Comprehensive AAP and Powerpoint slide.
Contents Active Directory Requirements 2 Servers 2 Active Directory 3 Organizational Unit Design 4 OU Design Figure 1 4 OU Design Figure 2 5 OU configuration 6 OU Structure 6 Security Groups 6 Distribution Groups 7 AD Rights Groups Delegation 7 OU Change Management 7 Failover Cluster Services 7 IP address Management (IPAM): 8 DHCP (for employee systems): 8 Exchange/Outlook (sending and receiving e-mail): 8 Windows Deployment Services: 9 File Server (FSRM(quota & file screening): 9 File Classification Infrastructure 9 BitLocker 10 Microsoft’s Internet Explorer 11 Removable Media 12 Additional GPO’s 13
Active Directory Requirements
Servers
Servers will be maintained in the WWTC datacenter. Servers will be racked to keep services and organizational assets together.
Example:
Maintaining this management method will allow for easier management of servers, faster identification of specific issues related to the servers, and greater network control for configuration of QoS policies, ACLs, and IP assignment.
Active Directory
Active directory will be configured on the two servers nyc-ad1 and nyc-ad2 running Windows Server 2012. As the wwtc.com domain already exists, the New York site will be a new child domain within the wwtc.com active directory forest. Doing this allows us to provide local access to user as well as supply access to users on the wwtc.com domain at the New York office. nyc-ad1 will handle the PDC emulator, RID master, and Infrastructure master FSMO rolls. nyc-ad2 will operate as the standby operations master for these roles in the event nyc-ad1 becomes unavailable. To ensure adequate replication between wwtc.com Active Directory systems and the New York office systems, our team will work with corporate offices to ensure proper link configuration, and timings are configured between the two sites. Separate AD sites will be configured for all geographic locations. This will assist with site replication, and ensure that users login to their local domain controllers. All Domain controllers will be configured as global catalogs.
The Active Directory Domain Services role will be deployed on nyc-ad1 and nyc-ad2. Configuration of nyc-ad1 will begin first with assigning the new child domain nyc-site.wwtc.com. Upon completion of required accounts and configurations the system will be restarted and replicated with the WWTC.COM domain. Upon synchronizing the initial server nyc-ad2 will have AD-DS installed and it will be added to the domain with nyc-ad1.
Nyc-ad1 and nyc-ad2 will maintain NTP time synchronization with the servers on the larger wwtc.com network infrastructure. This will prevent Kerberos errors and ensure that Active Directory does not become out of sync and cause replication errors that are the result of time drift.
CIFS file sharing from the storage array will be provided using authentication from the nyc-site.wwtc.com domain.
Topology as it relates to WWTC New York Offices:
( WWTC.COM NYC-Site.WWTC.COM Parent-Child Trust corp-ad1 corp-ad2 corp-ad3 nyc-ad1 nyc-ad2 )
DNS
Internal DNS Configuration
The NYC-SITE domain will manage its own AD-Integrated DNS zone and DNS configuration. This will allow resources to be shared with the WWTC.com domain as well as other child domains. To provide additional security to the DNS infrastructure dynamic updates will be set to "secure only". This prevents updates from untrusted sources. At present there are no non AD-Integrated zones configured. However if future requirements call for additional zones, all zone transfers must be configured for only approved organizational DNS servers.
External DNS Configuration
For security reasons a separate internal and external DNS namespace will be maintained. WWTC will utilize the existing worldwidetrade.com namespace. Public servers will accessible using the external namespace. External DNS configuration will be controlled by the WWTC IT staff. DNS will be configured to point to servers based on their location/IP address. Sub-domains will be created as needed to support organizational requirements.
Organizational Unit Design
OU Design Figure 1
OU Design Figure 2
OU configuration
OU Structure
1. OUs for the NYC Office will be located in the NYC-Site.WWTC.COM domain
2. Top-Level OUs will be created for each department, including the VP offices, IT staff, and security staff.
i. Each of these OUs will contain sub-OUs for users, groups and workstations
ii. GPOs for users and workstations will be applied to the applicable OU.
3. A Top-level OU will be created for Servers
i. GPOs for Servers will be applied to the Server OU.
1. Filters may be used to ensure systems receive only the necessary GPOs.
4. A Top-level OU will be created for Printers
i. GPOs may be applied to this OU to manage printers.
