Website under construction



Download 13,37 Mb.
Pdf ko'rish
bet102/131
Sana27.03.2022
Hajmi13,37 Mb.
#512480
1   ...   98   99   100   101   102   103   104   105   ...   131
Bog'liq
9780735697744 Introducing Windows Server 2016 pdf

Windows Defender 
Windows Defender is included (and running) by default when you install Windows Server 2016. 
If your organization has a company standard for malware technology, you can uninstall it by using 
Windows PowerShell, as well: 
Uninstall-WindowsFeature -Name Windows-Server-Antimalware 
Windows Defender receives updates via Windows Update. If your organization manages Windows 
Update via an update deployment tool, you need to ensure that you are downloading the updates to 
keep Windows Defender up to date with its definitions. 
You also can configure Windows Defender via Group Policy for central control and administration. 
Threat detection technologies 
No matter how much you try to secure an environment, you still need to perform audits to validate 
whether those measures are effective. Windows Server 2016 introduces two new audit subcategories 
to give you greater insight into the events: 

Audit Group Membership This is part of the Logon/Logoff event category. The events in this 
subcategory are generated when group memberships are enumerated or queried on the PC 
where the sign-in session was created. 


115 
CHAPTER 4 | Security and identity 

Audit PNP Activity Found in the Detailed Tracking category, you can use the Audit PNP Activity 
subcategory to audit when plug-and-play detects an external device. Only Success audits are 
recorded for this category. 
Additional changes have been made in Windows Server 2016 that expose more information to help 
you identify and address threats quickly. The following table provides more information: 
Area 
Improvements 
Kernel Default 
Audit Policy 
In previous releases, the kernel depended on the LSA to retrieve information 
in some of its events. In Server 2016, the process creation events audit policy 
is automatically turned on until an actual audit policy is received from the 
LSA. This results in better auditing of services that might start before the LSA 
starts 
Default process 
Security ACL 
(SACL) to 
LSASS.exe 
A default process, SACL was added to LSASS.exe to log processes attempting 
to access LSASS.exe. The SACL is L"S:(AU;SAFA;0x0010;;;WD)". You can turn 
this on under Advanced Audit Policy Configuration|Object Access|Audit Kernel 
Object. 
New fields in the 
sign-in event 
The sign-in event ID 4624 has been updated to include more verbose 
information to make them easier to analyze. The following fields have been 
added to event 4624: 

MachineLogon String: yes or no 
If the account that signed in to the PC is a computer account, this field 
will be yes; otherwise, the field is no. 

ElevatedToken String: yes or no 
If the account that signed in to the PC is an administrative sign-in, this 
field will be yes; otherwise, the field is no. Additionally, if this is part of a 
split token, the linked login ID (LSAP_LOGON_SESSION) will also be 
shown. 


Download 13,37 Mb.

Do'stlaringiz bilan baham:
1   ...   98   99   100   101   102   103   104   105   ...   131




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish