Question

In: Computer Science

You are the senior system administrator in your company and are known for your Active Directory...

You are the senior system administrator in your company and are known for your Active Directory expertise. Your specialty is Group Policy Objects (GPO) and tracking changes. Your boss tells everyone about a tool developed by Microsoft called “Policy Analyzer” for tracking changes and troubleshooting GPO. He would like you to conduct a “lunch and learn” about Policy Analyzer for your Windows Administration Team. You realize that the product’s name has been changed to “Microsoft Security Configuration Toolkit”. Diplomatically conduct the lunch and learn and discuss the history of the tool, the name change, the features of the product and the benefits to your Windows Administration team in managing GPO.

A minimum of two references is required one of which can be your textbook.

<Insert your 1-2 page Lunch and Learn document with references cited in APA format>

Textbook info

Windows Server 2016 Administration Fundamentals

ISBN: 9781788626569

please provide a full new answer

Solutions

Expert Solution

Lunch and learn on “Microsoft Security Configuration Toolkit”

(Below discussed are the main points to be discussed in the lunch and learn event)

History of the tool policy analyser:

· The policy analyser was published on Technet on January 22,2016

· It was a tool used for analysing and comparing the GPO

· GPO is a feature provided by Microsoft

· GPO is a group of settings which say about how the system will behave and what the system will look for specific group of users

· Its mainly associated with some sites or some active directory containers etc.

· The tool allowed the view of all GPOs as a single unit

· Its mainly used to check whether some particular settings is duplicated among any GPOS

· Or if there are some conflicting value set in any GPOs

· All the observations and findings of this tool was able to be converted to a Microsoft spreadsheet file.

· After the policy analyser there came a new launch on 2010 which was SCM or security compliance manager

· This was a combination of many new functionalities like:

1. There was security recommendations based on GPO

2. Had shown and explained the threats and counter measures for each settings

3. Feature for create and edit the baselines and also to compare them and many more….

· But the disadvantage of this was, the SCM was very complex program

· It proved inflexible due to many reasons

· And also was unwelcomed by the users eventhough it had great new functionalities.

· This paved the way for Microsoft security configuration tool kit

About the name change:

· First the tool was called POLICY ANALYSER

· Then a new tool with same functions and added new functions which was an updated version of policy analyser came, SCM - security compliance manager

· Then the most updated Microsoft security configuration tool kit came into action

Feature of Microsoft security configuration tool kit:

· It was a combination of two policies

· They were the policy analyser and LGPO

· It also had some set of baselines enabling its use in different Windows versions.

· The policy analyser had the same features it had before.

· And adding to that the new concept of LGPO was introduced.

· LGPO ,Local Group Policy Object Utility is a transfer tool

· It helps in direct transfer of the Group policies between host registry and the backup files of a GPO

· Host registry is responsible for setting the domain policies and managing the registration etc of the host.

· All the LGPO transfers were done bypassing the domain controller

· A domain controller is a server mainly used for data organisation and providing security, which deals with the activities like, authentication request processing and verification of user on the given computer network.

· LGPO helps the administrators a lot, because its an easy way of verification of their group policy settings by the administrators.

· Security baselines were available as downloadable spreadsheet or as GPO backups.

· It’s a collection of Microsoft recommended configuration settings, it also explains their security impact.

· It was a kind of guidance provided by Microsoft for some selected group policy settings

Benefits of the tool in managing the GPO:

· It is having very less complexity

· Very easy to test and do the trouble shooting

· Allows easy configuration of local computers by easily helping it to apply the settings into some secure template into the local policy of the system

· The policy analyser helps in easy comparison between the GPOs for any differences or for some kind of issues between them.

· The baseline of the system is made available so that it can be referred in the coming time for checking and finding any kind of change occurred

· Using the LGPO tool ,settings could be loaded from registry policy files, LGPO text files and could be easily applied

· It was possible to make updations or edits to existing group policy backups

· LGPO was also used to test the updated backups by loading it into some host, so the tesing was made easy.

· After the testing completed, and if it succeeds,then the revised backup could be used as new group policy also.

REFERENCES:

https://docs.microsoft.com/en-us/windows/security/threat-protection/security-compliance-toolkit-10

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/new-tool-policy-analyzer/ba-p/701049

https://www.scip.ch/en/?labs.20200305

APA format guidelines:(the above given points should be presented in the given format)

1.use Times Roman format for the texts

2.use a text size of 12pt

3.there should be page margin provided(1 inches should be the margin width)

4.double spacing should be provided between the rows of lines, that is from the normal spacing between rows of words give tha double of that in APA format.

5.there should be a title or running head for every pages

6.every new paragraph should be intended with a spacing of 1/2 inches between the two paragraphs.


Related Solutions

What are the permissions for your home directory set by your system administrator? What command did...
What are the permissions for your home directory set by your system administrator? What command did you use to answer the question? Show your session.
You have an Active Directory forest named csmtech.local and two Active Directory domains in the forest...
You have an Active Directory forest named csmtech.local and two Active Directory domains in the forest named csmpub.local and csmsales.local. You want the DNS servers in each domain to be able to handle DNS queries from client computers for any of the other domains. DNS servers in the csmtech.local and csmpub.local domains should be authoritative for their own domains and the csmsales.local domain. However, DNS servers in csmsales. local should be authoritative only for csmsales.local. How should you set up...
Organizational Unit diagram Active Directory: Design an OU Structure for your company. You should have at...
Organizational Unit diagram Active Directory: Design an OU Structure for your company. You should have at least 4 separate IT Sub-groups that will need to be delegated access to their own OU sub-structures. Plan for separating Users, Computers, Groups, and resources like Printers. Also plan to have a separated Privileged IT Accounts section. You also have a Helpdesk Group. Plan for appropriate rights for them. They will need to reset User Passwords. A diagram of the OU hierarchy A list...
You are the Senior Systems Administrator for a community based charity. Your charity is involved in...
You are the Senior Systems Administrator for a community based charity. Your charity is involved in locating and providing accommodation, mental health services, training and support services to disadvantaged people in the community. Your charity currently runs a small data centre that has some 50 x86 64 bit servers running mainly Windows Server 2008 R2 for desktop services, database and file services. It also has about 10 Red Hat Enterprise Linux 5 servers for public facing Web pages, services and...
The Active Directory database can be moved to a new location if you decide that there...
The Active Directory database can be moved to a new location if you decide that there is a need to relocate it due to space limitations. How do you accomplish this? When you back up Active Directory, what must be included? Explain the basic functions of a directory service and how Active Directory Domain Services fulfills them and describe how DNS names are formed out of domains and a hostname. # Note: No plagiarism, please
Active Directory Domain Services Installation Wizard
Active Directory Domain Services Installation Wizard
ou are the Senior Systems Administrator for a community based charity. Your charity is involved in...
ou are the Senior Systems Administrator for a community based charity. Your charity is involved in locating and providing accommodation, mental health services, training and support services to disadvantaged people in the community. Your charity currently runs a small datacentre that has some 50 x86 64 bit servers running mainly Windows Server 2008 R2 for desktop services, database and file services. It also has about 10 Red Hat Enterprise Linux 5 servers for public facing Web pages, services and support....
Windows administration answer this question for computer network To provide support to Active Directory, suggest your...
Windows administration answer this question for computer network To provide support to Active Directory, suggest your DNS strategy: Active Directory is dependent on DNS as a domain controller location mechanism and uses DNS domain naming conventions in the architecture of Active Directory domains. There are three components in the dependency of Active Directory on DNS: Domain controller locator (Locator) Active Directory domain names in DNS ● Active Directory DNS objects Internal DNS External DNS 1) What is the advantage of...
As an administrator of a company, you are concerned with the absenteeism among​ your employees ....
As an administrator of a company, you are concerned with the absenteeism among​ your employees . The issue has been raised by employees, who feel they often have to perform work normally done by their assistants. To get the​ facts, absenteeism data were gathered for the last three​ weeks, which is considered a representative period for future conditions. After taking random samples of 64 personnel files each​ day, the following data were​ produced:                                                                                                                                         Day Assistants Absent Day Assistants  Absent Day...
You are a member of the senior executive group at your company. The company has a...
You are a member of the senior executive group at your company. The company has a reputation of compensating its executives at a very high level. In fact your own compensation appears to be at least 50% above that of your peers in like companies. Due to pressure from the founder who has a controlling interest in the company and now lives in another state the company is considering developing an incentive system for all employees who other than the...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT