Welcome to TechNet Blogs Sign in | Join | Help

Technical RollUp

Premier Field Engineering - Technical Rollup Mails

News

  • Disclaimer: All postings are provided "AS IS" with no warranties, and confer no rights. This weblog does not represent the thoughts, intentions, plans or strategies of Microsoft. This content is for informational purposes only. Microsoft makes no warranties express or implied, as to the information in this document. If you are a customer of Microsoft, please refer to the terms and conditions which cover the provision of support and consulting services to you/your organization.  If you are not corresponding in the course of, or in connection with a Microsoft contract or program with its own terms and conditions, please note that no liability is accepted by Microsoft for the contents of this document. 

    Whos Reading Where!?

    Locations of visitors to this page

    Make a Difference

September 2008 - Technical Rollup Mail - Security

News

 

Inside the Windows Vista Kernel http://go.microsoft.com/?linkid=9239060

By Mark Russinovich, Technical Fellow, Microsoft Platform and Services Division In this article, Mark discusses Windows Vista kernel features and enhancements in the areas of reliability, recovery, and security including the Kernel Transaction Manager, enhanced crash support, Volume Shadow Copy, BitLocker, and Code Integrity verification.

 

Evaluate System Center Configuration Manager 2007 SP1 http://go.microsoft.com/?linkid=9239062

Manage the full deployment and update life cycle with streamlined, policy-based automation and enhanced insight into -- and control over -- assets and systems compliance. Microsoft System Center Configuration Manager 2007 offers optimization for Windows--particularly Windows Server 2008 and Windows Vista--and extensibility to customized administration experiences and third-party applications.

 

patterns & practices Improving Web Services Security: Scenarios and Implementation Guidance for WCF http://go.microsoft.com/?linkid=9313821

Download the beta version of the WCF Security guide from the CodePlex web site. The guide, Improving Web Services Security: Scenarios and Implementation Guidance for WCF, is our Microsoft playbook for Windows Communication Foundation (WCF /"Indigo".) and shows you how to build secure services using WCF. A compendium of proven practices, product team recommendations and insights from the field, it includes end-to-end application scenarios (web applications / Smart Clients), as well as step-by-step 'How To's'. Most importantly, it frames the web services security space and shows you how to be effective with WCF.

 

Hyper-V RTM Now Available http://go.microsoft.com/?linkid=9239063

Take advantage of the scalability, high performance, reliability, security, flexibility, and manageability that an ideal virtualization platform should provide. A key feature of Windows Server 2008, Hyper-V has a thin, micro-kernelized hypervisor architecture with minimal attack surface, and can easily plug into your IT infrastructure so you can capitalize on your existing tools and processes for patching, provisioning, management, and support.

 

Windows Vista Security Guide http://go.microsoft.com/?linkid=9239064

Get the guidance and tools you need to use new and enhanced security technologies in Windows Vista to better defend the client computers in your organization against malware and protect corporate data. Application compatibility testing recommendations are also included.

 

Security Compliance Management http://go.microsoft.com/?linkid=9260645

Solution Accelerators are authoritative resources that help IT pros plan, deliver, operate, and manage IT systems that address real-world scenarios. Solution Accelerators provide free, prescriptive guidance and automation to accelerate cross-product integration, core infrastructure development, and other enhancements.

 

How Do I: Export and Import Certificates? http://go.microsoft.com/?linkid=9239072

Learn how to export and import certificates with this short, How-Do-I video.

 

Security White Papers  http://go.microsoft.com/?linkid=9215650

Security white papers that address the specific security needs of particular industries, such as the professional services and financial services industries.

 

Microsoft Security Bulletin Summary for July, 2008

http://www.microsoft.com/technet/security/bulletin/ms08-jul.mspx 

 

Search for previous security bulletins http://go.microsoft.com/?linkid=3992478 

 

Security Bulletin Feed http://go.microsoft.com/?linkid=3992479  RSS http://go.microsoft.com/?linkid=3992480

 

Microsoft Internet Security and Acceleration Server

 

Internet Security and Acceleration (ISA) Server TechCenter

http://technet.microsoft.com/en-gb/forefront/edgesecurity/default.aspx

Please note that if you have feedback on documentation or wish to request new documents - email isadocs@microsoft.com

