80 phút
Group Policy và Security
Group Policy và Security
Group Policy Objects (GPO) nâng cao
Scope of Management
Site → Domain → OU → Child OU
GPOs apply theo thứ tự LSDOU (Local, Site, Domain, OU)
GPO Processing Order
1. Local GPO
2. Site GPOs
3. Domain GPOs
4. OU GPOs (từ trên xuống)
Conflict: GPO applied last wins
Link Order: Số nhỏ apply sau (win)
Security Filtering
- Authenticated Users (default)
- Chỉ định user/group cụ thể
- Deny Apply Group Policy
WMI Filters
Ví dụ: Apply chỉ cho Windows 10
SELECT * FROM Win32_OperatingSystem
WHERE Caption LIKE "%Windows 10%"
Ví dụ: Apply cho laptop
SELECT * FROM Win32_ComputerSystem
WHERE PCSystemType = 2
Security Policies
Password Policy
Computer Configuration → Policies → Windows Settings
→ Security Settings → Account Policies → Password Policy
- Enforce password history: 24 passwords
- Maximum password age: 60 days
- Minimum password age: 1 day
- Minimum password length: 12
- Password must meet complexity: Enabled
- Store passwords using reversible encryption: Disabled
Account Lockout Policy
- Account lockout duration: 30 minutes
- Account lockout threshold: 5 attempts
- Reset account lockout counter: 30 minutes
Fine-Grained Password Policy
# Tạo PSO cho Admins
New-ADFineGrainedPasswordPolicy `
-Name "AdminPasswordPolicy" `
-Precedence 10 `
-MinPasswordLength 16 `
-PasswordHistoryCount 24 `
-MaxPasswordAge "30.00:00:00" `
-MinPasswordAge "1.00:00:00" `
-ComplexityEnabled $true `
-LockoutThreshold 3 `
-LockoutDuration "60.00:00:00" `
-LockoutObservationWindow "60.00:00:00"
# Apply to group
Add-ADFineGrainedPasswordPolicySubject `
-Identity "AdminPasswordPolicy" `
-Subjects "IT_Admins"
Audit Policy
Enable Auditing
Computer Configuration → Policies → Windows Settings
→ Security Settings → Local Policies → Audit Policy
Audit events:
- Account logon events: Success, Failure
- Account management: Success, Failure
- Logon events: Success, Failure
- Object access: Success, Failure
- Policy change: Success, Failure
- Privilege use: Success, Failure
- System events: Success, Failure
Advanced Audit Policy
Computer Configuration → Policies → Windows Settings
→ Security Settings → Advanced Audit Policy Configuration
Categories:
- Account Logon
- Account Management
- Detailed Tracking
- DS Access
- Logon/Logoff
- Object Access
- Policy Change
- Privilege Use
- System
Audit PowerShell
# Enable module logging
Computer Configuration → Policies → Administrative Templates
→ Windows Components → Windows PowerShell
Settings:
- Turn on Module Logging: Enabled
- Turn on PowerShell Script Block Logging: Enabled
- Turn on PowerShell Transcription: Enabled
Advanced GPO Settings
Software Restriction Policies
Computer Configuration → Policies → Windows Settings
→ Security Settings → Software Restriction Policies
Rules:
- Path rules: Allow/Disallow by path
- Hash rules: By file hash
- Certificate rules
- Network zone rules
AppLocker
Computer Configuration → Policies → Windows Settings
→ Security Settings → Application Control Policies → AppLocker
Rule types:
- Executable rules
- Windows Installer rules
- Script rules
- Packaged app rules
- DLL rules
Firewall with Advanced Security
Computer Configuration → Policies → Windows Settings
→ Security Settings → Windows Firewall with Advanced Security
Inbound Rules:
- Block all by default
- Allow specific ports/services
Outbound Rules:
- Allow all by default
- Block specific
Connection Security Rules:
- IPsec
- Authentication
Security Baselines
Microsoft Security Compliance Toolkit
Download từ: https://www.microsoft.com/en-us/download/details.aspx?id=55319
Bao gồm:
- Windows Server 2022 Security Baseline
- Windows 10/11 Security Baseline
- Microsoft 365 Apps Security Baseline
- Edge Security Baseline
Import Baseline GPO
# Import GPO từ Microsoft baseline
Import-GPO `
-BackupGpoName "MSFT Windows Server 2022 - Domain Security" `
-Path "C:\Baselines\Windows Server 2022" `
-TargetName "WS2022-Domain-Security"
# Link GPO
New-GPLink -Name "WS2022-Domain-Security" `
-Target "DC=abc,DC=local"
Security Tools
LAPS (Local Administrator Password Solution)
# Cài LAPS
Import-Module LAPS
# Extend AD Schema
Update-LapsADSchema
# Grant permissions
Set-LapsADComputerSelfPermission -Identity "OU=Computers,DC=abc,DC=local"
Set-LapsADReadPasswordPermission -Identity "OU=Computers,DC=abc,DC=local" `
-AllowedPrincipals "ABC\IT_Admins"
# Configure via GPO
# Computer → Policies → Administrative Templates → LAPS
# - Enable password backup
# - Password complexity
# - Password age
# - Password length
Windows Defender ATP
Integration với Microsoft Defender for Endpoint
Central management qua Microsoft 365 Defender portal
Monitoring và Troubleshooting
gpresult
# Xem GPO applied
gpresult /R
# Report chi tiết
gpresult /H gpo-report.html
# Scope computer
gpresult /S CO01 /SCOPE COMPUTER /R
# RSOP
rsop.msc
Get-GPResultantSetOfPolicy -Computer "PC01" `
-ReportType Html -Path "C:\Reports\rsop.html"
GPO Troubleshooting
# Force update
gpupdate /force
# Xem GPO settings
Get-GPO -Name "PasswordPolicy" | Get-GPOReport `
-ReportType Html -Path "report.html"
# Backup all GPOs
Backup-GPO -All -Path "C:\GPOBackup"
# Restore GPO
Restore-GPO -Name "PasswordPolicy" -Path "C:\GPOBackup"
Event Logs
Applications and Services Logs →
Microsoft → Windows → GroupPolicy → Operational
Log level:
- Information
- Warning
- Error
Tìm errors khi apply GPO
Best Practices
GPO Design
1. Ít GPO nhất có thể
2. Tên rõ ràng, có prefix
Ví dụ: "Sec-Password-Policy"
3. Comment đầy đủ
4. Phân loại:
- Security GPOs
- Configuration GPOs
- Software GPOs
5. Test trong lab trước
6. Backup định kỳ
7. Documentation đầy đủ
Security Best Practices
1. Least Privilege Principle
2. Tiered Admin Model:
- Tier 0: Domain Controllers
- Tier 1: Servers
- Tier 2: Workstations
3. Separate admin accounts
4. PAWs (Privileged Access Workstations)
5. Regular security audit
6. Patch management
7. Backup + DR plan
8. Monitor privileged accounts
9. Enable auditing
10. Regular penetration test
Tiered Administration Model
Tier 0 (Domain Controllers):
- Domain Admins
- Enterprise Admins
- Schema Admins
- DCs, AD FS, AD CS
Tier 1 (Servers):
- Server Admins
- Application Admins
- Member servers, apps
Tier 2 (Workstations):
- Helpdesk
- Workstation Admins
- User workstations
Bài tập thực hành
Hãy triển khai Security Baseline cho doanh nghiệp!