際際滷

際際滷Share a Scribd company logo
MCSA 2012 Local Group Policy
Khi user ng nh畉p th狸 h畛 ch畛u nh畛ng 叩p 畉t c畛a HDH, trong qu叩
tr狸nh qu畉n l箪 ta c坦 nhu c畉u h畉n ch畉 hay th棚m vo c叩c quy畛n h畉n
c畛a h畛 khi truy c畉p 畛ng d畛ng hay truy c畉p ti nguy棚n.
C叩c th畛i HDH windows c滴 th狸 ta ph畉i m畛 c叩c file system.ini 畛
c畉u h狸nh. T畛 windows 98 tr畛 l棚n, Microsoft cho ph辿p ta th畛c hi畛n
c畉u h狸nh b畉ng Registry, b畉ng c担ng c畛 ny th狸 admin c坦 th畛 thi畉t l畉p
c叩c quy 畛nh 叩p 畉t l棚n h畛 th畛ng, user . V狸 vi畛c ch畛nh s畛a registry
r畉t ph畛c t畉p, Microsoft l畉y 1 s畛 key trong registry 畛 t畉o thnh
Group Policy (ch鱈nh s叩ch nh坦m) gi炭p c叩c admin c坦 th畛 ch畛nh s畛a
d畛 dng.
Group Policy c坦 th畛 叩p d畛ng l棚n local computer hay m担i tr動畛ng
domain.
Group Policy tr棚n local computer 動畛c g畛i l Local Group Policy
(local policy).
C担ng c畛 qu畉n l箪 local policy:
C叩ch 1:
run -> gpedit.msc (xu畉t hi畛n c担ng c畛 qu畉n l箪 l Local Group
Policy Editor).
C叩ch 2:
 run -> mmc (giao di畛n console root), menu File ch畛n
Add/Remove Snap-in.
 ch畛n Group Policy Object Editor, 畛 m畉c 畛nh Local computer -
> add r畛i save l畉i.
Mcsa 2012 local group policy
Policy g畛m 2 ph畉n:
Computer Configuration: n畉u thi畉t l畉p c叩c policy trong ph畉n ny
th狸 畛i t動畛ng b畛 t叩c 畛ng l computer v user account
User Configuration: 畛i t動畛ng b畛 t叩c 畛ng l user account.
C叩c gi叩 tr畛 c坦 tr棚n Policy c畛a Windows:
 Not configured/Defined: kh担ng can thi畛p vo policy, 畛 m畉c
畛nh theo Microsoft ( gi叩 tr畛 m畉c 畛nh c坦 l炭c s畉 l disable policy,
c坦 l炭c s畉 l enable policy).
 Enabled: b畉t policy.
 Disable: t畉t policy.
C叩ch 叩p 畉t policy 達 hi畛u ch畛nh cho h畛 th畛ng:
 M畛t s畛 Policy s畉 t畛 畛ng c坦 hi畛u l畛c.
 Ta vo run -> cmd, d湛ng l畛nh: gpupdate /force 畛 b畉t bu畛c h畛
th畛ng c畉p nh畉t policy.
 N畉u gpupdate /force m v畉n ch動a th畉y c坦 hi畛u l畛c th狸 log off sau
坦 log on l畉i.
 3 b動畛c tr棚n kh担ng d湛ng 動畛c th狸 Restart server (l動u 箪: ch畛 d湛ng
khi 3 c叩ch tr棚n kh担ng c坦 hi畛u l畛c).
M畛t s畛 policy th動畛ng d湛ng:
1/ B畉t/T畉t ch畛c nng Display shutdown event tracker: 但y l
ch畛c nng b畉t ta khai b叩o l箪 do n畉u t畉t server.
 Computer configuration Administrative Templates System: b棚n
ph畉i ch畛n Display shutdown event tracker
2/ C叩c policy li棚n quan 畉n Control Panel
User Configuration Administrative Templates Control Panel
+ Show only specified Control Panel items: ch畛 cho ph辿p s畛 d畛ng 1
s畛 item trong control panel do admin ch畛 畛nh.
enable r畛i click show, ta nh畉p 炭ng t棚n item tr棚n control panel m
ta cho ph辿p hi畛n th畛
v鱈 d畛 ch畛 cho ph辿p hi畛n th畛 item fonts
叩nh l畛nh: gpupdate /force
K畉t qu畉:
+ Prohibit access to Control Panel and PC settings: c畉m truy
c畉p Control Panel. B畉t l畛i c畛a policy ny l nh畛ng thi畉t l畉p li棚n
quan 畉n control panel 畛u b畛 c畉m ( Screen solution, Properties
Computer, v.v 畛u b畛 c畉m).
3/ C叩c policy li棚n quan 畉n Desktop
User Configuration Administrative Templates Desktop
+ Remove Recycle Bin icon from desktop: m畉t icon Recycle Bin 畛
desktop (mu畛n m畉t th狸 enable policy ny).
4/ C叩c policy li棚n quan 畉n Start Menu v Taskbar
User Configuration Administrative Templates Start Menu
and Taskbar
+ Remove Run menu from Start menu: c畉m ch畉y menu Run (b畉m
Windows + R c滴ng b畛 c畉m).
5/ C叩c policy li棚n quan 畉n System
+ Prevent access to the command prompt: c畉m s畛 d畛ng cmd.
+ Dont run specified Windows application: c畉m c叩c 畛ng d畛ng c畛a
Windows.
enable, ch畛n show
M畛i 畛ng d畛ng s畉 c坦 file th畛c thi (*.exe), ch畛 c畉n add file th畛c thi l
policy c畉m 動畛c 畛ng d畛ng.
v鱈 d畛: c畉m internet explore (IE), file th畛c thi c畛a IE l iexplore.exe
+ Run only specified Windows application: ch畛 cho ch畉y c叩c 畛ng
d畛ng 動畛c ch畛 畛nh.
Local Security Policy (ch鱈nh s叩ch b畉o m畉t)
N坦 n畉m trong Computer Configuration Windows Settings
Security Settings ho畉c c坦 th畛 m畛 n坦 b畉ng l畛nhsecpol.msc
C叩c security policy th動畛ng g畉p:
Account Policies (ch鱈nh s叩ch ti kho畉n):
1/ Password Policies: nh畛ng ch鱈nh s叩ch li棚n quan 畉n m畉t kh畉u
+ Minimum password length: quy 畛nh chi畛u di t畛i thi畛u c畛a m畉t
kh畉u.
+ Minimum password age: tu畛i th畛 t畛i thi畛u c畛a 1 password, n畉u
quy 畛nh l 2 th狸 sau 2 ngy password m畛i c坦 th畛 動畛c 畛i.
+ Maximum password age: tu畛i th畛 t畛i a c畛a 1 password (m畉c
畛nh 42 ngy). L炭c ny user n畉u kh担ng mu畛n thay 畛i password
th狸 c坦 th畛 畉t l畉i password c滴, do 坦 ta c畉n 1 policy 畛 ngn c畉n
vi畛c ny l:
+ Enforce password history: n畉u ch畛n 3 th狸 n坦 s畉 nh畛 3 password
tr動畛c 坦 c畛a user. L畉n 1 畉t pass: 12 3 th狸 n坦 s畉 nh畛 l畉i, v n坦 s畉
nh畛 t畛i a c叩i s畛 m ta ch畛 畛nh. Theo y棚u c畉u c畛a Microsoft th狸
n棚n 畛 24 (!!).
+ Password must meet complexity requirements: ph畉i 畉t
password ph畛c t畉p (xem l畉i b Local User and Group). N畉u kh担ng
mu畛n 畉t ph畛c t畉p th狸 disable.
+ Store passwords using reversible encryption: m畉c 畛nh windows
l動u user, password d動畛i d畉ng m達 h坦a trong file SAM (Security
Account Manager), c坦 2 d畉ng m達 h坦a l Reversible (c坦 th畛 d畛ch
ng動畛c  m達 h坦a 2 chi畛u) v Irreversible ( kh担ng th畛 d畛ch ng動畛c
m達 h坦a 1 chi畛u). N畉u enable th狸 h畛 th畛ng s畉 m達 h坦a 2 chi畛u, lm
gi畉m 畛 an ton khi c坦 ng動畛i no 坦 l畉y 動畛c file SAM.
2/ Account lockout Policy: c叩c ch鱈nh s叩ch kh坦a ti kho畉n
+ Account lockout threshold: ng動畛ng 畛 quy 畛nh kh坦a ti kho畉n
(m畉c 畛nh l kh担ng kh坦a). N畉u ta ch畛 畛nh threshold l 3 th狸 n畉u
nh畉p sai password 3 l畉n th狸 s畉 kh坦a ti kho畉n (l畉n 4 nh畉p 炭ng
c滴ng kh担ng 動畛c). D湛ng 畛 ch畛ng d嘆 m畉t kh畉u.
+ Account lockout duration (T1) : kh坦a ti kho畉n trong v嘆ng bao
nhi棚u ph炭t (gi畉 s畛 ta kh坦a trong 30 ph炭t)
+ Reset account lockout counter after (T2): nh畛 c坦 b畛 畉m
(counter) m h畛 th畛ng th畛ng k棚 動畛c s畛 l畉n ng nh畉p sai, policy
ny quy 畛nh th畛i gian b畛 畉m reset l畉i v畛 0. L炭c ny ng動畛i d湛ng
m畛i c坦 th畛 ti畉p t畛c ng nh畉p
L動u 箪: th畛i gian T1 >= T2.
Khi ti kho畉n b畛 kh坦a th狸 s畉 hi畛n d畉u check Account is locked out
N畉u ng動畛i d湛ng kh担ng mu畛n 畛i 畉n h畉t th畛i gian T2 畛 ng
nh畉p th狸 c坦 th畛 nh畛 admin b畛 check .
N畉u T1 = 0 th狸 ti kho畉n s畉 b畛 kh坦a cho 畉n khi admin b畛 check.
Local Policies: c叩c ch鱈nh s叩ch c畛c b畛
User rights assignment: g叩n quy畛n cho ng動畛i d湛ng.
+ Allow log on locally: cho ph辿p ng nh畉p tr棚n m叩y.
+ Deny log on locally: c畉m ng nh畉p tr棚n m叩y ( n畉u user v畛a
動畛c Allow, v畛a b畛 Deny th狸 Deny m畉nh h董n => b畛 c畉m log on).
+ Shut down the system: cho ph辿p user no 動畛c t畉t m叩y.
+ Change the system time: cho ph辿p ch畛nh gi畛 h畛 th畛ng.
Security Option:
Trong giao di畛n log-on, m畉c 畛nh h畛 th畛ng hi畛n th畛 c叩c user ang
c坦 => kh担ng b畉o m畉t, ta d湛ng policy
+ Interactive logon: Do not display last user name (kh担ng hi畛n th畛
user name cu畛i c湛ng v 畛ng th畛i kh担ng hi畛n ra c叩c user khi ng
nh畉p).
+ Interactive logon: Do not require CTRL + ALT + DEL : khi log-
on kh担ng c畉n b畉m t畛 h畛p 3 ph鱈m
+ Shutdown: Allow system to be shutdown without having to log
on: cho ph辿p t畉t m叩y m kh担ng c畉n log on.
+ Account: Rename administrator account : 畛i t棚n ti kho畉n
administrator.
C叩c policy li棚n quan 畉n v畉n 畛 truy c畉p ti nguy棚n m畉ng.
+ Secpol.msc -> security options -> local policies
-> Security Options
Network access: Sharing and security model for local accounts:
C叩c ch畉 畛 truy c畉p m畉ng
 Classic (default) : cho ph辿p ch畛ng th畛c b畉ng c叩c ti kho畉n tr棚n
local computer c畛a m叩y chia s畉.
 Guest: ch畛 cho ph辿p vo b畉ng ti kho畉n guest.
Account: Limit local account use of blank password to console log
on only: c畉m ti kho畉n kh担ng c坦 password truy c畉p ti nguy棚n
-> User Rights Assignment
Access this computer from the network: cho ph辿p user, group truy
c畉p ti nguy棚n (m畉c 畛nh l t畉t c畉 user).
Deny access to this computer from the network : c畉m user, group
no 坦 truy c畉p ti nguy棚n (n畉u v畛a allow, v畛a deny th狸 deny 動u
ti棚n h董n).
*
Nh動 m狸nh 達 tr狸nh by, c叩c policy ta v畛a k畛 tr棚n l Local Group
Policy 叩p 畉t cho t畉t c畉 user tr棚n h畛 th畛ng. T畛 Windows Vista tr畛
l棚n, Microsoft h畛 tr畛 c担ng c畛 叩p policy cho 1 user c畛 th畛 l Local
User Policy.
Start -> Run -> MMC -> Add/Remove Snap-in -> Group Policy
Object Editor -> Browse -> tab user ch畛 畛nh user c畛 th畛 -> OK
(mu畛n th棚m bao nhi棚u user th狸 lm l畉i b畉y nhi棚u l畉n).
L動u 箪 1: C叩c policy l動u trong 1 file l:
動畛ng d畉n: C: Windows  System32  Group Policy
M畉c 畛nh folder Group Policy b畛 畉n, ta ph畉i hi畛n th畛 c叩c file 畉n.
Machine: l動u c叩c policy c畛a m叩y t鱈nh, User: c叩c policy li棚n quan
畉n user.
Ta x坦a folder ny v restart th狸 WIndows s畉 ph叩t sinh c畉u h狸nh
default => m畉t policy.
L動u 箪 2:
Ta nh畉n th畉y Administrator c坦 th畛 ng nh畉p vo safe mode khi b畛
disable, th狸 畛 b畉o m畉t ti kho畉n Administrator (built-in) ta c畉n
lm c叩c b動畛c sau:
+ T畉o user add vo group Administrators.
+ Rename ti kho畉n Administrator built-in.
+ 畉t password ph畛c t畉p cho Administrator built-in.