 

New Community Contributed Content includes:

 

Security Considerations with Forefront Edge Virtual Deployments

http://technet.microsoft.com/en-us/library/cc891502.aspx

 

Considerations when using antivirus software on ISA Server

http://technet.microsoft.com/en-us/library/cc707727.aspx

 

"Deep Packet Inspection"; What Does it Mean, Really?

http://technet.microsoft.com/en-us/library/cc707728.aspx

 

Deploying Forefront Client Security to non domain joined servers on a perimeter network through ISA Server 2006

http://technet.microsoft.com/en-us/library/cc752954.aspx

 

Security Considerations with Forefront Edge Virtual Deployments

http://technet.microsoft.com/en-us/library/cc891502.aspx

 

ISA Server Branch Office Policies Best Practices: ISA Server co-location with a domain controller

http://technet.microsoft.com/en-us/library/cc891503.aspx

 

KCD with Cross-Forest Accounts

http://technet.microsoft.com/en-us/library/cc752953.aspx

 

Forefront Edge Security Community

http://technet.microsoft.com/en-gb/forefront/edgesecurity/bb687298.aspx

 

Forefront TMG (ISA Server) Product Team Blog

The ISA Server Product Team Blog (http://blogs.technet.com/isablog/) is updated on a regular basis. Latest entries include:

 

Files larger than 512MB are not served from cache after ISA Server firewall service is restarted

http://blogs.technet.com/isablog/archive/2008/07/30/files-larger-than-512mb-are-not-served-from-cache-after-isa-server-firewall-service-is-restarted.aspx

 

New Article on Enhancing TS Gateway Security with ISA Server 2006

http://blogs.technet.com/isablog/archive/2008/08/03/new-article-on-enhancing-ts-gateway-security-with-isa-server-2006.aspx

 

Understanding how you use this blog

http://blogs.technet.com/isablog/archive/2008/08/07/understanding-how-you-use-this-blog.aspx

 

Tales from the Edge

http://blogs.technet.com/isablog/archive/2008/08/07/tales-from-the-edge.aspx

 

ISA Server 2006 SP1 – New Perfmon Counter

http://blogs.technet.com/isablog/archive/2008/08/19/isa-server-2006-sp1-new-perfmon-counter.aspx

 

ISA & TMG NAT behavior And MS08-037

http://blogs.technet.com/isablog/archive/2008/08/28/isa-tmg-nat-behavior-and-ms08-037.aspx

 

Intelligent Application Gateway 2007

 

Intelligent Application Gateway 2007 Technical Resources

http://technet.microsoft.com/en-gb/forefront/edgesecurity/bb687299.aspx

 

Forefront Edge Security Community

http://technet.microsoft.com/en-gb/forefront/edgesecurity/bb687298.aspx

 

Intelligent Application Gateway Product Team Blog

The IAG Product Team Blog (http://blogs.technet.com/edgeaccessblog) is updated on a regular basis. Latest entries include:

 

Anouncement: Two AES Ciphersuites (128/256 bits) are now supported

http://blogs.technet.com/edgeaccessblog/archive/2008/08/05/anouncement-two-aes-ciphersuites-128-256-bits-are-now-supported.aspx

 

Documents

 

Understanding and Configuring User Account Control in Windows Vista http://go.microsoft.com/?linkid=9239065

Find out how UAC works, including deployment scenarios and ensuring that older applications will be compatible.

 

Windows Vista Application Development Requirements for UAC http://go.microsoft.com/?linkid=9239066

This article is intended to assist application developers with designing Windows Vista-capable applications that are compliant with UAC. Detailed steps about the design process are included, along with code samples, requirements, and best practices. This article also details technical updates and changes to the user experience in Windows Vista.

 

Step-by-Step Guide to Controlling Device Installation and Usage with Group Policy http://go.microsoft.com/?linkid=9239067

Controlling installation and device usage this way improves your security, and it enhances the effectiveness of your help desk by limiting the devices that users can install to those your organization approves and supports. Learn how to control the installation and usage of devices on the computers that you manage with Windows Vista and Windows Server 2008.

 

Step-by-Step Guide to Managing Multiple Local Group Policy http://go.microsoft.com/?linkid=9239068

This guide covers the fundamental concepts needed to successfully configure Multiple Local Group Policy objects on stand-alone computers running Windows Vista and offers several task-based scenarios that show you how to use each feature.

 

Microsoft Forefront Client Security Enterprise Manager http://go.microsoft.com/?linkid=9239069

The Enterprise Manager tool allows you to aggregate reporting and management of up to 10 Forefront Client Security down-level deployments. With this tool, you can manage up to 100,000 client computers from a single Forefront Client Security console.

 

Microsoft Forefront Integration Kit for Network Access Protection http://go.microsoft.com/?linkid=9239070

Together, Forefront Client Security and NAP can provide an additional defense-in-depth layer against malicious attacks and give you a significant degree of control over the security and health of networked computers. This collection of software components and guidance will help you configure a compliance health policy for computers that run Forefront Client Security and isolate noncompliant computers to a restricted network until compliance can be properly addressed.

 

New Microsoft Security Development Lifecycle (SDL) Center http://go.microsoft.com/?linkid=9239071

Find information about this industry-leading software security assurance process, and quickly access process guidance, training and resources, tools, and blogs.

 

Downloads

 

Microsoft Antigen for Exchange with Antigen Spam Manager with SP1 Trial Software

http://www.microsoft.com/downloads/details.aspx?FamilyID=866b63bf-6207-4197-9c5d-511b7212e40c&DisplayLang=en

 

Microsoft Source Code Analyzer for SQL Injection

http://www.microsoft.com/downloads/details.aspx?FamilyID=58a7c46e-a599-4fcb-9ab4-a4334146b6ba&DisplayLang=en

 

Forefront Security for Office Communications Server 2007 Beta

http://www.microsoft.com/downloads/details.aspx?FamilyID=d128fd1a-42a2-47cb-9de8-e4ea8ba2382d&DisplayLang=en

 

July 2008 Security Releases ISO Image

http://www.microsoft.com/downloads/details.aspx?FamilyID=b9456bd2-f6ef-4d61-9d3c-fa855118397d&DisplayLang=en

 

Office 2003/XP Add-in: Remove Hidden Data

http://www.microsoft.com/downloads/details.aspx?FamilyID=144e54ed-d43e-42ca-bc7b-5446d34e5360&DisplayLang=en

 

Microsoft Internet Security and Acceleration (ISA) Server 2006 Service Pack 1

http://www.microsoft.com/downloads/details.aspx?FamilyID=d2feca6d-81d7-430a-9b2d-b070a5f6ae50&DisplayLang=en

 

Microsoft® Windows® Malicious Software Removal Tool (KB890830)

http://www.microsoft.com/downloads/details.aspx?FamilyID=ad724ae0-e72d-4f54-9ab3-75b8eb148356&DisplayLang=en

 

Microsoft® Windows® Malicious Software Removal Tool (KB890830) x64

http://www.microsoft.com/downloads/details.aspx?FamilyID=585d2bde-367f-495e-94e7-6349f4effc74&DisplayLang=en

 

Update for Microsoft Office Outlook 2007 Junk Email Filter (KB953463)

http://www.microsoft.com/downloads/details.aspx?FamilyID=e269e6f4-afaf-4703-9238-5b84951f6324&DisplayLang=en

 

Update for Microsoft Office Outlook 2003 Junk Email Filter (KB953465)

http://www.microsoft.com/downloads/details.aspx?FamilyID=8f008afb-f6a9-42b2-8472-279623063dfb&DisplayLang=en

 

Update for Windows Mail Junk E-mail Filter for x64-based Systems [July 2008] (KB905866)

http://www.microsoft.com/downloads/details.aspx?FamilyID=749e10cd-f40c-4f94-8e38-d4221ded7652&DisplayLang=en

 

Update for Windows Mail Junk E-mail Filter [July 2008] (KB905866)

http://www.microsoft.com/downloads/details.aspx?FamilyID=aa029fde-f341-44fc-8b85-0c6f3d3c2d69&DisplayLang=en

 

Step-by-Step Guide: Demonstrate NAP IPsec Enforcement in a Test Lab

http://www.microsoft.com/downloads/details.aspx?FamilyID=298ff956-1e6c-4d97-a3ed-7e7ffc4bed32&DisplayLang=en

 