Security Groups
1. All Security groups will be managed by the WWTC IT Dept.
2. Security groups will be used to assign or deny user rights and permissions.
3. Security groups will be located in the department’s groups sub-OU.
4. Users may request new security group through the WWTC IT Dept.
a. Global groups must contain members from the local domain accounts only
b. Global groups will be created for each department
i. These groups can be used to assign rights via GPO.
c. Global groups may be used to grant or deny permissions to NYC-Site resources.
i. For example, they can be used to grant NTFS permissions to the department’s folder on the file server
d. Global groups are to be populated by user accounts only whenever possible. They should not contain nested groups. This provides transparency and helps ensure unauthorized users do not gain access to protected resources.
e. Naming Convention
i. [Dept]-S-[Function]
1. Example: VP_OPR-G-Brokers
a. Universal groups may contain users from any domain in the forest.
b. They can be used to grant permission to access resources in other domains in the forest.
c. Membership in universal groups is restricted and should be granted only when necessary.
d. Universal groups will be located in the department’s groups sub-OU.
e. Naming Convention
1. Example: NYC-U-VPReportShare
Distribution Groups
1. Distribution groups will be created on an as needed basis.
ii. Users may request new distribution groups through the WWTC IT Dept.
2. Distribution groups will be located in the department’s groups sub-OU.
iii. [Dept]-D-[Function]
1. Example: VP_OPR-D-Brokers
AD Rights Groups Delegation
1. AD rights will be delegated using the least privileged principle.
iv. For example: Help desk personnel will only have the rights delegated necessary to perform their job functions. These rights will be delegated only on the necessary OUs.
2. AD rights delegation must be approved by the IT manager using the change management procedures.
3. All delegations and changes must be documented.
OU Change Management
1. OU creation/change is restricted.
2. A change request form must be submitted in the instance that a change, such as adding an OU is requested.
3. Change requests will be submitted to a Change Management Board (CMB). The request will be reviewed and if approved will be given to WWTC IT staff for implementation.
Failover Cluster Services
Failover cluster services will be implemented on the app-srv1 and app-srv2 servers. To facilitate a quorum drive for the two systems an iSCSI mount will be configured using the Microsoft Software iSCSI initiator and a partition created on the iSCSI storage array. By using iSCSI it creates a persistent physical disk that will switch between the hosts in the event of the current holder of the drive going down. This drive maintains its connection to the server even when the user is logged off, which is not the case with a CIFS share or Microsoft shared folder. The actual name of the system that will be accessible to users is the virtual hostname app-srv. The virtual host name enables users to connect to the server holding the quorum even when that server changes as a result of a failure.
The Failover Cluster servers will be used to provide application and file server functions to the users. Applications include Remote Desktop Services, web services such as SharePoint or IIS, or shared applications deployed for use within the New York Offices of WWTC.
IP address Management (IPAM):
IPAM is an agentless multi-server, multi-service management feature that utilizes standard Windows remote management protocols to manage, monitor and collect data from IP address infrastructure servers. IPAM relies on a host of remote management technologies to provide full functionality. IPAM must be installed on a domain member computer. IPAM server only provides support for a single AD forest. In order to IPAM to work on AD it must be joined to a domain member server. Since the number of IP address we plan on using for the NYC office is less than 20,000 we can deploy a single IPAM server to manage all of the IP address space.
DHCP (for employee systems):
Dynamic Host Configuration Protocol (DHCP) is a method that dynamically and automatically assigns IP addressing (IP Addresses) to client computers located on the NY WWTC domain. The DHCP server not only issues the client IP address, but will also deliver the network subnet mask, the default gateway of the network, and both a primary and secondary DNS server IP addresses to domain client computers.
DHCP will be installed and configured on nyc-ad1 and nyc-ad2. Address pools will be created for all workstation subnets. MAC address reservations will be used to ensure only authorized systems are able to obtain an IP address. Employees are permitted to attach their notebook computers to the WWTC network. Employees must register their systems with the IT department to ensure that an address reservation is created for their system.
Exchange/Outlook (sending and receiving e-mail):
For the exchange server in the NYC WWTC network, we will utilize Microsoft Clustering Service. Cluster Service acts as a back-end cluster; it provides high availability for various applications such as databases, messaging and file and print services. MSCS attempts to minimize the effect of failure on the system as any node (a server in the cluster) fails or is taken offline. Microsoft Cluster Service is based on the shared-nothing clustering model. The shared-nothing model dictates that while several nodes in the cluster may have access to a device or resource, the resource is owned and managed by only one system at a time. The exchange Server operates within Microsoft Cluster Server (MSCS) on an active/standby basis. Therefore the exchange server cluster must consist of two machines: a primary node and a secondary node. The primary node runs Exchange Server under most conditions. The secondary node doesn't run Exchange Server until the primary node has a problem. Then, a cluster transition moves the set of Exchange services to the secondary node and makes it the active node. The secondary node takes on Exchange Server operations from the point of failure. A resource group must be created before the exchange server is installed on the cluster. When you install Exchange Server, the setup program adds components such as the System Attendant, the IS, the Directory Service (DS), and the Message Transfer Agent (MTA) to the resource group. The setup program also adds to the resource group the network share that holds message tracking logs, and the resource group specifies the IP address and network name that represent the cluster's virtual server. Without these components, Exchange Server can't function in a cluster; the application can move between the two physical computers during cluster transitions because the server that Exchange recognizes is virtual.
