Developers: Try out the Windows Identity Foundation Release Candidate

Windows Identity Foundation (formerly called code name Geneva framework) is a new Microsoft .NET Framework technology that gives developers a programming model and SDK to create new advanced identity capabilities in .NET applications.  It provides developers pre-built .NET security logic for building claims-aware applications, enhancing either ASP.NET or WCF applications.  Windows Identity Foundation makes it easeir to build richer, more secure applications (cloud and on-premise) without being a security and identity expert.  It will boost developer productivity, as a result, and enhance app security through a standard approach to federation, strong authentication and identity delegation.   

 

The RC is available here. 

 

Look for more information about "WIF" coming out of Microsoft's Professional Developer Conference, the week of Nov 16.

 

Action by Dec 1 - keep your protection current!

A reminder from the Forefront Server Security blog.

As we announced on July 1, 2009, Microsoft is revising its engine mix on Dec. 1, 2009 for the Forefront and Antigen products.  This change will allow customers to utilize a set of engines that help optimize detection, while also allowing us to invest in new areas for increasing overall protection for customers. 

 

Antimalware Protection

The AhnLab, CA, and Sophos engines will be retired on Dec. 1, 2009.  After December 1st, customers will not receive any updates for these retired engines. In order to make sure your Antigen and Forefront products continue to scan efficiently and effectively for malware, any customers running the AhnLab, CA, or Sophos engines must DISABLE these engines before Dec. 1, 2009 and select from the new set of five engines – Authentium, Kaspersky, Microsoft, Norman, and VirusBuster.

 

SPECIAL NOTE:  Antigen for SharePoint 8.0 and Antigen for Instant Messaging 8.0 customers – In order to gain access to the new engine set and provide optimal protection for your messaging and collaboration environments, please download the Service Pack 1 releases of these products on the MVLS or VLSC site prior to Dec. 1, 2009.  The updates for the new engine set will use a new update infrastructure as of Dec. 31, 2009 – the Service Pack 1 releases will allow you to continue to receive updates correctly from their new location. 

 

For more information about Service Pack 1 for Antigen for SharePoint and Antigen for IM, see the following KB article:

http://support.microsoft.com/kb/975850/

                                                              

-          SPECIAL NOTE:  Antigen for Exchange 8.0 and Antigen for SMTP Gateways 8.0 customers –These products will end of life on Dec. 31, 2009.  Customers must upgrade to Antigen 9.0 SP2 for Exchange before this date, as the product will no longer continue to receive anti-malware updates starting Jan. 1, 2010.   With the retirement of the CA, Sophos, and AhnLab engines on Dec. 1, customers running Antigen for Exchange 8.0 or Antigen SMTP Gateways 8.0 will only be protected by the Norman engine.  For customers who need to continue using this product between Dec. 1, 2009 and the end-of-life date of Dec. 31, 2009, please contact Forefront Contract Administration for access to the revised engine set. 

For more information on upgrading your Antigen for Exchange 8.0 or Antigen for SMTP Gateways 8.0 to Antigen 9.0, see the following KB article:

http://support.microsoft.com/kb/932396/

 

Antispam Protection

One of the most important changes in our engine revision strategy is moving to the Cloudmark antispam engine*, which provides 99%+ detection rate and less than 1 in 250,000 false positives (West Coast Labs).

 

The Mail-Filters SpamCure antispam engine will be retired on Dec. 1, 2009. Customers using Antigen products for antispam protection must upgrade to the latest service pack releases listed below BEFORE DEC. 1, 2009 to maintain their antispam defenses.  This is the only way to gain access to the new Cloudmark engine.  The service packs can be accessed on the Microsoft MVLS and VLSC sites:

-          Antigen for Exchange Server with Antigen Spam Manager 9.0 with SP2

-          Antigen for SMTP Gateways with Antigen Spam Manager 9.0 with SP2

 

For more information on the engine revision strategy, see the Antimalware Engine Notifications and Developments Web page or contact Forefront Contract Administration .  Again, we strongly urge all customers to update to the newest service packs before Dec. 1, 2009 to get the full protection benefits of the Forefront and Antigen server products. 

 

*Please note:  Customers using Forefront Security for Exchange Server will get access to the Cloudmark engine in the next version release – Forefront Protection 2010 for Exchange Server – scheduled to be available in Q4 CY09. 

