Group Policy và Security

80 phút

Group Policy và Security

Group Policy và Security

Group Policy Objects (GPO) nâng cao

Scope of Management

Site → Domain → OU → Child OU
GPOs apply theo thứ tự LSDOU (Local, Site, Domain, OU)

GPO Processing Order

1. Local GPO
2. Site GPOs
3. Domain GPOs
4. OU GPOs (từ trên xuống)

Conflict: GPO applied last wins
Link Order: Số nhỏ apply sau (win)

Security Filtering

- Authenticated Users (default)
- Chỉ định user/group cụ thể
- Deny Apply Group Policy

WMI Filters

Ví dụ: Apply chỉ cho Windows 10
SELECT * FROM Win32_OperatingSystem 
WHERE Caption LIKE "%Windows 10%"

Ví dụ: Apply cho laptop
SELECT * FROM Win32_ComputerSystem 
WHERE PCSystemType = 2

Security Policies

Password Policy

Computer Configuration → Policies → Windows Settings 
→ Security Settings → Account Policies → Password Policy

- Enforce password history: 24 passwords
- Maximum password age: 60 days
- Minimum password age: 1 day
- Minimum password length: 12
- Password must meet complexity: Enabled
- Store passwords using reversible encryption: Disabled

Account Lockout Policy

- Account lockout duration: 30 minutes
- Account lockout threshold: 5 attempts
- Reset account lockout counter: 30 minutes

Fine-Grained Password Policy

# Tạo PSO cho Admins
New-ADFineGrainedPasswordPolicy `
    -Name "AdminPasswordPolicy" `
    -Precedence 10 `
    -MinPasswordLength 16 `
    -PasswordHistoryCount 24 `
    -MaxPasswordAge "30.00:00:00" `
    -MinPasswordAge "1.00:00:00" `
    -ComplexityEnabled $true `
    -LockoutThreshold 3 `
    -LockoutDuration "60.00:00:00" `
    -LockoutObservationWindow "60.00:00:00"

# Apply to group
Add-ADFineGrainedPasswordPolicySubject `
    -Identity "AdminPasswordPolicy" `
    -Subjects "IT_Admins"

Audit Policy

Enable Auditing

Computer Configuration → Policies → Windows Settings 
→ Security Settings → Local Policies → Audit Policy

Audit events:
- Account logon events: Success, Failure
- Account management: Success, Failure
- Logon events: Success, Failure
- Object access: Success, Failure
- Policy change: Success, Failure
- Privilege use: Success, Failure
- System events: Success, Failure

Advanced Audit Policy

Computer Configuration → Policies → Windows Settings 
→ Security Settings → Advanced Audit Policy Configuration

Categories:
- Account Logon
- Account Management
- Detailed Tracking
- DS Access
- Logon/Logoff
- Object Access
- Policy Change
- Privilege Use
- System

Audit PowerShell

# Enable module logging
Computer Configuration → Policies → Administrative Templates 
→ Windows Components → Windows PowerShell

Settings:
- Turn on Module Logging: Enabled
- Turn on PowerShell Script Block Logging: Enabled
- Turn on PowerShell Transcription: Enabled

Advanced GPO Settings

Software Restriction Policies

Computer Configuration → Policies → Windows Settings 
→ Security Settings → Software Restriction Policies

Rules:
- Path rules: Allow/Disallow by path
- Hash rules: By file hash
- Certificate rules
- Network zone rules

AppLocker

Computer Configuration → Policies → Windows Settings 
→ Security Settings → Application Control Policies → AppLocker

Rule types:
- Executable rules
- Windows Installer rules
- Script rules
- Packaged app rules
- DLL rules

Firewall with Advanced Security

Computer Configuration → Policies → Windows Settings 
→ Security Settings → Windows Firewall with Advanced Security

Inbound Rules:
- Block all by default
- Allow specific ports/services

Outbound Rules:
- Allow all by default
- Block specific

Connection Security Rules:
- IPsec
- Authentication

Security Baselines

Microsoft Security Compliance Toolkit

Download từ: https://www.microsoft.com/en-us/download/details.aspx?id=55319

Bao gồm:
- Windows Server 2022 Security Baseline
- Windows 10/11 Security Baseline
- Microsoft 365 Apps Security Baseline
- Edge Security Baseline

Import Baseline GPO

# Import GPO từ Microsoft baseline
Import-GPO `
    -BackupGpoName "MSFT Windows Server 2022 - Domain Security" `
    -Path "C:\Baselines\Windows Server 2022" `
    -TargetName "WS2022-Domain-Security"

# Link GPO
New-GPLink -Name "WS2022-Domain-Security" `
    -Target "DC=abc,DC=local"

Security Tools

LAPS (Local Administrator Password Solution)

# Cài LAPS
Import-Module LAPS

# Extend AD Schema
Update-LapsADSchema

# Grant permissions
Set-LapsADComputerSelfPermission -Identity "OU=Computers,DC=abc,DC=local"
Set-LapsADReadPasswordPermission -Identity "OU=Computers,DC=abc,DC=local" `
    -AllowedPrincipals "ABC\IT_Admins"

# Configure via GPO
# Computer → Policies → Administrative Templates → LAPS
# - Enable password backup
# - Password complexity
# - Password age
# - Password length

Windows Defender ATP

Integration với Microsoft Defender for Endpoint
Central management qua Microsoft 365 Defender portal

Monitoring và Troubleshooting

gpresult

# Xem GPO applied
gpresult /R

# Report chi tiết
gpresult /H gpo-report.html

# Scope computer
gpresult /S CO01 /SCOPE COMPUTER /R

# RSOP
rsop.msc
Get-GPResultantSetOfPolicy -Computer "PC01" `
    -ReportType Html -Path "C:\Reports\rsop.html"

GPO Troubleshooting

# Force update
gpupdate /force

# Xem GPO settings
Get-GPO -Name "PasswordPolicy" | Get-GPOReport `
    -ReportType Html -Path "report.html"

# Backup all GPOs
Backup-GPO -All -Path "C:\GPOBackup"

# Restore GPO
Restore-GPO -Name "PasswordPolicy" -Path "C:\GPOBackup"

Event Logs

Applications and Services Logs → 
Microsoft → Windows → GroupPolicy → Operational

Log level:
- Information
- Warning
- Error

Tìm errors khi apply GPO

Best Practices

GPO Design

1. Ít GPO nhất có thể
2. Tên rõ ràng, có prefix
   Ví dụ: "Sec-Password-Policy"
3. Comment đầy đủ
4. Phân loại:
   - Security GPOs
   - Configuration GPOs
   - Software GPOs
5. Test trong lab trước
6. Backup định kỳ
7. Documentation đầy đủ

Security Best Practices

1. Least Privilege Principle
2. Tiered Admin Model:
   - Tier 0: Domain Controllers
   - Tier 1: Servers
   - Tier 2: Workstations
3. Separate admin accounts
4. PAWs (Privileged Access Workstations)
5. Regular security audit
6. Patch management
7. Backup + DR plan
8. Monitor privileged accounts
9. Enable auditing
10. Regular penetration test

Tiered Administration Model

Tier 0 (Domain Controllers):
- Domain Admins
- Enterprise Admins
- Schema Admins
- DCs, AD FS, AD CS

Tier 1 (Servers):
- Server Admins
- Application Admins
- Member servers, apps

Tier 2 (Workstations):
- Helpdesk
- Workstation Admins
- User workstations

Bài tập thực hành

Hãy triển khai Security Baseline cho doanh nghiệp!

Bài tập 1