1. Trung T但m ATHENA SVTT: CHUNG THANH XUN
Local SecurityPolicy
Chu畉n b畛:
- M叩y Windows Server 2008 (ch動a n但ng c畉p Domain):
Server 1
NIC 1: 192.168.1.1/24
- M叩y Windows XP: PC 1
NIC 1: 192.168.1.2/24
M担 h狸nh:
M畛c ti棚u bi LAB:
- T畉o local security policy tr棚n m叩y server1 畛 叩p d畛ng ch鱈nh s叩ch cho
c叩c user
- M畛c ti棚u cu畛i c湛ng: 叩p d畛ng 動畛c c叩c ch鱈nh s叩ch an ninh cho
c叩c user
L動u 箪:
Khi th畛c hi畛n tr棚n m叩y 畉o VM-ware, c叩c card m畉ng s畉 thi畉t l畉p 畛 ch畉 畛 HOST
ONLY, N棚n t畉t t鱈nh nng Windows Firewall tr棚n c叩c m叩y Server v PC.
2. Trung T但m ATHENA SVTT: CHUNG THANH XUN
Th畛c Hi畛n:
B動畛c 1(Cho ph辿p t畉o user v畛i password 董n
gi畉n):
Tr棚n m叩y server1, vo Start ch畛n Run r畛i g探 lusrmgr.msc 畛 vo Local Users
and Groups:
Trong Local Users and Groups, T畉o m畛i user u1 v畛i password 董n gi畉n l 123 s畉
b畛 b叩o l畛i l
password kh担ng 畛 畛 ph畛c t畉p:
3. Trung T但m ATHENA SVTT: CHUNG THANH XUN
Tr棚n m叩y server1, vo Start ch畛n Run r畛i g探 secpol.msc 畛 vo Local
Security Policy:
Trong Local Security Policy, ch畛n Account Policies->Password Policy->
Password must
meet complexity requirements:
Trong Password must meet complexity requirements Properties, ch畛n
Disabled. Sau 坦
Apply r畛i OK:
4. Trung T但m ATHENA SVTT: CHUNG THANH XUN
畛 update security policy v畛a c畉u h狸nh, ta vo Start->Run g探 gpupdate
/force r畛i Enter.
5. Trung T但m ATHENA SVTT: CHUNG THANH XUN
Test security policy v畛a t畉o b畉ng c叩ch t畉o l畉i user u1 v畛i password 董n
gi畉n l 123:
B動畛c 2(T畉o 1 Security Policy kh坦a 1 user n畉u ng nh畉p vo server1
sai 3 l畉n):
Tr棚n m叩y server1, vo Start ch畛n Run r畛i g探 secpol.msc 畛 vo Local
Security Policy:
6. Trung T但m ATHENA SVTT: CHUNG THANH XUN
Trong Local Security Policy, ch畛n Account Policies->Account Lockout Policy,
ti畉p theo ta s畉
c畉u h狸nh 3 m畛c l:Account lockout duration, Account lockout threshold v
Reset account
lockout counter after:
1. Trong Account lockout threshold Properties(c畉u h狸nh s畛 l畉n ng nh畉p sai
c畛a user 畛 kh坦a user
坦), g探 s畛 3 vo ph畉n
Account will lock out
after:
7. Trung T但m ATHENA SVTT: CHUNG THANH XUN
2. Trong Account lockout duration Properties(quy 畛nh th畛i gian kh坦a user
ng nh畉p sai 3 l畉n), g探 s畛 ph炭t m b畉n mu畛n kh坦a user vo ph畉n Account is
locked out for:
3. Trong Reset account lockout counter after(quy 畛nh th畛i gian reset user 達
b畛 kh坦a do ng nh畉p sai 3 l畉n), g探 s畛 ph炭t m b畉n mu畛n reset user b畛 kh坦a vo
ph畉n Reset account lock out counter after:
畛 update security
policy v畛a c畉u
h狸nh, ta vo Start-
>Run g探 gpupdate
/force r畛i Enter.
8. Trung T但m ATHENA SVTT: CHUNG THANH XUN
Test security policy v畛a t畉o b畉ng c叩ch ng nh畉p 1 user sai qu叩 3 l畉n v 但y l
th担ng b叩o l畛i c畛a
user u1:
Trong Local Users and Groups c畛a Administrator, ta s畉 th畉y user u1
b畛 lock out:
9. Trung T但m ATHENA SVTT: CHUNG THANH XUN
B動畛c 3(T畉o Security Policy cho ph辿p t畉t c畉 c叩c user 畛u c坦 quy畛n
t畉t m叩y):
畉u ti棚n, ta ng nh畉p user u1 s畉 kh担ng th畉y quy畛n t畉t
m叩y:
10. Trung T但m ATHENA SVTT: CHUNG THANH XUN
Tr棚n m叩y server1, vo Start ch畛n Run r畛i g探 secpol.msc 畛 vo Local
Security Policy:
Trong Local Security Policy, ch畛n Local Policies->User Rights Assignment-
>Shutdown the
system:
11. Trung T但m ATHENA SVTT: CHUNG THANH XUN
Trong Shutdown the system Properties, ch畛n Add User or Group v 畛 担
Enter the object
names to select ta g探 Everyone r畛i OK->
OK
畛 update security policy v畛a c畉u h狸nh, ta vo Start->Run g探 gpupdate
/force r畛i Enter.
12. Trung T但m ATHENA SVTT: CHUNG THANH XUN
Test security policy v畛a t畉o b畉ng c叩ch ng nh畉p vo 1 user b畉t k狸 畛 ki畛m tra
quy畛n t畉t m叩y: