Implementing System Restore Points
1. Investigate the System Restore tool (used to manage system restore points). To access the tool, open the System tool from Control Panel (Control Panel > System and Security > System).
2. Then, click on System Protection (left menu).
System restore tool helps users of the operating system to restore back the previous versions of files that were deleted from the computer. The tool will not affect the state of the computer in the current condition like affecting the installed files or software. (Poulton, Bellet & Holt, 2015).
3. Identify appropriate sources of information (e.g. Windows Help, Microsoft Technet, etc.) for instructions for using the Windows 8.1 System Restore Point capability. Using those sources, research the procedures required to perform the following tasks:
a. Create a system restore point for a Windows 8.1 system
Launch the Windows Help and Support from the start menu, then search for create restore point.
From the search results, select “create restore point.”
This will take you to the panel with the descriptions on how to create the restore point on Windows operating system.
b. Use a system restore point to roll-back changes made to a Windows 8.1 system
To roll-back the changes made is possible on the Windows platform where there is the undo feature.
c. To access this, utilize the Windows Help and Support, after launching the Windows Help and Support, type “undo restore point.”
d. Select on the “undo system restore” option on the search results. This will give the guidelines on how to undo the system restore on the Windows operating system.
e. Remove system restore points from a Windows 8.1 system (some and all).
It is possible to remove the restore points from Windows 8.1 platform. This action is possible through the use of the delete restore point option in the Windows Help and Support. Search for “delete a restore point” on the Windows Help and Support tool. This will give a guide on whether to delete all the restore points or some of the restore point.
Managing Programs and Features for Windows 8.1
1. Programs and Features tool
This tool is a default point in Windows operating system where all the installed programs can be located in the computer. This tools can act as an alternative place for uninstalling programs from the computer. All the programs installed will be displayed together with the necessary information regarding the specified program like date modified, size on the disk etc (Poulton, Bellet, & Holt, 2015).
To access, launch the control panel on Windows operating system then under programs item, go to Program and Features option (Poulton, Bellet, & Holt, 2015).
2. Identify appropriate sources of information (e.g. Windows Help, Microsoft Technet, etc.) for instructions for using the Programs and Features tool. Using those sources, research the procedures required to perform the following tasks:
a. Turn Windows Features On or Off.
Windows Help and Support
To launch the windows help and support feature, access the start menu then locate the help and support menu item. Launch the help and support item the search help type programs and features then press enter (Poulton, Bellet & Holt, 2015).
The list provided, contains the instruction on how to use this feature on the Windows operating system. From the list, click on ‘turn Windows features on or off’
This tool works best because it has documentation of windows and all the guidelines to use the platform.
b. Modify, Repair, or uninstall a program from a Windows 8.1 system.
Uninstalling a program.
Programs after being installed to the computer, can only be deleted by uninstalling them off from the computer. Programs can be uninstalled from the Programs and Features option on the control panel (Poulton, Bellet, & Holt, 2015). All the installed programs will be displayed in this area. To uninstall a program, select on the program you want to uninstall. Then the option will display on the top of the panel to uninstall. However, some programs can be changed or repaired while others can only be uninstalled. You can choose to uninstall the selected program, change or repair it (Poulton, Bellet, & Holt, 2015).
Windows Help and Support.
Launch the Windows Help and Support from the start menu. Type program and features then press enter. Select uninstall or change program.
This will provide the guidelines to uninstall or change a program on the Windows operating system.
c. Select and Install Updates for Windows and Windows Applications, find an installed Update, Remove an installed update.
Find an installed update
To find Windows Updates, launch the control panel from the start menu. Go to system and security then WindowsUupdate.
To view the installed updates, click on the update history on the navigation panel. Then on the opened pane, click on see the installed updates.
You can choose to remove an installed update by uninstalling from the system.
Implementing Security Configuration Rules Using the Local Group Policy Editor
Note: you are NOT implementing the DISA / DoD STIG in this section. You are implementing a set of security configuration rules that your “company” has selected from industry accepted sources.
1. Investigate the Local Group Policy Editor tool (Windows Key + R then type gpedit.msc). Pay particular attention to the menu tree in the left-hand pane (expand and review the categories of settings which can be changed using this tool).
Security settings policies are the rules that the computer user can configure on a single computer, or multiple computers, for the main purpose of protecting resources that are on a computer or network. The Security Settings extension of the Local Group Policy Editor snap-in (Gpedit.msc) allows the computer user to define security configurations as part of a Group Policy Object (GPO) (Poulton, Bellet, & Holt, 2015).
This security measure operates on the software environment where the instruction on how the computer works is based (Poulton, Bellet, & Holt, 2015).
Security settings can control:
i. User authentication to the network or computer.
ii. Whether to record a user’s actions in the Event log.
iii. The resources that the computer users are permitted to access.
iv. Membership in the group.
Logical groups
Banner group
Warning: Using Registry Editor incorrectly can cause serious, system-wide problems that may require reinstallation of Windows 2000 to correct them. Microsoft cannot guarantee that any problems resulting from the use of Registry Editor can be solved (Poulton, Bellet, & Holt, 2015).
1. Login to the domain controller machine with the administrator account. Click on Start, Click on Administrative Tools, Click on Group Policy Management. Under Domains, right click your domain and click on Create a GPO in this domain, and link it here. Create the policy of your choice.
2. Write the policy you created and click on Edit. On Group Policy Management Editor, click on Computer Configuration, expand Policies, expand Windows Settings, expand Security Settings, expand Local Policies, and click on Security Options.
3. On the right pane look for the policy Interactive Logon: Message text for users attempting to log on. This security setting specifies a text message that is displayed to users when they log on. You can paste the Logon text that is to be displayed to the users before they log in. Click on Apply and OK.
4. On the right pane look for the policy Interactive Logon: Message title for users attempting to log on. This security setting allows the title to appear in the title bar of the window that contains the Interactive logon. Type the title text and click on Apply and OK.
Notification group
It is recommended that the system display a warning message to users before allowing them to log on. It may be necessary to get help with the wording of the message from the company's legal department. The message should inform users that the system is for authorized use only, and that they could be prosecuted if they misuse the system (Poulton, Bellet, & Holt, 2015). For example,
1. Log on using an administrator account.
2. Open the Active Directory Users and Computers tool.
3. Right-click the container holding the domain controller and click Properties.
4. Click the Group Policy tab, and then click Edit to edit the Default Domain Policy.
5. In the Group Policy window, expand Computer Configuration, navigate to Windows Settings, to Security Settings, and then to Local Policies.
6. Select Security Options.
7. In the details pane, double-click Message title for users attempting to log on.
8. Check the Define this policy setting box.
9. Enter the title for the message (for example, "Warning") and click OK.
10. Double-click Message text for users attempting to log on.
11. Check the Define this policy setting box.
12. Enter the text for the message and click OK.
13. Exit the Group Policy window.
Restart a domain client and log in to the domain to see the login banner message.
Since this security setting is associated with the default domain GPO, it applies to all computers in the domain. This setting will override any local policies (defined on individual computers) that specify this security parameter, but will not override any OU policies that specify this value.
Log on group.
This security option determines whether a computer can be shut down without having to log on to Windows. When this policy is enabled, the Shut Down command is available on the Windows logon screen. When this policy is disabled, the option to shut down the computer does not appear on the Windows logon screen. In this case, users must be able to log on to the computer successfully and have the Shut down the System user right in order to perform a system shutdown. By default, this option is enabled on workstations and disabled on servers in Local Computer Policy (Poulton, Bellet, & Holt, 2015).
Disable the shutdown button on the Windows logon screen of Domain Computers as follows:
1. Log on using an administrator account.
2. Open the Active Directory Users and Computers tool.
3. Right-click the container holding the domain controller and click Properties.
4. Click the Group Policy tab, and then click Edit to edit the Default Domain Policy.
5. In the Group Policy window, expand Computer Configuration, navigate to Windows Settings, to Security Settings, and then to Local Policies.
6. Select Security Options.
7. In the details pane, double-click Allow system to be shut down without having to log on.
8. Check the Define this policy setting box, select Disabled and click OK.
9. Exit the Group Policy window.
References
Poulton, D., Bellet, R., & Holt, H. (2015). MCSA 70-687 cert guide: Configuring Microsoft Windows 8.1. Indianapolis, IN: Pearson.
Kim, D., & Solomon, M. (2011). Fundamentals of information systems security. Sudbury, MA: Jones & Bartlett Learning.
Zacker, C. (2014). Configuring Windows 8.1, exam 70-687.