Windows Deployment Services:
A Windows Deployment Services server must be a member of an Active Directory Domain Services (AD DS) domain or a domain controller for an AD DS domain. WDS allows network-based installation of Windows operating systems, which reduces the complexity and cost when compared to manual installations. WDS transmits data and images by using multicast functionality
WDS will be installed and configured the WWTC domain and all child domains. This server will be used to deploy baseline images to all company workstations using PXE. Baseline images will be updated quarterly with current baseline requirements. All baselines must include all approved security patches, updated versions of pre-installed software, and all required organizational security settings.
File Server
To provide increased manageability, scalability, and data availability, the WWTC IT team enables a technology known as BranchCache across the network. BranchCache is a technology that copies content from WWTC’s Hong Kong file servers and caches (saves in memory) the content on to WWTC’s New York regional office file servers allowing client computers at the regional offices to access the content locally rather than over the WAN. A benefit of deploying BranchCache results in efficient optimization and use of bandwidth. For example, when a client accesses remote content in Japan, BranchCache is used to store (cache) the desired content locally on the NY site. If a client wants to access the same content later, that data does not need to be downloaded a second time as it already resides within the BranchCache in NY. By default, BranchCache allocates 5% of the disk space for the cache, but this value can easily be changed by creating and assigning a GPO. One of the concerns is bandwidth. Bandwidth can become quickly saturated if wireless networking (WLAN) is utilized alongside wired methods.
FSRM
FSRM will be installed and configured the WWTC domain and all child domains so that the type and quantity of data stored on the file servers can be controlled. Quotas will be set to ensure that there are hard and soft limits to control the amount of space that users have access to. File screening will be configured to block unauthorized file types from being stored on the file servers. This prevents wasted storage space, and added security.
File Classification Infrastructure
File Classification Infrastructure (FCI) implemented on the app-srv1 and app-srv2 servers. FCI is implemented through the File Server Resource Manager (FSRM) and installed with the FSRM Role Requirements will be obtained for management as to exactly what File Classifications the company would like implemented but below are some suggestions:
· File Classifications:
· IT
· Scan for IT related content that should not be viewed by standard users
· HR
· Protect HR related files related to personnel, policies, documentation
· Finance
· Protect company financial information
· Broker
· Protect Broker specific data.
· Ensure non-leakage of potential SEC protected information
· VP/Management
· Protect corporate proprietary information
FCI is an automated process that runs on the file server and classifies files that have certain content that may be sensitive. The process implements protections on these unprotected files to ensure proper permissions are assigned to allow only those who should have access to view the content of the file. Proper FCI configuration prevents data leakage and access to files by unauthorized users.
The policies and configuration of FCI can be tailored to meet the specific needs of the company.
BitLocker
In order to prevent unauthorized data access on lost, stolen, and compromised system devices, BitLocker will be employed. BitLocker will be deployed, implemented, and enforced through Active Directory Group Policy. BitLocker works by encrypting the entire contents of the operating system partition. It encompasses operating system files, virtual swap files, all of the systems current user files, and other system files. In order to access the encrypted content, a special BitLocker key must be used for decryption. In addition to system file encryption, BitLocker will also be used to check system file integrity during the systems boot process. BitLocker will prevent boot to the drive if any changes to the system files in between the last power down and current boot up are found.
BitLocker reduces disk throughput effectively slowing down system performance. Accordingly, BitLocker will not be pushed out to every single device on the WWTC network by default. Only devices that have been surveyed and identified as vulnerable due to the locational security issues and are gauged as easily accessible to unauthorized users will enrolled into the BitLocker group policy.
In order to properly implement BitLocker, devices must be outfitted with a Trusted Platform Module (TPM). TPM modules are required in order to generate and store cryptographic keys. All devices that are expected to be operating in non-secure locations will be ordered with TPM modules.
Devices that are not outfitted with TPM modules will still be locked down with BitLocker; however, they will generate and store security keys on a USB device. This will prevent devices from booting up unless the USB device is inserted.
