文档介绍:UNCLASSIFIED
Report Number: C4-052R-00
Guide to Securing Microsoft
Windows 2000 Group Policy:
Security Configuration Tool Set
Network Security Evaluations and Tools Division
of the
Systems work Attack Center (SNAC)
Author: Updated: January 22, 2002
Julie M. Haney Version
National Security Agency
9800 Savage Rd. Suite 6704
Ft. Meade, MD 20755-6704
******@
UNCLASSIFIED
UNCLASSIFIED
Change Control
Version Date Details
22 Jan. 2002 Added this change control section to track version modifications.
On pp. 19 and 23, removed references to a “companion CD.”
In Chapter 2, renamed the section “Undoing Security Changes” to
“Before Making Security Changes” and moved the section to before
the “Checklist for Applying the mendations in this Guide”
section. In this same section changed “(described later)” to
“(described in Chapter 10).”
On page 23, added the line “ is available to .
government agencies only” under the “Passwords must meet
complexity requirements” table entry.
On page 25 under the Account Lockout Policy section, changed
“thousands of well-known passwords are tried” to “thousands of
words are tried.”
On page 26, changed “Maximum lifetime for user ticket removal” to
“Maximum lifetime for user ticket renewal.”
On page 30, added the “ENTERPRISE DOMAIN CONTROLLERS”
group to the “Access puter work” user right.
On page 37, under the table entry for “Allow Server Operators to
schedule tasks,” corrected the registry entry to be
HKLM\System\CurrentControlSet\Control\Lsa\SubmitControl= 0.
On page 54, under the Maximum log size table entry, changed the
last sentence in the note to read “This ensures that the system will
still halt if the event log exceeds 4 GB, even if there is space on the
hard drive.”
On page 84, moved the incorrect entry for %SystemRoot%\Program