Windows 7 refresh is opportune time to revisit desktop control policies

by Mary Rose 8. December 2010 08:54

Perspective:
With the Windows XP sunset date fast approaching, plans for Windows 7 migrations are in full swing. This has prompted most organizations to re-assess their approach to PC lockdown. Our survey indicates a 456% jump in demand to implement privilege management software for companies planning to migrate to Windows 7 in the first half of 2011. The data further shows that 63% of survey respondents deem it critical to manage administrative privileges for end users to ensure security and reduce vulnerability.

A smart approach. A privilege management system balances the rigidity of locking down end points with the needs of user customization. It provides security and operations professionals with a method for securing the end-point by elevating privileges at the application level, or for desktop functions, rather than providing total administrative privileges. Systems are less at risk without sacrificing user productivity or increasing support call volume, thereby offering a cost effective approach to providing secure and productive desktop computing environments.

Access the newsletter and resources here.

Benefits of Lock Down on Windows 7 Desktops

by Mary Rose 11. November 2010 09:27

Many organizations look at the migration to Windows 7 as an opportune time to re-evaluate polices associated with granting local administrator rights to users on Windows system.  There are a number of advantages when end users do not have local administrative rights on their Windows desktops.  These include:

-         Less chance for malware to successfully attack the system.   When the end user doesn’t have local administrator rights, the malware that tries to exploit vulnerabilities in software such as media players, mail clients, and internet browsers is much less likely to succeed.   A locked down desktop doesn’t eliminate the need for firewall, AV, and other security software, however it certainly does provide another layer of defense against malware.

-         Reduce chance for the end user to make unauthorized changes to the system.   When users are not able to make unauthorized changes to their system there is less chance for something to break that will lead to a support call from the user.   The more changes that are made to a system the more chance that there will be system or application errors introduced.  Locking down the desktop results in a more stable and predictable computing environment for the end users.

-         Better control on which applications are installed and used on the system.   When end users do not have local administrator rights there are many applications that they can no longer install.   This helps organizations better ensure compliance with software license counts.  Controlling which applications are installed and run on the desktop also limits the chances for application incompatibility issues.

-         Fewer support calls to the IT helpdesk.   When end users are running in an environment that is more stable from a perspective of system changes and applications that are installed, there are problems that the end user encounters.  This results in fewer calls to the IT helpdesk.   

 

Privilege Management allows IT professionals to reach these objectives, without sacrificing user productivity or increasing support call volume, by providing granular, multi-level user permissions control.  Ideally, endpoints can be supported regardless of worker location and the Privilege Management software should not require laptops or desktops to be part of the Active Directory domain or to be directly connected to the corporate network in order to activate policies.

As you migrate to Windows 7, be prepared!  Get a step ahead on managing and controling administrative privileges by incorporating Privilege Management software as part of the standard operating system image. This way you avoid having to separately deploy the agent after provisioning a new desktop or performing a migration. 

 

eWeek Product Review on Privilege Management

by Mary Rose 22. October 2010 14:38

Managing user privileges is one of the first steps in securing desktops from unauthorized use. However, privilege management can be a complex and difficult process. Viewfinity removes much of that complexity and should be useful for regulatory compliance.
by Frank Ohlhorst

In the past, administrators looking to lock down PCs and servers had to rely on complex, difficult-to-audit schemes that used policies driven by a directory service, such as Microsoft's Active Directory. That approach involved the creation of granular policies using native operating system tools that proved tedious at best, unenforceable at worst.

Viewfinity in the lab

I found that Viewfinity offers an easy-to-use, Web-based management console, which is laid out in dashboard fashion. Here, it was pretty easy to determine what to do. For example, if I wanted to control administrative privileges for a group of PCs or users, I could simply select from the "Policies" menu and then select "Create policy," which would offer me some choices, such as "Elevate privileges," "Application policy" or "Computer policy." With "Elevate privileges" I was presented with choices from which to create rules for the privilege set, such as "Run application with administrative privileges" or "Permit ActiveX control installation," and so on.

The rule selection can get very granular, allowing administrators to fine-tune access and control policies. Administrators also have the option of creating policies based upon specific applications or specific computers. Application policies that control privileges can be very useful. Take for example a situation that requires an application to have access to certain low-level OS functions. Let's say it is an application that uses an ActiveX control—normally, you may want to lock down access to that control to prevent a breach. With Viewfinity, you can grant temporary privileges to the application, allowing access to the normally locked-down ActiveX control, so the application can function properly, while the level of security remains high.

That granularity fits well with the preferred security concept of locking everything down and only allowing access to what is required. Viewfinity offers a plethora of policy controls that can be combined, grouped and assigned in multiple fashions. That level of flexibility allows administrators to create complex policies that span several administrative privileges on a PC. That bodes well for those trying to meet regulatory compliance requirements, such as HIPAA (Health Insurance Portability and Accountability Act), FDCC, PCI or the Sarbanes-Oxley Act, which encompass access controls and the control of sensitive information.

... [read the full review]

Viewfinity also offers comprehensive auditing reporting, which lets administrators create full audit reports identifying who has what privileges. Auditing goes one step further to record activity, access attempts and dependencies required by applications and processes.

Read the full review:  http://www.eweek.com/c/a/Security/Viewfinity-Takes-the-Pain-out-of-Privilege-Management-720233/

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Tags:

Privilege Management | Viewfinity

Viewfinity and PrepFire Partner to Manage and Control Least Privilege Desktops

by Mary Rose 27. September 2010 13:33

Viewfinity and PrepFire Partner to offer Privilege Management for Locked Down PCs

Michael Kozeliski, President and CEO of PrepFire, a Service Disabled Veteran Owned Small Business (SDVOSB), has been providing technology solutions to government and commercial organizations for years and has built a reputation for understanding that a solution is more than just a set of technical tasks.  Michael recognized the need for a Privilege Management product to help his government and commercial organizations successfully implement compliance policies, such as the FDCC mandate.  By partnering with Viewfinity, PrepFire Solutions (www.prepfire.com) is able to offer its customers Viewfinity Privilege Management and provide services for the solution suite. For organizations who lock down their desktops, or who are planning to move to a locked down desktop environment, the only efficient method for managing your PCs is to work with a privilege management product that provides role-based account access control for desktops, laptops and servers.

 

Read the full press release announcing this partnership.

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Tags: , , , ,

Privilege Management | Viewfinity

Migrating to Windows 7 and Thinking About Locking Down Your Desktops?

by Mary Rose 17. August 2010 15:13

Most IT professionals are looking to take advantage of the Windows 7 desktop refresh as an opportunity to move to a least privileges environment to secure and gain better control of its PCs. With this change, however, legacy applications and routine Windows desktops tasks that require administrative rights will need to be considered. Rather than locking down 90% of desktops and leaving the remaining 10% unprotected because these end users need administrative rights to perform their job, IT professionals can use Viewfinity Privilege Management to elevate privileges as needed.

Viewfinity offers enhanced flexibility and control for managing administrator rights for locked down computers. You have the ability to control who and what applications should get administrative rights to run:

  • Applications requiring administrative rights to execute
  • Active X installations
  • Windows Administrative functions (updating the system clock, disk defragmentation, etc.)
  • Application Blocking/Whitelisting 
  • Click here for more details: http://www.viewfinity.com/Products/PrivilegeManagement/Win7-Refresh.aspx

    Currently rated 1.0 by 1 people

    • Currently 1/5 Stars.
    • 1
    • 2
    • 3
    • 4
    • 5

    Tags: , ,

    Compliance | Privilege Management | Windows 7

    Powered by BlogEngine.NET 1.4.5.0
    Theme by Mads Kristensen

    Calendar

    <<  May 2013  >>
    MoTuWeThFrSaSu
    293012345
    6789101112
    13141516171819
    20212223242526
    272829303112
    3456789

    View posts in large calendar

    About Viewfinity

    Viewfinity provides privilege management and application control for desktops, laptops and servers, empowering enterprises to meet compliance mandates, reduce security risks, and lower IT costs. The Viewfinity solution allows enterprises to control end user and privileged user rights for applications and systems which require elevated permissions. Viewfinity's granular-level control enables companies to establish and enforce consistent policies for least privilege Windows-based environments based on segregation of duties. For more information, visit www.viewfinity.com.

    Follow us on Twitter: viewfinity
    Find us on LinkedIn: www.linkedin.com/companies/viewfinity
    Become a fan on Facebook: www.viewfinity.com/facebook