Home > Enterprise Desktop Tips > Windows desktop security tips > Using third-party technologies with Microsoft's NAP
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WINDOWS DESKTOP SECURITY TIPS

Using third-party technologies with Microsoft's NAP


Greg Shields, Contributor
10.01.2009
Rating: --- (out of 5)


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


This is the final article in a three-part series on Microsoft's Network Access Protection.

NAP is more than just a Microsoft technology -- 87 partners are integrating their software into NAP's framework in hopes of further extending security enforcement protections to custom configurations.

Microsoft designed multiple points of extensibility into NAP's client and server enforcement architectures. This allows individual application vendors to supply and support their own mechanisms for enforcement, authentication and identity management; verification of compliance; and remediation of noncompliant clients.

Since these activities are separate in NAP's management consoles, third-party technologies can be added as an organization sees fit.

Third-party technologies for enforcement
Microsoft's options for policy enforcement require the use of Microsoft technologies. For example, Dynamic Host Configuration Protocol enforcement requires Microsoft's DHCP server, while virtual private network (VPN) enforcement requires an Internet Security and Acceleration or Routing and Remote Access server.

In this case, extensibility enables organizations with technologies such as alternate VPNs or switch port authentication infrastructures to plug directly into NAP. Organizations that need special protection for wireless networks and those that want to add pervasive access support, like Microsoft's new DirectAccess capability in Windows Server 2008 R2, can benefit.

Authentication and identity management
Advanced technologies in the enforcement mechanisms enable rich support for authentication and identity management. Users and computers can be positively verified against those allowed in the infrastructure. Permissions to access discrete services can be set at extremely granular levels based on user ID, role, location and other contextual elements.

In addition, user identities can be mapped to linked assets. Tighter links between individual users, their assets and their approved levels of connectivity are increasingly important as more mobile users connect to LAN resources.

Verification of compliance at the client layer
Security software vendors have augmented their client applications to include enforcement components.

For example, consider a typical anti-malware application that an organization has been running for a while. The organization would prefer to keep the existing infrastructure setup and simply add compliance-verification components.

Such an organization could take advantage of the NAP awareness that many enterprise-focused software companies have added to their application infrastructures.

Remediation of noncompliant clients
A NAP infrastructure that kicks out noncompliant clients is only partially useful. You also need automated systems to remediate noncompliant clients relocated to special networks.

Getting started with Microsoft's Network Access Protection

Part 1: The role of NAP in your security infrastructure

Part 2: NAP's internal and external components

Part 3: Using third-party technologies with Microsoft's NAP

In addition, you need extremely precise support to determine what to do with these noncompliant clients, since many types of clients may attempt to connect to an environment. For example, while a corporate asset can be remediated on its first connection within the LAN, a user's home computer requires a different level of security when connecting via a VPN.

Finding the right remediation system that aligns with your security requirements as well as your existing client security setup is critical for a successful NAP deployment. In general, many large organizations will require more from NAP than the native components.

Not only must you find the best add-ons for your organization, but you must also recognize that enforcement mechanisms such as NAP are necessary in today's enterprise environments.

Organizations that don't incorporate an enforcement component are merely hoping or wishing that their servers and workstations remain compliant with security mandates.

About the author
Greg Shields
Greg Shields is an independent author, instructor, Microsoft MVP and IT consultant based in Denver. He is a co-founder of Concentrated Technology LLC and has nearly 15 years of experience in IT architecture and enterprise administration. Shields specializes in Microsoft administration, systems management and monitoring, and virtualization. He is the author of several books, including Windows Server 2008: What's New/What's Changed, available from Sapien Press.


Rate this Tip
To rate tips, you must be a member of SearchEnterpriseDesktop.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Endpoint security management tools
How to get -- and keep -- user support with security
MDOP for Windows 7 available now
Microsoft's Online Desktop Manager caters to small IT shops
Monitoring user activity with network analyzers
Understanding Microsoft's NAP's internal and external components
Microsoft's NAP can ensure security compliance
Top 5 registry keys for Windows XP
Microsoft releases WSUS 3 SP2 with Win 7, R2 support
Using System Center Essentials as a patch management tool
Troubleshooting Microsoft WSUS connectivity issues

Windows desktop security tips
Improvements to offline file synchronization in Windows 7
How to get -- and keep -- user support with security
Structuring patch management in seven steps
Underlying causes of inconsistent patch management
Monitoring user activity with network analyzers
Microsoft's Patch Tuesday brings a bumper crop of security fixes
Understanding Microsoft's NAP's internal and external components
Microsoft's NAP can ensure security compliance
Top 5 registry keys for Windows XP
Secure Windows XP before a Windows 7 upgrade

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
system tray  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts