audit Account H th ng s ghi nh n khi ti kho n ng動 i d湛ng ho c Management nh坦m c坦 s thay i th担ng tin hay c叩c thao t叩c qu n tr li棚n quan n ti kho n ng動 i d湛ng Audit Directory Ghi nh但n vi c truy c p c叩c d ch v th動 m c Service Access Audit Logon Events Ghi nh但n c叩c s ki n li棚n quan n qu叩 tr狸nh logon nh動 thi hnh m t logon script ho c truy c p n m t roaming profile Audit Object Access Ghi nh n vi c truy c p c叩c t p tin, th動 m c, v m叩y tin Audit Policy Change Ghi nh n c叩c thay i trong ch鱈nh s叩ch ki m to叩n Ch鱈nh s叩ch ki m to叩n C叩c l a ch n trong ch鱈nh s叩ch ki m to叩n (t.t) Ch鱈nh s叩ch M担 t Audit privilege use H th ng s ghi nh n l i khi b n b n thao t叩c qu n tr tr棚n c叩c quy n h th ng nh動 c p ho c x坦a quy n c a m t ai 坦 Audit process Ki m to叩n ny theo d探i ho t ng c a ch動董ng tr狸nh hay tracking h i u hnh Audit system event H th ng s ghi nh n m i khi b n kh i ng l i m叩y ho c t t m叩y 5
  • 6. 4/21/2010 Ch鱈nh s叩ch c c b Quy n h th ng c a ng動 i d湛ng (User Rights Assignment) L quy n c p cho user th c thi m t s t叩c v tr棚n h th ng t c l m t s quy n m user 動 c s d ng tr棚n server. C坦 2 c叩ch c p quy n h th ng cho ng動 i d湛ng l gia nh p ti kho n ng動 i d湛ng vo nh坦m t o s n (built-in) ho c d湛ng c担ng c User Rights Assignment g叩n t ng quy n r i r c cho ng動 i d湛ng th棚m, b t quy n ch c n add hay remove Ch鱈nh s叩ch c c b Quy n h th ng c a ng動 i d湛ng (User Rights Assignment) 6
  • 7. 4/21/2010 Quy n h th ng c a ng動 i d湛ng M t s quy n h th ng cho ng動 i d湛ng v nh坦m Quy n M担 t Access This Computer Cho ph辿p ng動 i d湛ng truy c p m叩y t鱈nh th担ng from the Network qua m ng. M c nh m i ng動 i u c坦 quy n ny. Allow log on locally Cho ph辿p ng動 i d湛ng ng nh p c c b vo server Bypass Traverse Checking Cho ph辿p ng動 i d湛ng duy t qua c u tr炭c th動 m c n u ng動 i d湛ng kh担ng c坦 quy n xem (list) n i dung th動 m c ny. Back Up Files and Cho ph辿p ng動 i d湛ng sao l動u d ph嘆ng (backup) Directories c叩c t p tin v th動 m c b t ch p c叩c t p tin v th動 m c ny ng動 i 坦 c坦 quy n kh担ng. Change the System Time Cho ph辿p ng動 i d湛ng thay i gi h th ng c a m叩y t鱈nh. Deny Access to This Cho ph辿p b n kh坦a ng動 i d湛ng ho c nh坦m kh担ng Computer from the 動 c truy c p n c叩c m叩y t鱈nh tr棚n m ng. Network Quy n h th ng c a ng動 i d湛ng M t s quy n h th ng cho ng動 i d湛ng v nh坦m (t.t) Quy n M担 t Deny Logon Locally Cho ph辿p b n ngn c n nh ng ng動 i d湛ng v nh坦m truy c p n m叩y t鱈nh c c b . Load and unload device Cho ph辿p ng動 i d湛ng ci t ho c g b driver drivers c a thi t b Log On Locally Cho ph辿p ng動 i d湛ng logon t i m叩y t鱈nh Server. Restore Files and Cho ph辿p ng動 i d湛ng ph c h i t p tin v th動 Directories m c, b t ch p ng動 i d湛ng ny c坦 quy n tr棚n file v th動 m c ny hay kh担ng. Shut Down the System Cho ph辿p ng動 i d湛ng shut down c c b m叩y Windows 2003. Take Ownership of Files or Cho ng動 i d湛ng t動 c quy n s h u c a m t i Other Objects t動 ng h th ng. 7
  • 8. 4/21/2010 Ch鱈nh s叩ch c c b C叩c l a ch n b o m t (Security Options) Cho ph辿p qu n tr khai b叩o th棚m th担ng s nh m tng t鱈nh b o m t cho h th ng C叩c l a ch n b o m t C叩c l a ch n b o m t th担ng d ng T棚n l a ch n M担 t Shutdown: allow system to be shut Cho ph辿p ng動 i d湛ng shutdown h down without having to log on th ng m kh担ng c n logon. Audit : audit the access of global Gi叩m s叩t vi c truy c p c叩c i t動 ng system objects h th ng ton c c. Network security: force logoff when T ng log off kh i h th ng khi logon hours expires. ng動 i d湛ng h t th i gian s d ng ho c ti kho n h t h n. Interactive logon: do not require Kh担ng y棚u c u n ba ph鱈m CTRL+ALT+DEL CTRL+ALT+DEL khi logon. Interactive logon: do not display last Kh担ng hi n th t棚n ng動 i d湛ng 達 user name logon tr棚n h p tho i Logon. Account: rename administrator Cho ph辿p i t棚n ti kho n account Administrator thnh t棚n m i Account: rename guest account Cho ph辿p i t棚n ti kho n Guest thnh t棚n m i 8
  • 9. 4/21/2010 IP Security (IPSec) IP Security l giao th c h tr c叩c k t n i an ton d a tr棚n IP. IPSec l ho t ng t ng th 3 (Network) s d ng IPSec b n t o ra c叩c quy t c (rule), m t quy t c IPSec l s k t h p gi a b l c (IPSec) v c叩c quy t叩c ng (action) IP Security (IPSec) C叩c t叩c ng b o m t Block transmissons: ch c nng ngn ch n nh ng g坦i d li u 動 c truy n Encrypt transmissions: Ch c nng m達 h坦a nh ng g坦i tin truy n i Sign transmissions: Ch c nng k箪 t棚n vo g坦i d li u truy n nh m tr叩nh gi m u Permit transmissions: Ch c nng l cho ph辿p d li u truy n qua, d湛ng t o ra c叩c quy t t h n ch m t s i u v kh担ng h n ch m t s i u kh叩c 9
  • 10. 4/21/2010 IP Security (IPSec) C叩c b l c (Filter) IPSec Filter d湛ng th ng k棚 c叩c i u ki n quy t c ho t ng. Gi i h n t m t叩c d ng c a c叩c t叩c ng l棚n m t ph m vi m叩y t鱈nh no 坦. B l c IPSec d a tr棚n c叩c y u t : a ch IP, subnet ho c t棚n DNS c a m叩y ngu n. a ch IP, subnet ho c t棚n DNS c a m叩y 鱈ch. Theo s hi u c ng (port) v ki n c ng (TCP, UDP, ICMP) IP Security (IPSec) Tri n khai IPSec tr棚n Windows Server 2003 10
  • 11. 4/21/2010 Tri n khai IPSec tr棚n Windows Server 2003 C叩c ch鱈nh s叩ch IPSec t o s n Client (Respond Only): ch鱈nh s叩ch quy nh m叩y t鱈nh b n kh担ng ch ng d湛ng IPSec tr khi nh p y棚u c u d湛ng IPSec t m叩y i t叩c. Server (Request Security): quy nh m叩y server c a b n ch ng kh i t o IPSec m i khi thi t l p k t n坦i t i m叩y kh叩c Secure Server (Require Security): quy nh kh担ng cho ph辿p b t k畛 cu c trao i d li u no v i Server hi n t i kh担ng d湛ng IPSec VD: t o ch鱈nh s叩ch IPSec m b o k t n i m達 h坦a 11