N畉u c叩c b畉n mu畛n t狸m hi畛u th棚m v畛 c叩c policy th狸 download file
ny
Ti li畛u GPEDIT.MSC

More Related Content

What's hot (20)

Huynh hongkhoi
Huynh hongkhoiHuynh hongkhoi
Huynh hongkhoi
H担Ka Huyn
Mcsa 2012 local user and group
Mcsa 2012 local user and groupMcsa 2012 local user and group
Mcsa 2012 local user and group
laonap166
Group policy management
Group policy managementGroup policy management
Group policy management
Hong Phi L畛c
Group policy management
Group policy managementGroup policy management
Group policy management
Hong H畛u H畉u
B叩o C叩o Th畛c T畉p Athena
B叩o C叩o Th畛c T畉p AthenaB叩o C叩o Th畛c T畉p Athena
B叩o C叩o Th畛c T畉p Athena
H担Ka Huyn
Audit policy gi叩m s叩t h畛 th畛ng
Audit policy  gi叩m s叩t h畛 th畛ngAudit policy  gi叩m s叩t h畛 th畛ng
Audit policy gi叩m s叩t h畛 th畛ng
laonap166
Hdsd dau ghi
Hdsd dau ghiHdsd dau ghi
Hdsd dau ghi
BENCO Vi畛t Nam
Hdsd dau ghi full
Hdsd dau ghi fullHdsd dau ghi full
Hdsd dau ghi full
BENCO Vi畛t Nam
Lab 1 ci 畉t windows server 2008.pdf
Lab 1 ci 畉t windows server 2008.pdfLab 1 ci 畉t windows server 2008.pdf
Lab 1 ci 畉t windows server 2008.pdf
Pham Viet Dung
Tr狸nh by c叩c t叩c v畛 qu畉n l箪 Domain v畛i Windows Server 2008
Tr狸nh by c叩c t叩c v畛 qu畉n l箪 Domain v畛i Windows Server 2008Tr狸nh by c叩c t叩c v畛 qu畉n l箪 Domain v畛i Windows Server 2008
Tr狸nh by c叩c t叩c v畛 qu畉n l箪 Domain v畛i Windows Server 2008
T炭 Cao
Chuy棚n 畛 group policy
Chuy棚n 畛 group policyChuy棚n 畛 group policy
Chuy棚n 畛 group policy
B狸nh Tr畛ng n
Bi 5: Tri畛n khai AD Qu畉n tr畛 ti kho畉n m叩y t鱈nh - Gi叩o tr狸nh FPT
Bi 5: Tri畛n khai AD  Qu畉n tr畛 ti kho畉n m叩y t鱈nh - Gi叩o tr狸nh FPTBi 5: Tri畛n khai AD  Qu畉n tr畛 ti kho畉n m叩y t鱈nh - Gi叩o tr狸nh FPT
Bi 5: Tri畛n khai AD Qu畉n tr畛 ti kho畉n m叩y t鱈nh - Gi叩o tr狸nh FPT
MasterCode.vn
Lab 12 print server
Lab 12 print server   Lab 12 print server
Lab 12 print server
Pham Viet Dung
Part 13 organizational unit -www.key4_vip.info
Part 13   organizational unit -www.key4_vip.infoPart 13   organizational unit -www.key4_vip.info
Part 13 organizational unit -www.key4_vip.info
laonap166
Bi 7: Qu畉n tr畛 ng動畛i d湛ng th担ng qua ch鱈nh s叩ch nh坦m - Gi叩o tr狸nh FPT
Bi 7: Qu畉n tr畛 ng動畛i d湛ng th担ng qua ch鱈nh s叩ch nh坦m - Gi叩o tr狸nh FPTBi 7: Qu畉n tr畛 ng動畛i d湛ng th担ng qua ch鱈nh s叩ch nh坦m - Gi叩o tr狸nh FPT
Bi 7: Qu畉n tr畛 ng動畛i d湛ng th担ng qua ch鱈nh s叩ch nh坦m - Gi叩o tr狸nh FPT
MasterCode.vn
Huong dan su dung dau ghi hinh camera 6100 series
Huong dan su dung dau ghi hinh camera  6100 seriesHuong dan su dung dau ghi hinh camera  6100 series
Huong dan su dung dau ghi hinh camera 6100 series
Camera Hanoi
Th畛 thu畉t XP
Th畛 thu畉t XPTh畛 thu畉t XP
Th畛 thu畉t XP
Nguy畛n Anh
5 v畉n 畛 li棚n quan 畉n m畉t kh畉u tr棚n thi畉t b畛 HIKVISION
5 v畉n 畛 li棚n quan 畉n m畉t kh畉u tr棚n thi畉t b畛 HIKVISION5 v畉n 畛 li棚n quan 畉n m畉t kh畉u tr棚n thi畉t b畛 HIKVISION
5 v畉n 畛 li棚n quan 畉n m畉t kh畉u tr棚n thi畉t b畛 HIKVISION
thaihikvision
Tri畛n khai ph畉n m畛m tr棚n domain
Tri畛n khai ph畉n m畛m tr棚n domainTri畛n khai ph畉n m畛m tr棚n domain
Tri畛n khai ph畉n m畛m tr棚n domain
Pham Viet Dung
Huynh hongkhoi
Huynh hongkhoiHuynh hongkhoi
Huynh hongkhoi
H担Ka Huyn
Mcsa 2012 local user and group
Mcsa 2012 local user and groupMcsa 2012 local user and group
Mcsa 2012 local user and group
laonap166
Group policy management
Group policy managementGroup policy management
Group policy management
Hong Phi L畛c
Group policy management
Group policy managementGroup policy management
Group policy management
Hong H畛u H畉u
B叩o C叩o Th畛c T畉p Athena
B叩o C叩o Th畛c T畉p AthenaB叩o C叩o Th畛c T畉p Athena
B叩o C叩o Th畛c T畉p Athena
H担Ka Huyn
Audit policy gi叩m s叩t h畛 th畛ng
Audit policy  gi叩m s叩t h畛 th畛ngAudit policy  gi叩m s叩t h畛 th畛ng
Audit policy gi叩m s叩t h畛 th畛ng
laonap166
Lab 1 ci 畉t windows server 2008.pdf
Lab 1 ci 畉t windows server 2008.pdfLab 1 ci 畉t windows server 2008.pdf
Lab 1 ci 畉t windows server 2008.pdf
Pham Viet Dung
Tr狸nh by c叩c t叩c v畛 qu畉n l箪 Domain v畛i Windows Server 2008
Tr狸nh by c叩c t叩c v畛 qu畉n l箪 Domain v畛i Windows Server 2008Tr狸nh by c叩c t叩c v畛 qu畉n l箪 Domain v畛i Windows Server 2008
Tr狸nh by c叩c t叩c v畛 qu畉n l箪 Domain v畛i Windows Server 2008
T炭 Cao
Chuy棚n 畛 group policy
Chuy棚n 畛 group policyChuy棚n 畛 group policy
Chuy棚n 畛 group policy
B狸nh Tr畛ng n
Bi 5: Tri畛n khai AD Qu畉n tr畛 ti kho畉n m叩y t鱈nh - Gi叩o tr狸nh FPT
Bi 5: Tri畛n khai AD  Qu畉n tr畛 ti kho畉n m叩y t鱈nh - Gi叩o tr狸nh FPTBi 5: Tri畛n khai AD  Qu畉n tr畛 ti kho畉n m叩y t鱈nh - Gi叩o tr狸nh FPT
Bi 5: Tri畛n khai AD Qu畉n tr畛 ti kho畉n m叩y t鱈nh - Gi叩o tr狸nh FPT
MasterCode.vn
Lab 12 print server
Lab 12 print server   Lab 12 print server
Lab 12 print server
Pham Viet Dung
Part 13 organizational unit -www.key4_vip.info
Part 13   organizational unit -www.key4_vip.infoPart 13   organizational unit -www.key4_vip.info
Part 13 organizational unit -www.key4_vip.info
laonap166
Bi 7: Qu畉n tr畛 ng動畛i d湛ng th担ng qua ch鱈nh s叩ch nh坦m - Gi叩o tr狸nh FPT
Bi 7: Qu畉n tr畛 ng動畛i d湛ng th担ng qua ch鱈nh s叩ch nh坦m - Gi叩o tr狸nh FPTBi 7: Qu畉n tr畛 ng動畛i d湛ng th担ng qua ch鱈nh s叩ch nh坦m - Gi叩o tr狸nh FPT
Bi 7: Qu畉n tr畛 ng動畛i d湛ng th担ng qua ch鱈nh s叩ch nh坦m - Gi叩o tr狸nh FPT
MasterCode.vn
Huong dan su dung dau ghi hinh camera 6100 series
Huong dan su dung dau ghi hinh camera  6100 seriesHuong dan su dung dau ghi hinh camera  6100 series
Huong dan su dung dau ghi hinh camera 6100 series
Camera Hanoi
Th畛 thu畉t XP
Th畛 thu畉t XPTh畛 thu畉t XP
Th畛 thu畉t XP
Nguy畛n Anh
5 v畉n 畛 li棚n quan 畉n m畉t kh畉u tr棚n thi畉t b畛 HIKVISION
5 v畉n 畛 li棚n quan 畉n m畉t kh畉u tr棚n thi畉t b畛 HIKVISION5 v畉n 畛 li棚n quan 畉n m畉t kh畉u tr棚n thi畉t b畛 HIKVISION
5 v畉n 畛 li棚n quan 畉n m畉t kh畉u tr棚n thi畉t b畛 HIKVISION
thaihikvision
Tri畛n khai ph畉n m畛m tr棚n domain
Tri畛n khai ph畉n m畛m tr棚n domainTri畛n khai ph畉n m畛m tr棚n domain
Tri畛n khai ph畉n m畛m tr棚n domain
Pham Viet Dung

Viewers also liked (17)

Disk management p1
Disk management p1Disk management p1
Disk management p1
laonap166
Bi 5 Lm vi畛c v畛i b叩o c叩o n但ng cao - Gi叩o tr狸nh FPT
Bi 5 Lm vi畛c v畛i b叩o c叩o n但ng cao - Gi叩o tr狸nh FPTBi 5 Lm vi畛c v畛i b叩o c叩o n但ng cao - Gi叩o tr狸nh FPT
Bi 5 Lm vi畛c v畛i b叩o c叩o n但ng cao - Gi叩o tr狸nh FPT
MasterCode.vn
Mcsa 2012 m畉ng cn b畉n ph畉n 2
Mcsa 2012 m畉ng cn b畉n ph畉n 2 Mcsa 2012 m畉ng cn b畉n ph畉n 2
Mcsa 2012 m畉ng cn b畉n ph畉n 2
laonap166
T畛 h畛c mcsa 2012 m畉ng cn b畉n ph畉n 1
T畛 h畛c mcsa 2012 m畉ng cn b畉n ph畉n 1T畛 h畛c mcsa 2012 m畉ng cn b畉n ph畉n 1
T畛 h畛c mcsa 2012 m畉ng cn b畉n ph畉n 1
laonap166
Mcsa 2012 m畉ng cn b畉n ph畉n 7
Mcsa 2012 m畉ng cn b畉n ph畉n 7Mcsa 2012 m畉ng cn b畉n ph畉n 7
Mcsa 2012 m畉ng cn b畉n ph畉n 7
laonap166
Mcsa 2012 ntfs permission
Mcsa 2012 ntfs permissionMcsa 2012 ntfs permission
Mcsa 2012 ntfs permission
laonap166
Mcsa 2012 m畉ng cn b畉n ph畉n 6
Mcsa 2012 m畉ng cn b畉n ph畉n 6Mcsa 2012 m畉ng cn b畉n ph畉n 6
Mcsa 2012 m畉ng cn b畉n ph畉n 6
laonap166
Mcsa 2012 file server v share permission
Mcsa 2012 file server v share permissionMcsa 2012 file server v share permission
Mcsa 2012 file server v share permission
laonap166
Disk management end
Disk management endDisk management end
Disk management end
laonap166
Mcsa 2012 m畉ng cn b畉n ph畉n 3
Mcsa 2012 m畉ng cn b畉n ph畉n 3Mcsa 2012 m畉ng cn b畉n ph畉n 3
Mcsa 2012 m畉ng cn b畉n ph畉n 3
laonap166
Disk management ph畉n 2
Disk management ph畉n 2Disk management ph畉n 2
Disk management ph畉n 2
laonap166
Mcsa 2012 m畉ng cn b畉n ph畉n 5
Mcsa 2012 m畉ng cn b畉n ph畉n 5Mcsa 2012 m畉ng cn b畉n ph畉n 5
Mcsa 2012 m畉ng cn b畉n ph畉n 5
laonap166
Mcsa 2012 m畉ng cn b畉n ph畉n 4
Mcsa 2012 m畉ng cn b畉n ph畉n 4Mcsa 2012 m畉ng cn b畉n ph畉n 4
Mcsa 2012 m畉ng cn b畉n ph畉n 4
laonap166
Bi 3 Lm vi畛c v畛i bi畛u m畉u n但ng cao - Gi叩o tr狸nh FPT
Bi 3 Lm vi畛c v畛i bi畛u m畉u n但ng cao - Gi叩o tr狸nh FPTBi 3 Lm vi畛c v畛i bi畛u m畉u n但ng cao - Gi叩o tr狸nh FPT
Bi 3 Lm vi畛c v畛i bi畛u m畉u n但ng cao - Gi叩o tr狸nh FPT
MasterCode.vn
An Ton v b畉o m畉t HTTT-C董 b畉n v畛 m達 ho叩 (cryptography)
An Ton v b畉o m畉t HTTT-C董 b畉n v畛 m達 ho叩 (cryptography)An Ton v b畉o m畉t HTTT-C董 b畉n v畛 m達 ho叩 (cryptography)
An Ton v b畉o m畉t HTTT-C董 b畉n v畛 m達 ho叩 (cryptography)
dlmonline24h
畛 c動董ng 担n t畉p h畛 th畛ng th担ng tin qu畉n l箪
畛 c動董ng 担n t畉p h畛 th畛ng th担ng tin qu畉n l箪畛 c動董ng 担n t畉p h畛 th畛ng th担ng tin qu畉n l箪
畛 c動董ng 担n t畉p h畛 th畛ng th担ng tin qu畉n l箪
Qu叩ch 畉i D動董ng
Step by Step Installation of Microsoft SQL Server油2012
Step by Step Installation of Microsoft SQL Server油2012 Step by Step Installation of Microsoft SQL Server油2012
Step by Step Installation of Microsoft SQL Server油2012
Sameh AboulDahab
Disk management p1
Disk management p1Disk management p1
Disk management p1
laonap166
Bi 5 Lm vi畛c v畛i b叩o c叩o n但ng cao - Gi叩o tr狸nh FPT
Bi 5 Lm vi畛c v畛i b叩o c叩o n但ng cao - Gi叩o tr狸nh FPTBi 5 Lm vi畛c v畛i b叩o c叩o n但ng cao - Gi叩o tr狸nh FPT
Bi 5 Lm vi畛c v畛i b叩o c叩o n但ng cao - Gi叩o tr狸nh FPT
MasterCode.vn
Mcsa 2012 m畉ng cn b畉n ph畉n 2
Mcsa 2012 m畉ng cn b畉n ph畉n 2 Mcsa 2012 m畉ng cn b畉n ph畉n 2
Mcsa 2012 m畉ng cn b畉n ph畉n 2
laonap166
T畛 h畛c mcsa 2012 m畉ng cn b畉n ph畉n 1
T畛 h畛c mcsa 2012 m畉ng cn b畉n ph畉n 1T畛 h畛c mcsa 2012 m畉ng cn b畉n ph畉n 1
T畛 h畛c mcsa 2012 m畉ng cn b畉n ph畉n 1
laonap166
Mcsa 2012 m畉ng cn b畉n ph畉n 7
Mcsa 2012 m畉ng cn b畉n ph畉n 7Mcsa 2012 m畉ng cn b畉n ph畉n 7
Mcsa 2012 m畉ng cn b畉n ph畉n 7
laonap166
Mcsa 2012 ntfs permission
Mcsa 2012 ntfs permissionMcsa 2012 ntfs permission
Mcsa 2012 ntfs permission
laonap166
Mcsa 2012 m畉ng cn b畉n ph畉n 6
Mcsa 2012 m畉ng cn b畉n ph畉n 6Mcsa 2012 m畉ng cn b畉n ph畉n 6
Mcsa 2012 m畉ng cn b畉n ph畉n 6
laonap166
Mcsa 2012 file server v share permission
Mcsa 2012 file server v share permissionMcsa 2012 file server v share permission
Mcsa 2012 file server v share permission
laonap166
Disk management end
Disk management endDisk management end
Disk management end
laonap166
Mcsa 2012 m畉ng cn b畉n ph畉n 3
Mcsa 2012 m畉ng cn b畉n ph畉n 3Mcsa 2012 m畉ng cn b畉n ph畉n 3
Mcsa 2012 m畉ng cn b畉n ph畉n 3
laonap166
Disk management ph畉n 2
Disk management ph畉n 2Disk management ph畉n 2
Disk management ph畉n 2
laonap166
Mcsa 2012 m畉ng cn b畉n ph畉n 5
Mcsa 2012 m畉ng cn b畉n ph畉n 5Mcsa 2012 m畉ng cn b畉n ph畉n 5
Mcsa 2012 m畉ng cn b畉n ph畉n 5
laonap166
Mcsa 2012 m畉ng cn b畉n ph畉n 4
Mcsa 2012 m畉ng cn b畉n ph畉n 4Mcsa 2012 m畉ng cn b畉n ph畉n 4
Mcsa 2012 m畉ng cn b畉n ph畉n 4
laonap166
Bi 3 Lm vi畛c v畛i bi畛u m畉u n但ng cao - Gi叩o tr狸nh FPT