BitLocker will be enabled via the Group Policy. The following policies will be edited in order to properly configure BitLocker for all Windows devices:
Computer Configuration>Policies>Administrative Templates>Windows Components>Bitlocker Drive Encryption.
Enable: Provide Unique Identifies for your organization
Computer Configuration>Policies>Administrative Templates>Windows Components>Bitlocker Drive Encryption>Fixed Data Drive.
Enable: Configured use of passwords for fixed data drives & Choose how BitLocker-protected fixed drives can be recover...
Computer Configuration>Policies>Administrative Templates>Windows Components>Bitlocker Drive Encryption>Operating System Drive
Enable: Require additional authentication at startup, Configure minimum PIN length for startup, and Choose how BitLocker-protected operating system drives ca...
Configure Require additional authentication at startup accordingly.
Computer Configuration>Policies>Administrative Templates>Windows Components>Bitlocker Drive Encryption>Removable Data Drives
Enable: Control use of BitLocker on removable drives, Configure use of passwords for removable drives, and Choose how BitLocker-protected removable drives can be r...
Computer Configuration>Policies>Administrative Templates> System>Trusted Platform Module Service
Enable: Turn on TPM backup o Active Directory Domain Services
Microsoft’s Internet Explorer
Microsoft’s Internet Explorer is required to be used by WWTC employees in order to access multiple company applications. The Internet Explorer will also be used by employees to browse websites and access applications hosted outside of the WWTC network, inherently resulting in major and minor security vulnerabilities. Accordingly, multiple security settings in Internet Explorer will be configured to enhance web browsing privacy and security. The Internet Explorer security configuration settings will be configured in Active Directory Group Policy editor and pushed down through Active Directory too all Microsoft Windows systems in the environment.
Security will be configured through group policy and pushed down to all systems in order to define security levels for specified websites. The Local intranet zone, Trusted sites zone, Restricted sites zone, and Internet zone will be configured.
The Local intranet zone will be customized with parameters to automatically add all local WWTC instant sites to this zone. This zone will be set to apply medium-low security as all internal WWTC intranet hosted websites can be trusted.
The Trusted sits zone will be configured as a zone with minimal to no security. Selective intranet and trusted partner websites will be manually configured into this zone.
The Restricted sites zone will be configured with selected sites that are deemed as unsecured and pose security risks, but cannot be entirely blocked for a number of reasons. This zone holds the highest security settings.
The Internet zone sill encompass all sites that do not fit in either the Local intranet zone, Trusted sites zone, or Restricted sites zone.
The use of cookies in the Internet Explorer web browser will be strictly restricted by configuration through Privacy settings. Both the use of First-party cookies and Third-party cookies are restricted.
Internet explorer web browsers will be configured to automatically clear all data in the cache upon the end of the web browsing session.
Other Internet Explorer settings that will be configured:
· Always ask me where to save files option will be configured
· Remember search and form history will be disabled
· Accept third-party cookies will be disabled
· Remember passwords for sites option will be disabled
· Use a master password option will be disabled
· Block pop-ups windows will be enabled
· Load images automatically will be enabled
· Enable JavaScript will be enabled
Removable Media
The ability for users to reach and write to and from removable devices such as CD/DVD drives, floppy drivers, USB drives, tape drives, and other portable devices will be restricted to all devices currently running on the confidential network.
The policy will be pushed down through group policy, dependent on the site and subnet of the device. The Local Computer Policy>Computer Configuration>Administrative Template>System>Removable Storage Access>All Removable Storage classes: Deny all access group policy will be pushed down through active directory.
Additional GPO’s
Group policy will be utilized to enforce strict and secure password policies throughout the domain against every single Windows server and workstation system on the network. Enforcement of password history, maximum password age, minimum password age, minimum password length, complexity requirements, and password storage using reversible encryption will be enabled and enforced through group policy.
Group policy will be configured to enable the Automatic Updates feature in Windows. All Windows systems will be forced to download and install Windows updates.
Group policy will be used to automatically rename all Local Administrator accounts to harden the machines against unwanted access.
All local guest accounts on all windows systems will be disabled through group policy. This will prevent unwanted access to the systems through unused local accounts on the system. Since all systems will be attached to the domain, guest and non-privileges local accounts are not required.
Event logs will be enabled through group policy. They will be configured to log event success and failures. Event logs are required for troubleshooting purposes. They can also be utilized to track down computer crimes committed internally or externally.
User Account Control shall be enabled on all workstations and servers in order to prevent malicious programs from damaging computers and spreading throughout the network.