 

Brita Jenquin

Sr. Product Manager

Forefront secure messaging screencast & interview

Cristian Mora Aguilar, Forefront Technical PM, starts off by briefly telling us about Microsoft's secure messaging solution and what business problems it resolves. He then gives us a screencast / demo of some of the cool scenarios enabled and problems solved with the secure messaging solution.  Find out how Microsoft products help secure Microsoft Exchange Server.

http://edge.technet.com/Media/Forefront-Secure-Messaging-screencast-and-interview/

 

Microsoft Security Intelligence Report

The 7th volume of the Microsoft Security Intelligence Report (SIR) was released today.  The top finding is that worms infections in the enterprise rose by nearly 100 percent during the first half of 2009. 

 

According to the report, rogue security software remained the single largest threat category for the first half of 2009. Microsoft products and services removed such malware from more than 13 million computers worldwide, down from 16.8 million in the second half of 2008.

 

The SIR provides a deep, accurate view of the threat landscape country-by-country and, for the first time, the SIR includes security best practices from countries that have consistently exhibited low malware infection, such as Japan, German and Austria. 

 

Data for the SIR is collected through a wide variety of means, including but not limited to: Microsoft’s Malicious Software Removal Tool, Bing, Windows Live OneCare, Windows Defender and, of course, Forefront solutions.

 

The full SIR, guidance and other resources are available here.

Direct Access and UAG video - Deep dive with a Program Manager

Ben Bernstein and Stephen Bowie tell us what the value is for Forefront Unified Access Gateway (UAG) with Direct Access (DA).

After this, we do a whiteboard of UAG + DA architecture, including explaining how it works with multiple UAG servers. Here's how the rest of the interview breaks down:

How UAG supports legacy IPv4 clients (Marker 3 @ 8:02)

How does the client know to connect to the proper DNS server and not the one from the local ISP? (Marker 4 @ 13:17)

How do we know it's securely talking to the proper DNS server? (Marker 5 @ 15:01)

What other components on UAG enable DA? (Marker 6 @ 16:10)

Additional value add for UAG with DA (Marker 7 @ 17:55)

http://edge.technet.com/Media/Direct-Access-and-UAG-video-Deep-dive-with-a-Program-Manager/

Get Microsoft Silverlight
Forefront scores in VB100

Forefront Client Security (FCS) received its 10th consecutive VB100 award in the October 2009 Edition of Virus Bulletin.  In order for a product to be awarded the VB100 award, it must detect 100% of the WildList malware samples and must not have any false positives (FP) on the Virus Bulletin clean file collection. 

FCS received one of the highest scores overall – and the highest among major competitors -  in both the proactive and reactive aspects of the new VB RAP (Reactive and Proactive) test, reaffirming the strong result shown in August VB edition and in the May 2009 report from AV-Comparative.org.

Schedule and Strategy Update for Forefront Endpoint Protection

Today we are announcing a schedule and strategy update for Forefront Endpoint Protection 2010, a component of the upcoming Forefront Protection Suite (previously codenamed “Stirling.”)

 

We are delaying the release Forefront Endpoint Protection 2010 - anti-malware for Windows desktops and servers - until the second half of 2010.  Based on customer feedback and market trends, we have made the strategic decision to build Forefront Endpoint Protection (FEP) on System Center Configuration Manager, Microsoft’s solution to comprehensively assess, deploy, and update servers, clients, and devices.  This approach better aligns our customers’ client management and security infrastructure, helping simplify deployment and reduce costs.

 

We are confident this is the right decision for our customers.  In the interim, we will continue to offer our current Forefront Client Security (FCS) solution, which supports and protects both Windows 7 and Windows Server 2008 R2.  We are developing the necessary tools and guidance to facilitate the future upgrade from Forefront Client Security to Forefront Endpoint Protection and will help customers with the migration process.

 

We also remain committed to providing integrated management for the Forefront Protection Suite.  We will release Forefront Protection Manager in the first half of 2010, as scheduled, providing multi-server management for Forefront Protection 2010 for Exchange Server and Forefront Protection 2010 for SharePoint.  We will provide information about endpoint security management in Forefront Protection Manager at a later time.