Bi 3 Lm vi畛c v畛i bi畛u m畉u n但ng cao - Gi叩o tr狸nh FPTBi 3 Lm vi畛c v畛i bi畛u m畉u n但ng cao - Gi叩o tr狸nh FPT
Bi 3 Lm vi畛c v畛i bi畛u m畉u n但ng cao - Gi叩o tr狸nh FPT
MasterCode.vn
An Ton v b畉o m畉t HTTT-C董 b畉n v畛 m達 ho叩 (cryptography)
An Ton v b畉o m畉t HTTT-C董 b畉n v畛 m達 ho叩 (cryptography)An Ton v b畉o m畉t HTTT-C董 b畉n v畛 m達 ho叩 (cryptography)
An Ton v b畉o m畉t HTTT-C董 b畉n v畛 m達 ho叩 (cryptography)
dlmonline24h
畛 c動董ng 担n t畉p h畛 th畛ng th担ng tin qu畉n l箪
畛 c動董ng 担n t畉p h畛 th畛ng th担ng tin qu畉n l箪畛 c動董ng 担n t畉p h畛 th畛ng th担ng tin qu畉n l箪
畛 c動董ng 担n t畉p h畛 th畛ng th担ng tin qu畉n l箪
Qu叩ch 畉i D動董ng
Step by Step Installation of Microsoft SQL Server油2012
Step by Step Installation of Microsoft SQL Server油2012 Step by Step Installation of Microsoft SQL Server油2012
Step by Step Installation of Microsoft SQL Server油2012
Sameh AboulDahab

Similar to Mcsa 2012 local group policy (20)

Gpedit.msc
Gpedit.mscGpedit.msc
Gpedit.msc
laonap166
Tai lieuhuongdansudung
Tai lieuhuongdansudungTai lieuhuongdansudung
Tai lieuhuongdansudung
danhhui2002
New microsoft word document
New microsoft word documentNew microsoft word document
New microsoft word document
Hong Phi L畛c
Gpo
GpoGpo
Gpo
it
Khoa.pptx
Khoa.pptxKhoa.pptx
Khoa.pptx
HongHoi11
Mcsa 2012 domain network
Mcsa 2012 domain networkMcsa 2012 domain network
Mcsa 2012 domain network
laonap166
C04 2 qu畉n l箪 ti kho畉n ng動畛i d湛ng v nh坦m
C04 2 qu畉n l箪 ti kho畉n ng動畛i d湛ng v nh坦mC04 2 qu畉n l箪 ti kho畉n ng動畛i d湛ng v nh坦m
C04 2 qu畉n l箪 ti kho畉n ng動畛i d湛ng v nh坦m
dlmonline24h
Mcsa 2012 domain network thu畛c t鱈nh user v group
Mcsa 2012 domain network thu畛c t鱈nh user v groupMcsa 2012 domain network thu畛c t鱈nh user v group
Mcsa 2012 domain network thu畛c t鱈nh user v group
laonap166
Windows server-2008tai lieu mang
Windows server-2008tai lieu mangWindows server-2008tai lieu mang
Windows server-2008tai lieu mang
Quang Tien
Windows server-2008
Windows server-2008Windows server-2008
Windows server-2008
Hate To Love
Windows server-2008
Windows server-2008Windows server-2008
Windows server-2008
Hate To Love
Lab 5. GPO.pdf
Lab 5. GPO.pdfLab 5. GPO.pdf
Lab 5. GPO.pdf
7311NguynDuyNin
Lecture chinhsachnhom
Lecture chinhsachnhomLecture chinhsachnhom
Lecture chinhsachnhom
L達 畉t
File server resource manager
File server resource managerFile server resource manager
File server resource manager
laonap166
Bao cao th動味c t但味p
Bao cao th動味c t但味p Bao cao th動味c t但味p
Bao cao th動味c t但味p
killzzz
Local security policy
Local security policyLocal security policy
Local security policy
masternokizep
Gpedit.msc
Gpedit.mscGpedit.msc
Gpedit.msc
laonap166
Tai lieuhuongdansudung
Tai lieuhuongdansudungTai lieuhuongdansudung
Tai lieuhuongdansudung
danhhui2002
New microsoft word document
New microsoft word documentNew microsoft word document
New microsoft word document
Hong Phi L畛c
Gpo
GpoGpo
Gpo
it
Khoa.pptx
Khoa.pptxKhoa.pptx
Khoa.pptx
HongHoi11
Mcsa 2012 domain network
Mcsa 2012 domain networkMcsa 2012 domain network
Mcsa 2012 domain network
laonap166
C04 2 qu畉n l箪 ti kho畉n ng動畛i d湛ng v nh坦m
C04 2 qu畉n l箪 ti kho畉n ng動畛i d湛ng v nh坦mC04 2 qu畉n l箪 ti kho畉n ng動畛i d湛ng v nh坦m
C04 2 qu畉n l箪 ti kho畉n ng動畛i d湛ng v nh坦m
dlmonline24h
Mcsa 2012 domain network thu畛c t鱈nh user v group
Mcsa 2012 domain network thu畛c t鱈nh user v groupMcsa 2012 domain network thu畛c t鱈nh user v group
Mcsa 2012 domain network thu畛c t鱈nh user v group
laonap166
Windows server-2008tai lieu mang
Windows server-2008tai lieu mangWindows server-2008tai lieu mang
Windows server-2008tai lieu mang
Quang Tien
Windows server-2008
Windows server-2008Windows server-2008
Windows server-2008
Hate To Love
Windows server-2008
Windows server-2008Windows server-2008
Windows server-2008
Hate To Love
Lecture chinhsachnhom
Lecture chinhsachnhomLecture chinhsachnhom
Lecture chinhsachnhom
L達 畉t
File server resource manager
File server resource managerFile server resource manager
File server resource manager
laonap166
Bao cao th動味c t但味p
Bao cao th動味c t但味p Bao cao th動味c t但味p
Bao cao th動味c t但味p
killzzz
Local security policy
Local security policyLocal security policy
Local security policy
masternokizep

More from laonap166 (20)

Huong dan xu ly cac loi khi su dung phan mem reset may in
Huong dan xu ly cac loi khi su dung phan mem reset may inHuong dan xu ly cac loi khi su dung phan mem reset may in
Huong dan xu ly cac loi khi su dung phan mem reset may in
laonap166
Huong dan reset muc l200 epson
Huong dan reset muc l200 epsonHuong dan reset muc l200 epson
Huong dan reset muc l200 epson
laonap166
NEC Server Documents
NEC Server DocumentsNEC Server Documents
NEC Server Documents
laonap166
Mtcv gi叩m 畛c tt cntt
Mtcv gi叩m 畛c tt cnttMtcv gi叩m 畛c tt cntt
Mtcv gi叩m 畛c tt cntt
laonap166
N畉u b畉n lm it b畉n c畉n bi畉t
N畉u b畉n lm it  b畉n c畉n bi畉tN畉u b畉n lm it  b畉n c畉n bi畉t
N畉u b畉n lm it b畉n c畉n bi畉t
laonap166
Nh畉p mon lap trinh khong code
Nh畉p mon lap trinh khong code Nh畉p mon lap trinh khong code
Nh畉p mon lap trinh khong code
laonap166
Ha active active bang gfs2
Ha active  active bang gfs2Ha active  active bang gfs2
Ha active active bang gfs2
laonap166
H動畛ng d畉n ci 畉t ph畉n m畛m turnoffmonitor
H動畛ng d畉n ci 畉t ph畉n m畛m turnoffmonitorH動畛ng d畉n ci 畉t ph畉n m畛m turnoffmonitor
H動畛ng d畉n ci 畉t ph畉n m畛m turnoffmonitor
laonap166
Bao cao web cake php
Bao cao web cake phpBao cao web cake php
Bao cao web cake php
laonap166
He 74 a-thltht-l達xu但nt但m-11tlt
He 74 a-thltht-l達xu但nt但m-11tltHe 74 a-thltht-l達xu但nt但m-11tlt
He 74 a-thltht-l達xu但nt但m-11tlt
laonap166
Qu畉n l箪 cua hang giai khat lxt
Qu畉n l箪 cua hang giai khat lxtQu畉n l箪 cua hang giai khat lxt
Qu畉n l箪 cua hang giai khat lxt
laonap166
Ve ngoi nha lap trinh do hoa bang c
Ve ngoi nha lap trinh do hoa bang cVe ngoi nha lap trinh do hoa bang c
Ve ngoi nha lap trinh do hoa bang c
laonap166
Don xin thanh lap doanh nghiep lien doanh
Don xin thanh lap doanh nghiep lien doanhDon xin thanh lap doanh nghiep lien doanh
Don xin thanh lap doanh nghiep lien doanh
laonap166
Thu cam on khach hang
Thu cam on khach hangThu cam on khach hang
Thu cam on khach hang
laonap166
Cai dat su_dung_acronis_snapdeployforpc_debungfilebackuphangloat
Cai dat su_dung_acronis_snapdeployforpc_debungfilebackuphangloatCai dat su_dung_acronis_snapdeployforpc_debungfilebackuphangloat
Cai dat su_dung_acronis_snapdeployforpc_debungfilebackuphangloat
laonap166
Xd email server zimbra
Xd email server zimbraXd email server zimbra
Xd email server zimbra
laonap166
Tom tat ly thuyet thi b畉ng l叩i xe b2
Tom tat ly thuyet thi b畉ng l叩i xe b2Tom tat ly thuyet thi b畉ng l叩i xe b2
Tom tat ly thuyet thi b畉ng l叩i xe b2
laonap166
Policy Based Assignment DHCP Windows Server 2012
Policy Based Assignment DHCP  Windows Server 2012Policy Based Assignment DHCP  Windows Server 2012
Policy Based Assignment DHCP Windows Server 2012
laonap166
How to backup active directory domain services database in windows server 201...
How to backup active directory domain services database in windows server 201...How to backup active directory domain services database in windows server 201...
How to backup active directory domain services database in windows server 201...
laonap166
Dns backup and recovery in windows server 2012 r2
Dns backup and recovery in windows server 2012 r2Dns backup and recovery in windows server 2012 r2
Dns backup and recovery in windows server 2012 r2
laonap166
Huong dan xu ly cac loi khi su dung phan mem reset may in
Huong dan xu ly cac loi khi su dung phan mem reset may inHuong dan xu ly cac loi khi su dung phan mem reset may in
Huong dan xu ly cac loi khi su dung phan mem reset may in
laonap166
Huong dan reset muc l200 epson
Huong dan reset muc l200 epsonHuong dan reset muc l200 epson
Huong dan reset muc l200 epson
laonap166
NEC Server Documents
NEC Server DocumentsNEC Server Documents
NEC Server Documents
laonap166
Mtcv gi叩m 畛c tt cntt
Mtcv gi叩m 畛c tt cnttMtcv gi叩m 畛c tt cntt
Mtcv gi叩m 畛c tt cntt
laonap166
N畉u b畉n lm it b畉n c畉n bi畉t
N畉u b畉n lm it  b畉n c畉n bi畉tN畉u b畉n lm it  b畉n c畉n bi畉t
N畉u b畉n lm it b畉n c畉n bi畉t
laonap166
Nh畉p mon lap trinh khong code
Nh畉p mon lap trinh khong code Nh畉p mon lap trinh khong code
Nh畉p mon lap trinh khong code
laonap166
Ha active active bang gfs2
Ha active  active bang gfs2Ha active  active bang gfs2
Ha active active bang gfs2
laonap166
H動畛ng d畉n ci 畉t ph畉n m畛m turnoffmonitor
H動畛ng d畉n ci 畉t ph畉n m畛m turnoffmonitorH動畛ng d畉n ci 畉t ph畉n m畛m turnoffmonitor
H動畛ng d畉n ci 畉t ph畉n m畛m turnoffmonitor
laonap166
Bao cao web cake php
Bao cao web cake phpBao cao web cake php
Bao cao web cake php
laonap166
He 74 a-thltht-l達xu但nt但m-11tlt
He 74 a-thltht-l達xu但nt但m-11tltHe 74 a-thltht-l達xu但nt但m-11tlt
He 74 a-thltht-l達xu但nt但m-11tlt
laonap166
Qu畉n l箪 cua hang giai khat lxt
Qu畉n l箪 cua hang giai khat lxtQu畉n l箪 cua hang giai khat lxt
Qu畉n l箪 cua hang giai khat lxt
laonap166
Ve ngoi nha lap trinh do hoa bang c
Ve ngoi nha lap trinh do hoa bang cVe ngoi nha lap trinh do hoa bang c
Ve ngoi nha lap trinh do hoa bang c
laonap166
Don xin thanh lap doanh nghiep lien doanh
Don xin thanh lap doanh nghiep lien doanhDon xin thanh lap doanh nghiep lien doanh
Don xin thanh lap doanh nghiep lien doanh
laonap166
Thu cam on khach hang
Thu cam on khach hangThu cam on khach hang
Thu cam on khach hang
laonap166
Cai dat su_dung_acronis_snapdeployforpc_debungfilebackuphangloat
Cai dat su_dung_acronis_snapdeployforpc_debungfilebackuphangloatCai dat su_dung_acronis_snapdeployforpc_debungfilebackuphangloat
Cai dat su_dung_acronis_snapdeployforpc_debungfilebackuphangloat
laonap166
Xd email server zimbra
Xd email server zimbraXd email server zimbra
Xd email server zimbra
laonap166
Tom tat ly thuyet thi b畉ng l叩i xe b2
Tom tat ly thuyet thi b畉ng l叩i xe b2Tom tat ly thuyet thi b畉ng l叩i xe b2
Tom tat ly thuyet thi b畉ng l叩i xe b2
laonap166
Policy Based Assignment DHCP Windows Server 2012
Policy Based Assignment DHCP  Windows Server 2012Policy Based Assignment DHCP  Windows Server 2012
Policy Based Assignment DHCP Windows Server 2012
laonap166
How to backup active directory domain services database in windows server 201...
