19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS10.0200 Selective Authentication Trust Option [Windows Server 2003 DC required]<br />

STIG ID \ V-Key DS10.0200 \ V0008540<br />

Severity Cat II<br />

Short Name Selective Authentication Trust Option<br />

IA Controls ECAN-1, ECCD-1, ECCD-2<br />

MAC /Conf 1-CS, 2-CS, 3-CSP<br />

References AD STIG 2.3.3.2<br />

Long Name: An outgoing forest trust is configured without Selective Authentication.<br />

Checks:<br />

Note: This check is performed only on a domain with domain controller(s) running<br />

Windows Server 2003. For domains with only Windows 2000 Server domain<br />

controllers, this check will be Not Applicable.<br />

• Start the Active Directory Domains and Trusts console (“Start”, “Run…”,<br />

“domain.msc”).<br />

• Select the left pane item that matches the name of the domain being reviewed.<br />

- Right-click the domain name and select the Properties item.<br />

- On the domain object Properties window, select the Trusts tab.<br />

- For *each* outgoing forest trust:<br />

-- Right-click the trust item and select the Properties item<br />

-- On the trust Properties window, select the Authentication tab.<br />

-- Determine if the Selective Authentication option is selected.<br />

• If the Selective Authentication option is not selected on every outgoing forest<br />

trust, then this is a Finding.<br />

UNCLASSIFIED<br />

5-20

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!