Windows security information for IT Pros

This topic contains detailed information about security products and features for the IT professional to design, deploy, and maintain Windows Vista®.

Threats and Vulnerabilities Mitigation

Features and technologies that provide layered defenses against malicious software threats and intrusions through a strategy of prevention, isolation, and recovery.

Communication with the Internet

This white paper provides information about the communication that flows between features in Windows Vista and sites on the Internet, and describes steps to take to limit, control, or prevent that communication in an organization with many users.

Malicious Software Removal Tool

The Microsoft Windows Malicious Software Removal Tool checks computers running Windows® XP, Windows Vista, Windows® 2000, and Windows Server® 2003 for infections by specific, prevalent malicious software and helps remove any infection found.

Network Access Protection

The Network Access Protection (NAP) platform is a computer health policy enforcement technology that provides system health validated access to private networks. It provides an integrated way of detecting the health state of a network client that is attempting to connect to or communicate on a network and isolating that network client until the health requirements have been met.

User Account Control

User Account Control (UAC) reduces the exposure and attack surface of the operating system by requiring that all users run in standard user mode. This limitation minimizes the ability for users to make changes that could destabilize their computers or inadvertently expose the network to viruses through undetected malicious software that has infected their computer.

Windows Defender

Windows Defender is a free program for small businesses and home use that helps protect computers against pop-ups, slow performance, and security threats caused by spyware and other unwanted software.

Windows Firewall with Advanced Security

This roadmap contains links to getting started content, diagnostic and troubleshooting tools, and introduction to Server and Domain Isolation.

Windows Server Update Services

The Windows Server 2003 TechCenter contains information about administering Windows Server Update Services (WSUS) for Windows Vista.

Secure Configuration Assessment and Management

Tools and services of interest available for Windows Vista to administer security throughout a layered defense and manage ongoing threats.

Group Policy

Microsoft Baseline Security Analyzer

Security Policies

Software Restriction Policies

WMI Scripting for Security

Group Policy

The Windows Server 2003 TechCenter contains information pertinent to administering Group Policy for Windows Vista.

Microsoft Baseline Security Analyzer

Microsoft Baseline Security Analyzer (MBSA) is a tool designed for the IT professional that helps small- and medium-sized businesses determine their security state in accordance with Microsoft security recommendations and offers specific remediation guidance. MBSA detects common security misconfigurations and missing security updates on your computer systems.

Security Policies

Seventeen new security settings have been created for Windows Vista and are described in this topic. For security policy settings in Windows Server 2003, see Security Policy Settings on the TechCenter Web site.

Software Restriction Policies

With software restriction policies, administrators can help protect their computing environment from untrusted software by identifying and specifying which software is allowed to run. Two improvements have been made to software restriction policies for Windows Vista.

WMI Scripting for Security

WMI contains many new features and additional help in Windows Vista, including User Account Control scripting information, IPv6 and IPv4 support, security auditing of WMI namespaces, and new provider hosting models.

For a listing and links to the new security features in Windows Vista, see What's New in WMI.

Identity and Access Control

Features and technologies that provide a central way of managing credentials and technologies to allow only legitimate users access to devices, applications, and data.

BitLocker Drive Encryption

Security Identifiers (SIDs)

Trusted Platform Module

Windows Rights Management

BitLocker Drive Encryption

Drive encryption protects data by preventing unauthorized users from breaking Windows file and system protection on lost or stolen computers. This protection is achieved by encrypting the entire Windows volume. With BitLocker all user and system files are encrypted including the swap and hibernation files.

Security Identifiers (SIDs)

Security identifiers (SIDs) are numeric values that identify a user or group. For each access control entry (ACE), there is a SID that identifies the user or group for whom access is allowed, denied, or audited. OwnerRights is the new SID for Windows Vista.

For information about other well-known SIDs, see How Security Identifiers Work.

Trusted Platform Module

Trusted Platform Module (TPM) Services is a new feature set in Windows Vista and Windows Server® 2008 that is used to administer the TPM security hardware in a computer.

Windows Rights Management

Microsoft Windows Rights Management Services for Windows Server 2003 is a security technology that works with applications to help safeguard digital content for organizations that need to protect sensitive Web content, documents, and e-mail.

Resources for Guidance

Windows Vista Security Guidance

The Windows Vista Security Guide provides instructions and recommendations to help strengthen the security of desktop and laptop computers running Windows Vista in a domain with the Active Directory directory service.

The guide includes tools, step-by-step procedures, recommendations, and processes that significantly streamline the deployment process. It also provides a reproducible method that you can use to apply the guidance to both test and production environments.

Stay updated on the latest security developments by participating in the Windows Vista Security blog on MSDN.

Windows Server 2003 Security Guidance

The Windows Server 2003 Security Guide provides specific recommendations about how to harden computers that run Windows Server 2003 with Service Pack 1 (SP1) in enterprise environments.

The Threats and Countermeasures guide is a reference to all security settings that provide countermeasures for specific threats against current versions of the Windows operating systems.

MSDN Security Resources for Windows Vista

Understand the impact that the security changes in Windows Vista may have on existing solutions and the opportunities that exist to build a new generation of secure solutions for Windows.

Was this helpful?
Thank you.
Do you want to add anything else?
Thank you. Your feedback helps us to continually improve our content.
1200 400 How can we make this more helpful for you? Submit Skip this Do you want to add anything else? Submit No thanks