Require updates

Require updates

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Require updates Dumb Luck 09-01-2006
---> Re: Require updates Roger Abell [MV...09-01-2006
  `--> Re: Require updates karl levinson, ...09-02-2006
Posted by Dumb Luck on September 1, 2006, 1:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
What can I do to prevent new computers, or laptops that haven't
connected in a while, from joining the domain until they have all
required patches and updates? Thanks for any suggestions.


Posted by Roger Abell [MVP] on September 1, 2006, 7:24 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
NAP = network access protection
There is an initial release from Microsoft with W2k3 R2, and
published info on the evolution of this with future release.
Third parties, specifically the main networking players, would be
glad to also sell you the needed.

Basically, clients are shunted onto a limited vlan until they have
submitted to and passed scripted examination (failing which they
can get to the needed installables).

--
Roger Abell
Microsoft MVP (Windows Server : Security)
MCDBA, MCSE W2k3+W2k+Nt4
> What can I do to prevent new computers, or laptops that haven't
> connected in a while, from joining the domain until they have all
> required patches and updates? Thanks for any suggestions.
>



Posted by karl levinson, mvp on September 2, 2006, 10:24 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> NAP = network access protection
> There is an initial release from Microsoft with W2k3 R2, and
> published info on the evolution of this with future release.
> Third parties, specifically the main networking players, would be
> glad to also sell you the needed.
>
> Basically, clients are shunted onto a limited vlan until they have
> submitted to and passed scripted examination (failing which they
> can get to the needed installables).

Unless I'm mistaken, NAP only works for DHCP clients that are Windows XP and
newer? and the fullly functional release won't be until the OS after Vista
is released some years from now. I would have to recommend you look into
similar NAC Network Admission Control offerings from Cisco, Enterasys,
Juniper or others. I believe Cisco requires you to have all Cisco 802.1x
switches, whereas the Enterasys solution works with switches from multiple
vendors. In most implementations, 802.1x switches are used with a central
RADIUS server and third party antivirus and patch management servers that
are accessible from an isolated VLAN. I don't know whether any of these
solutions fit into your budget or not.

--
kind regards,
Karl Levinson, CISSP, CCSA, MCSE [MS MVP]
--------------------------------
Microsoft Security FAQ:
http://securityadmin.info



Similar ThreadsPosted
Require Info on EAP extension development for windows mobile February 21, 2007, 7:18 am
Running 3rd party apps that require admin privs on Vista January 24, 2008, 2:33 pm
New to CA server service require reconfigure CA server- Please hel July 17, 2006, 12:00 am
Re: updates August 30, 2005, 3:06 pm
updates...do they or don't they? November 19, 2005, 3:22 pm
Re: Security Updates June 23, 2005, 9:57 am
security updates? July 1, 2005, 5:13 am
NORTON UPDATES May 12, 2006, 6:24 pm
Security Updates July 9, 2006, 4:58 am
Automatic XP Updates August 27, 2006, 6:21 pm

The site map in XML format XML site map

Contact Us | Privacy Policy