How to backup active directory domain services database in windows server 201...How to backup active directory domain services database in windows server 201...
How to backup active directory domain services database in windows server 201...
laonap166
Dns backup and recovery in windows server 2012 r2
Dns backup and recovery in windows server 2012 r2Dns backup and recovery in windows server 2012 r2
Dns backup and recovery in windows server 2012 r2
laonap166

Mcsa 2012 local group policy

  • 1. MCSA 2012 Local Group Policy Khi user ng nh畉p th狸 h畛 ch畛u nh畛ng 叩p 畉t c畛a HDH, trong qu叩 tr狸nh qu畉n l箪 ta c坦 nhu c畉u h畉n ch畉 hay th棚m vo c叩c quy畛n h畉n c畛a h畛 khi truy c畉p 畛ng d畛ng hay truy c畉p ti nguy棚n. C叩c th畛i HDH windows c滴 th狸 ta ph畉i m畛 c叩c file system.ini 畛 c畉u h狸nh. T畛 windows 98 tr畛 l棚n, Microsoft cho ph辿p ta th畛c hi畛n c畉u h狸nh b畉ng Registry, b畉ng c担ng c畛 ny th狸 admin c坦 th畛 thi畉t l畉p c叩c quy 畛nh 叩p 畉t l棚n h畛 th畛ng, user . V狸 vi畛c ch畛nh s畛a registry r畉t ph畛c t畉p, Microsoft l畉y 1 s畛 key trong registry 畛 t畉o thnh Group Policy (ch鱈nh s叩ch nh坦m) gi炭p c叩c admin c坦 th畛 ch畛nh s畛a d畛 dng. Group Policy c坦 th畛 叩p d畛ng l棚n local computer hay m担i tr動畛ng domain. Group Policy tr棚n local computer 動畛c g畛i l Local Group Policy (local policy). C担ng c畛 qu畉n l箪 local policy: C叩ch 1: run -> gpedit.msc (xu畉t hi畛n c担ng c畛 qu畉n l箪 l Local Group Policy Editor).
  • 2. C叩ch 2: run -> mmc (giao di畛n console root), menu File ch畛n Add/Remove Snap-in. ch畛n Group Policy Object Editor, 畛 m畉c 畛nh Local computer - > add r畛i save l畉i.
  • 4. Policy g畛m 2 ph畉n: Computer Configuration: n畉u thi畉t l畉p c叩c policy trong ph畉n ny th狸 畛i t動畛ng b畛 t叩c 畛ng l computer v user account User Configuration: 畛i t動畛ng b畛 t叩c 畛ng l user account. C叩c gi叩 tr畛 c坦 tr棚n Policy c畛a Windows: Not configured/Defined: kh担ng can thi畛p vo policy, 畛 m畉c 畛nh theo Microsoft ( gi叩 tr畛 m畉c 畛nh c坦 l炭c s畉 l disable policy, c坦 l炭c s畉 l enable policy). Enabled: b畉t policy. Disable: t畉t policy. C叩ch 叩p 畉t policy 達 hi畛u ch畛nh cho h畛 th畛ng: M畛t s畛 Policy s畉 t畛 畛ng c坦 hi畛u l畛c.
  • 5. Ta vo run -> cmd, d湛ng l畛nh: gpupdate /force 畛 b畉t bu畛c h畛 th畛ng c畉p nh畉t policy. N畉u gpupdate /force m v畉n ch動a th畉y c坦 hi畛u l畛c th狸 log off sau 坦 log on l畉i. 3 b動畛c tr棚n kh担ng d湛ng 動畛c th狸 Restart server (l動u 箪: ch畛 d湛ng khi 3 c叩ch tr棚n kh担ng c坦 hi畛u l畛c). M畛t s畛 policy th動畛ng d湛ng: 1/ B畉t/T畉t ch畛c nng Display shutdown event tracker: 但y l ch畛c nng b畉t ta khai b叩o l箪 do n畉u t畉t server. Computer configuration Administrative Templates System: b棚n ph畉i ch畛n Display shutdown event tracker
  • 6. 2/ C叩c policy li棚n quan 畉n Control Panel User Configuration Administrative Templates Control Panel + Show only specified Control Panel items: ch畛 cho ph辿p s畛 d畛ng 1 s畛 item trong control panel do admin ch畛 畛nh. enable r畛i click show, ta nh畉p 炭ng t棚n item tr棚n control panel m ta cho ph辿p hi畛n th畛 v鱈 d畛 ch畛 cho ph辿p hi畛n th畛 item fonts
  • 7. 叩nh l畛nh: gpupdate /force K畉t qu畉:
  • 8. + Prohibit access to Control Panel and PC settings: c畉m truy c畉p Control Panel. B畉t l畛i c畛a policy ny l nh畛ng thi畉t l畉p li棚n quan 畉n control panel 畛u b畛 c畉m ( Screen solution, Properties Computer, v.v 畛u b畛 c畉m). 3/ C叩c policy li棚n quan 畉n Desktop User Configuration Administrative Templates Desktop + Remove Recycle Bin icon from desktop: m畉t icon Recycle Bin 畛 desktop (mu畛n m畉t th狸 enable policy ny).
  • 9. 4/ C叩c policy li棚n quan 畉n Start Menu v Taskbar User Configuration Administrative Templates Start Menu and Taskbar + Remove Run menu from Start menu: c畉m ch畉y menu Run (b畉m Windows + R c滴ng b畛 c畉m). 5/ C叩c policy li棚n quan 畉n System + Prevent access to the command prompt: c畉m s畛 d畛ng cmd. + Dont run specified Windows application: c畉m c叩c 畛ng d畛ng c畛a Windows. enable, ch畛n show M畛i 畛ng d畛ng s畉 c坦 file th畛c thi (*.exe), ch畛 c畉n add file th畛c thi l policy c畉m 動畛c 畛ng d畛ng. v鱈 d畛: c畉m internet explore (IE), file th畛c thi c畛a IE l iexplore.exe
  • 10. + Run only specified Windows application: ch畛 cho ch畉y c叩c 畛ng d畛ng 動畛c ch畛 畛nh. Local Security Policy (ch鱈nh s叩ch b畉o m畉t) N坦 n畉m trong Computer Configuration Windows Settings Security Settings ho畉c c坦 th畛 m畛 n坦 b畉ng l畛nhsecpol.msc C叩c security policy th動畛ng g畉p: Account Policies (ch鱈nh s叩ch ti kho畉n): 1/ Password Policies: nh畛ng ch鱈nh s叩ch li棚n quan 畉n m畉t kh畉u
  • 11. + Minimum password length: quy 畛nh chi畛u di t畛i thi畛u c畛a m畉t kh畉u. + Minimum password age: tu畛i th畛 t畛i thi畛u c畛a 1 password, n畉u quy 畛nh l 2 th狸 sau 2 ngy password m畛i c坦 th畛 動畛c 畛i. + Maximum password age: tu畛i th畛 t畛i a c畛a 1 password (m畉c 畛nh 42 ngy). L炭c ny user n畉u kh担ng mu畛n thay 畛i password th狸 c坦 th畛 畉t l畉i password c滴, do 坦 ta c畉n 1 policy 畛 ngn c畉n vi畛c ny l: + Enforce password history: n畉u ch畛n 3 th狸 n坦 s畉 nh畛 3 password tr動畛c 坦 c畛a user. L畉n 1 畉t pass: 12 3 th狸 n坦 s畉 nh畛 l畉i, v n坦 s畉 nh畛 t畛i a c叩i s畛 m ta ch畛 畛nh. Theo y棚u c畉u c畛a Microsoft th狸 n棚n 畛 24 (!!). + Password must meet complexity requirements: ph畉i 畉t password ph畛c t畉p (xem l畉i b Local User and Group). N畉u kh担ng mu畛n 畉t ph畛c t畉p th狸 disable. + Store passwords using reversible encryption: m畉c 畛nh windows l動u user, password d動畛i d畉ng m達 h坦a trong file SAM (Security Account Manager), c坦 2 d畉ng m達 h坦a l Reversible (c坦 th畛 d畛ch ng動畛c m達 h坦a 2 chi畛u) v Irreversible ( kh担ng th畛 d畛ch ng動畛c
  • 12. m達 h坦a 1 chi畛u). N畉u enable th狸 h畛 th畛ng s畉 m達 h坦a 2 chi畛u, lm gi畉m 畛 an ton khi c坦 ng動畛i no 坦 l畉y 動畛c file SAM. 2/ Account lockout Policy: c叩c ch鱈nh s叩ch kh坦a ti kho畉n + Account lockout threshold: ng動畛ng 畛 quy 畛nh kh坦a ti kho畉n (m畉c 畛nh l kh担ng kh坦a). N畉u ta ch畛 畛nh threshold l 3 th狸 n畉u nh畉p sai password 3 l畉n th狸 s畉 kh坦a ti kho畉n (l畉n 4 nh畉p 炭ng c滴ng kh担ng 動畛c). D湛ng 畛 ch畛ng d嘆 m畉t kh畉u. + Account lockout duration (T1) : kh坦a ti kho畉n trong v嘆ng bao nhi棚u ph炭t (gi畉 s畛 ta kh坦a trong 30 ph炭t) + Reset account lockout counter after (T2): nh畛 c坦 b畛 畉m (counter) m h畛 th畛ng th畛ng k棚 動畛c s畛 l畉n ng nh畉p sai, policy ny quy 畛nh th畛i gian b畛 畉m reset l畉i v畛 0. L炭c ny ng動畛i d湛ng m畛i c坦 th畛 ti畉p t畛c ng nh畉p L動u 箪: th畛i gian T1 >= T2. Khi ti kho畉n b畛 kh坦a th狸 s畉 hi畛n d畉u check Account is locked out N畉u ng動畛i d湛ng kh担ng mu畛n 畛i 畉n h畉t th畛i gian T2 畛 ng nh畉p th狸 c坦 th畛 nh畛 admin b畛 check . N畉u T1 = 0 th狸 ti kho畉n s畉 b畛 kh坦a cho 畉n khi admin b畛 check.
  • 13. Local Policies: c叩c ch鱈nh s叩ch c畛c b畛 User rights assignment: g叩n quy畛n cho ng動畛i d湛ng. + Allow log on locally: cho ph辿p ng nh畉p tr棚n m叩y. + Deny log on locally: c畉m ng nh畉p tr棚n m叩y ( n畉u user v畛a 動畛c Allow, v畛a b畛 Deny th狸 Deny m畉nh h董n => b畛 c畉m log on). + Shut down the system: cho ph辿p user no 動畛c t畉t m叩y. + Change the system time: cho ph辿p ch畛nh gi畛 h畛 th畛ng. Security Option: Trong giao di畛n log-on, m畉c 畛nh h畛 th畛ng hi畛n th畛 c叩c user ang c坦 => kh担ng b畉o m畉t, ta d湛ng policy + Interactive logon: Do not display last user name (kh担ng hi畛n th畛 user name cu畛i c湛ng v 畛ng th畛i kh担ng hi畛n ra c叩c user khi ng nh畉p). + Interactive logon: Do not require CTRL + ALT + DEL : khi log- on kh担ng c畉n b畉m t畛 h畛p 3 ph鱈m + Shutdown: Allow system to be shutdown without having to log on: cho ph辿p t畉t m叩y m kh担ng c畉n log on. + Account: Rename administrator account : 畛i t棚n ti kho畉n administrator. C叩c policy li棚n quan 畉n v畉n 畛 truy c畉p ti nguy棚n m畉ng. + Secpol.msc -> security options -> local policies -> Security Options Network access: Sharing and security model for local accounts: C叩c ch畉 畛 truy c畉p m畉ng Classic (default) : cho ph辿p ch畛ng th畛c b畉ng c叩c ti kho畉n tr棚n local computer c畛a m叩y chia s畉. Guest: ch畛 cho ph辿p vo b畉ng ti kho畉n guest. Account: Limit local account use of blank password to console log on only: c畉m ti kho畉n kh担ng c坦 password truy c畉p ti nguy棚n -> User Rights Assignment Access this computer from the network: cho ph辿p user, group truy c畉p ti nguy棚n (m畉c 畛nh l t畉t c畉 user).
  • 14. Deny access to this computer from the network : c畉m user, group no 坦 truy c畉p ti nguy棚n (n畉u v畛a allow, v畛a deny th狸 deny 動u ti棚n h董n). * Nh動 m狸nh 達 tr狸nh by, c叩c policy ta v畛a k畛 tr棚n l Local Group Policy 叩p 畉t cho t畉t c畉 user tr棚n h畛 th畛ng. T畛 Windows Vista tr畛 l棚n, Microsoft h畛 tr畛 c担ng c畛 叩p policy cho 1 user c畛 th畛 l Local User Policy. Start -> Run -> MMC -> Add/Remove Snap-in -> Group Policy Object Editor -> Browse -> tab user ch畛 畛nh user c畛 th畛 -> OK (mu畛n th棚m bao nhi棚u user th狸 lm l畉i b畉y nhi棚u l畉n).
  • 15. L動u 箪 1: C叩c policy l動u trong 1 file l: 動畛ng d畉n: C: Windows System32 Group Policy M畉c 畛nh folder Group Policy b畛 畉n, ta ph畉i hi畛n th畛 c叩c file 畉n.
  • 16. Machine: l動u c叩c policy c畛a m叩y t鱈nh, User: c叩c policy li棚n quan 畉n user. Ta x坦a folder ny v restart th狸 WIndows s畉 ph叩t sinh c畉u h狸nh default => m畉t policy. L動u 箪 2: Ta nh畉n th畉y Administrator c坦 th畛 ng nh畉p vo safe mode khi b畛 disable, th狸 畛 b畉o m畉t ti kho畉n Administrator (built-in) ta c畉n lm c叩c b動畛c sau:
  • 17. + T畉o user add vo group Administrators. + Rename ti kho畉n Administrator built-in. + 畉t password ph畛c t畉p cho Administrator built-in. N畉u c叩c b畉n mu畛n t狸m hi畛u th棚m v畛 c叩c policy th狸 download file ny Ti li畛u GPEDIT.MSC