 

We are on track to release all other Forefront products on schedule, as part of our Business Ready Security strategy:

o   Fourth quarter 2009:  Forefront Protection 2010 for Exchange Server, Forefront Online Protection for Exchange, Forefront Threat Management Gateway 2010 and Forefront Unified Access Gateway 2010

o   First half 2010: Forefront Protection 2010 for SharePoint, Forefront Identity Manager 2010.

 

The Forefront team

MSFT Identity and Access news: Forefront Identity Manager RC1 and ADFS 2.0 SAML interoperability

The RC1 release of Forefront Identity Manager 2010 (FIM) is available today here.  The next version of Identity Lifecycle Manager 2007, FIM 2010 dramatically improves enterprise identity management by delivering powerful self-service capabilities for Office end-users, rich administrative tools and enhanced automation for IT professionals, and .NET and WS-* based extensibility for developers.  The final release is slated for the first quarter of 2010. 

 

What’s new in FIM RC1:

·         Significant performance and scalability improvements across the product.

·         Key feature enhancements, including management policy rule (MPR) explorer and capability to enable/disable MPR’s, usability improvements in the portal and ability to disable batch approve/reject of membership requests if needed. Also, a System Center Operations Manager (SCOM) management pack and configuration migration tools are new for RC1.

·         The FIM 2010 user interface has enhanced usability and layout in many areas, resulting directly from RC0 customer feedback.

·         The product is now rebranded as Forefront Identity Manager 2010, with a few exceptions, replacing the old “ILM 2” codename. 

 

FIM is part of Microsoft’s continued, far-reaching commitment to enabling more secure, identity-based access to applications  -  on-premises and in the cloud, from virtually any location or device.

 

This commitment includes other solutions, such as Forefront Unified Access Gateway, and capabilities in the Windows platform, such as Active Directory Federation Services 2.0 (formerly known by codename “Geneva.”) ADFS 2.0 uses identity federation to extend Active Directory authentication and single sign-on to cloud-based services, hosted by Microsoft or others, so IT can gain flexibility and cost savings but avoid managing extra user accounts and passwords.

 

Another key part of our efforts in identity and access management is work across the industry to ensure interoperability.  Today, for example, Microsoft was part of a Kantara Initiative and Liberty Alliance announcement.  ADFS passed SAML 2.0 interoperability testing, meaning it will interoperate with heterogeneous environments and provide federation.

 

And, also, this week the Organization for the Advancement of Structured Information Standards (OASIS) is holding its Identity Management 2009 conference. Microsoft is a sponsor and participating in sessions and discussion around helping governments transparently manage citizens' identities and access to information.  Lee Nackman, Microsoft vice president of the Identity and Security Division, is quoted in the OASIS press release.

 

"Promoting widespread use of secure and trustworthy digital identities, while preserving personal privacy and protecting civil liberties, is a critical challenge for governments and the technology industry. Working with government leaders, industry partners and consortia like OASIS, Microsoft is committed to the technical and policy innovation needed to provide citizens with safe access to resources and services, in both the public and private sectors. Identity Management 2009 will provide an ideal forum for knowledge sharing and collaboration in this area."

 

Steve Ballmer on The New Efficiency

Making business decisions regarding IT investment is tougher than ever. To help, today Microsoft hosted a special VIP Business Leadership Roundtable event.  CEO Steve Ballmer and moderator Robert Youngjohns, President of the Microsoft US Subsidiary, discussed major trends in the new role of technology in the workplace.  Ballmer and Youngjohns were joined by a panel of early adopter customers representing key industries like automotive, hospitality, transportation and IT.  Attendees got a close look at how real companies are making IT investments across the desktop, server, network and beyond. 

  • How IT needs to keep pace with increasingly sophisticated users
  • The ever more mobile and distributed workforce, and
  • The impact of greater industry regulations and ongoing threats to data.

Forefront identity and security solutions, and our Business Ready Security strategy, are core parts of the way Microsoft is helping customers tackle these issues.   You can view highlights of today's event and get lots of info on the range of Microsoft IT solutions - including a Business Ready Security overview, Secure Messaging, Secure Collaboration, Identity and Access Management and Information Protection at www.TheNewEfficiency.com

 

Microsoft Security Essentials available tomorrow

Microsoft Security Essentials, the new no-cost, anti-malware service that helps protect consumers against viruses, spyware and other malicious software, will be available tomorrow, Tuesday, Sept. 29. It requires no registration, trials or renewals and will be available for download directly from Microsoft at http://www.microsoft.com/security_essentials.

