【文章內(nèi)容簡介】
AppLocker是用來替換軟件限制策略的 ? SRP控制臺(tái)和 SRP規(guī)則在 Windows7 同樣也支持,主要用來實(shí)現(xiàn)向下兼容性 ? AppLocker規(guī)則完全獨(dú)立于 SRP規(guī)則 ? AppLocker組策略獨(dú)立于 SRP組策略 ? If AppLocker規(guī)則定義于一個(gè) GPO中,只有指定規(guī)則被應(yīng)用 ? 根據(jù)企業(yè)客戶端版本分別定義 AppLocker和 SRP規(guī)則 ? SRP和 AppLocker比較 Lesson 5:配置用戶賬戶控制 ?什么 UAC? ? UAC如何工作 ? Demo: 配置 UAC的組策略設(shè)置 ?配置 UAC提示設(shè)置 什么 UAC? 用戶賬戶控制 (UAC)是一項(xiàng)安全功能,使得用戶在標(biāo)準(zhǔn)用戶模式下執(zhí)行必須的日常任務(wù) ?UAC必要時(shí)會(huì)要求用戶提升到管理員模式下執(zhí)行相應(yīng)的操作 ?Windows 7增強(qiáng)了用戶控制的提升體驗(yàn) UAC如何工作 在 Windows 7中,當(dāng)用戶執(zhí)行一項(xiàng)需要管理員特權(quán)的任務(wù)時(shí),會(huì)出現(xiàn)什么提示 ? Administrative Users UAC prompts the user for permission to plete the task Standard Users UAC prompts the user for the credentials of a user with administrative privileges Demo: 配置 UAC的組策略設(shè)置 In this demonstration, you will see how to: ? Open the User Accounts window ? Review user groups ? View the Credential Prompt ? Change User Account Settings and View the Consent Prompt 10 min 配置 UAC提示設(shè)置 UAC的用戶體驗(yàn)級(jí)別有: ? Always notify me ? Notify me only when programs try to make changes to my puter ? Notify me only when programs try to make changes to my puter (do not dim my desktop) ? Never notify Lab A: Configuring UAC, Local Security Policies, EFS, and AppLocker ? Exercise 1: Configuring virus protection and User Account Control (UAC) notification settings in Action Center ? Exercise 2: Configuring Multiple Local Group Policies to manage the appearance of selected program icons ? Exercise 3: Configuring and testing encryption of files and folders ? Exercise 4: Configuring and testing AppLocker rules to control what programs can be executed Logon information Estimated time: 50 minutes Virtual machine 6292ALONDC1 6292ALONCL1 User name Contoso\Administrator Password Pa$$w0rd Lab A Scenario Your pany is implementing Windows 7 puters for all corporate users. As an administrator at your anization, you are responsible for configuring the new Windows 7 puters to support various corporate requirements. You have been asked to: ? Turn off virus protection notifications ? Verify the User Account Control (UAC) settings are set to “Always notify but not dim the desktop” ? Configure multiple local group policies to control which of the default program icons appear on users’ and administrators’ puters ? Encrypt all sensitive data on puters using EFS ? Use AppLocker rules to prevent corporate users from running Windows Media Player and installing unauthorized applications Lab A Review ? Where can you turn on and off security messages related to virus protection? What are some of the other security messages that can be configured in Windows 7? ? How can the notifications about changes to the puter be suppressed? ? Can multiple local group policies be created and applied to different users? ? What are some of the ways of protecting sensitive data in Windows 7? ? How can Windows 7 users be prevented from running applications, such as Windows Media Player? Lesson 6: 配置 Windows Firewall ?討論:什么是防火墻 ? ?配置基本防火墻設(shè)置 ?高級(jí)安全 Windows防火墻 ?常見應(yīng)用程序使用的端口 ? Demo: 配置入站、出戰(zhàn)連接安全規(guī)則 討論:什么是防火墻 ? 1. 你們公司正在使用哪種類型的防火墻 ? 2. 是什么原因選擇的它 ? 10 min 配置網(wǎng)絡(luò)位置 打開或關(guān)閉 Windows防火墻,自定義網(wǎng)絡(luò)位置設(shè)置 添加,修改和移除允許的程序 設(shè)置和修改多個(gè)活動(dòng)的配置文件設(shè)置 配置 Windows 防火墻提示 配置基本防火墻設(shè)置 高級(jí)安全 Windows防火墻 Windows Firewall with Advanced Security filters ining and outgoing connections based on its configuration Inbound rules explicitly allow or explicitly block traffic that matches criteria in the rule. Outbound rules explicitly allow or explicitly deny traffic originating from the puter that matches the criteria in the rule. Connection security r