Microsoft Internet Security and Acceleration Server 2006 Management Pack for OpsMgr 2007

http://www.microsoft.com/downloads/details.aspx?FamilyID=c576fcdf-42f0-4eb5-990d-e8e7c7e9c07e&DisplayLang=en

 

Secure Web and Remote Access Enablement Datasheet

http://www.microsoft.com/downloads/details.aspx?FamilyID=3d253737-4cda-4b35-99e3-08ebbc02efc8&DisplayLang=en

 

Enterprise Network Protection Datasheet

http://www.microsoft.com/downloads/details.aspx?FamilyID=74bb13dc-15a5-483a-a879-1882aaef3268&DisplayLang=en

 

Enterprise Data Security Optimization Datasheet

http://www.microsoft.com/downloads/details.aspx?FamilyID=eb91333a-c26b-4a0d-9251-80a494df9e5c&DisplayLang=en

 

Security, Identity, and Access Management Datasheet

http://www.microsoft.com/downloads/details.aspx?FamilyID=b53dee69-a3f9-4800-91a8-42c1b8b365db&DisplayLang=en

 

Identity and Access Optimization Datasheet

http://www.microsoft.com/downloads/details.aspx?FamilyID=e6daec91-7669-47a6-a9f7-39fcce339bcc&DisplayLang=en

 

Application and Host Protection Datasheet

http://www.microsoft.com/downloads/details.aspx?FamilyID=1c60fb1f-d23a-4d51-a6b4-15dd3c633ce3&DisplayLang=en

 

System Center Solution: Managing Data Server Compliance

http://www.microsoft.com/downloads/details.aspx?FamilyID=f5db44ae-7017-43fc-a65b-4948173c409d&DisplayLang=en

 

A Guide to Group Policy Preferences for Users of PolicyMaker Standard Edition

http://www.microsoft.com/downloads/details.aspx?FamilyID=8d5f2917-7b6d-460d-83c1-497b721d666c&DisplayLang=en

 

Events/WebCasts 

 

Visit TechNet Spotlight: www.microsoft.com/technetspotlight   

Video on Demand, Video Downloads, PowerPoint Presentations, Audio and more

 

Microsoft Security Webcast Series: Upcoming and On-Demand

 

Security Webcast Calendar http://go.microsoft.com/fwlink/?LinkId=37910 

Find security webcasts listed in an easy-to-use calendar format.

 

Upcoming Security Webcasts

http://www.microsoft.com/events/security/upcoming.mspx 

 

Register for the following Webcasts on the link above

 

TechNet Webcast: Information About Microsoft August Security Bulletins (Level 200)

Wednesday, August 13, 2008 11:00 A.M.-12:00 P.M. Pacific Time

 

On-Demand Security Webcasts

http://www.microsoft.com/events/security/ondemand.mspx  

 

New or updated KB’s

 

Microsoft Internet Security and Acceleration Server

 

Microsoft server software and supported virtualization environments

http://support.microsoft.com/kb/957006

 

Intelligent Application Gateway 2007

 

Supported browsers, applications, and AV products in IAG

http://support.microsoft.com/kb/956907

 

Message of the Day feature in IAG

http://support.microsoft.com/kb/956906

 

Microsoft server software and supported virtualization environments

http://support.microsoft.com/kb/957006

 

Troubleshooting e-gap appliance sync issues

http://support.microsoft.com/kb/956895

 

A.O.B

 

Microsoft Product Lifecycle Information

Find information about your particular products on the Microsoft Product Lifecycle http://go.microsoft.com/?linkid=9239140 Web site.

 

See a List of Supported Service Packs http://go.microsoft.com/?linkid=9239141: Microsoft provides free software updates for security and nonsecurity issues for all supported service packs.

 

Security Awareness Materials http://go.microsoft.com/?linkid=9239085

Guidance, samples, and templates for creating a security-awareness program in your organization.

 

Learn Security On the Job http://go.microsoft.com/?linkid=9239086

 

Learning Paths for Security - Microsoft Training References and Resources http://go.microsoft.com/?linkid=9239087

 

Posted: Monday, September 01, 2008 12:00 AM by Justin Zarb
Filed under: , ,

Comments

No Comments

Anonymous comments are disabled
Page view tracker