Making Microsoft Security Essentials (MSE) broadly available as a free consumer download for genuine Windows-based PCs is part of the company's ongoing commitment to provide a more trustworthy computing experience for all customers. The company hopes to encourage broader adoption of anti-virus protection across the consumer audience, which in turn will help increase security across the entire Windows ecosystem. For business customers, Microsoft continues to offer Forefront Client Security.

MSE will have a positive impact on Forefront products, because it allows Microsoft to capture additional threat intelligence from customers using MSE and apply it to our security research, signature development and protection capabilities in Forefront solutions.

Forefront Identity Manager RC1 at TEC 2009

Forefront Identity Manager Release Candidate 1 will be released on Sept 30 - moving closer to final release next year. In advance of the RC1 release, we will preview it this week at The Experts Conference (TEC) 2009 EMEA.  TEC 2009 EMEA presents a great opportunity to showcase significant feature enhancements since RC0 including improved manageability tools, updated UI and performance enhancements.  We're looking forward to seeing European customers and partners at the event and discussing identity management!

 

You will be able to download RC1 here on Sept 30.

CERN replaces Symantec with Forefront

CERN - the European Organization for Nuclear Research - recently announced in its computing newsletter that it is replacing Symantec with Forefront Client Security to protect PCs on its network.  Why?  From the newsletter:

By the end of this year, all NICE PCs will have MS Forefront Client Security installed. This new anti-virus and anti-malware application will replace the current anti-virus product from Symantec. The reasons for this change include the small footprint of the client application, excellent response times for pattern updates and very good integration with the existing NICE infrastructure.

Video: FPE vs FOPE and Exchange 2010 – Secure messaging with Forefront

Over on TechNet Edge Mike Chan, product manager for the Forefront team, breaks down the differences between security protection for Forefront Protection for Exchange (FPE), Forefront Online Protection for Exchange (FOPE), and the built-in protection which exists in Exchange 2010.  We start out with a brief history of the messaging products and then dig into the details of differences between FPE, FOPE, and Exchange 2010 on the whiteboard at [4:22].  Should you run FPE alone or FPE and FOPE?  Watch and decide.

Watch the video here:  http://edge.technet.com/Media/FPE-vs-FOPE-and-Exchange-2010--Secure-messaging-with-Forefront/ 

Forefront Protection 2010 for Exchange Server RC

If you're not already aware...the Release Candidate of Forefront Protection 2010 for Exchange Server (the next, newly named version of Forefront Security for Exchange) is available for download and evaluation now!  Part of the Forefront Protection Suite - the next generation of the Forefront Security Suite, aka "Stirling" - FPE provides fast and effective protection against malware and spam by inlcuding multiple scanning engines. Its comprehensive messaging protection also prevents out-of-policy content from entering or leaving your network using content filtering. And it integrates with Forefront Online Protection for Exchange to provide the defense-in-depth benefits of hosted and on-premise filtering in a single solution.

Forefront Client Security v1.0 on Windows 7 and Windows Server 2008 R2

Forefront Client Security (FCS) v1.0 is fully supported on Windows 7 and Windows Server 2008 R2 as of August 31, 2009.  With the release of new updates available through Windows Server Update Services or Microsoft Update, customers will be able to extend the protection of FCS v1.0 on Windows 7 and Windows Server 2008 R2 systems and incorporate security in their infrastructure upgrade plans.  More information on updates needed for this support is provided in a knowledge base article here.

 

FCS v1.0 will be supported on all of the following versions of Windows 7:  Windows 7 Business, Enterprise, Home, and Ultimate.  FCS v1.0 will also be supported on Windows Server 2008 R2 Standard Server and Windows Server 2008 R2 Enterprise Server installation.  For a full list of supported platforms, please visit http://technet.microsoft.com/en-us/library/bb404245.aspx

 

Windows Server 2008 R2 Server Core installation is not supported at this time. However, it is planned to be supported with future updates.

 

More Posts Next page »

Search

This Blog

Syndication

Page view tracker