7
Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint [email protected] | www.sevecek.com Passwords everywhere aka why use smart cards instead

Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint…

Embed Size (px)

DESCRIPTION

Separate administrators (basic physical security principle) PC ForestA DomainB DC SRV ForestA DomainA DC1 SRV NTB ForestA DomainA DC2

Citation preview

Page 1: Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint…

Ing. Ondřej ŠevečekMCSM:Directory | MVP:Enterprise Security |Certified Ethical Hacker | MCSE:[email protected] | www.sevecek.com

Passwords everywhere aka why use smart cards instead

Page 2: Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint…

Agenda

Why are workstations doomed Why not type strong accounts' passwords on insecure

computers Why use separate administrative accounts and thus limit

attack surface Why use smart cards instead of passwords wherever

possible

Page 3: Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint…

Separate administrators (basic physical security principle)

PCPC

PC

ForestADomainB

DC

SRV

ForestADomainA

DC1

SRVSRV

SRVSRV

SRV

NTBNTB

NTB

ForestADomainA

DC2

Page 4: Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint…

Separate administrators (better physical security principle)

PCPCPCopen-space

ForestADomainB

DC

ForestADomainA

DC1

SRVSRV

SRVin

datacenter

NTBNTBNTB

no BitLocker

ForestADomainA

DC2

PCPCPCin-office

SRVin

branche1

SRVin

branche2

NTBNTBNTB

with BitLocker

Page 5: Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint…

NTBNTBNTB

no BitLocker

NTBNTBNTB

with BitLocker

Separate administrators (server role principle)

PCPCPCopen-space

ForestADomainB

DC

ForestADomainA

DC1

SRVSRV

FS

ForestADomainA

DC2

PCPCPCin-office

SRVSRV

SQLSRV

SRVWeb

SRVSRV

SharePoint SRV

SRVExchange

SRVSRV

RDP

SRVSRVRemote Access

Page 6: Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint…

SymantecBackup

SQL

SharePointFarm

Intranet

SharePointFarm

Intranet

Separate administrators (application principle)

ForestADomainB

DC

ForestADomainA

DC1

ForestADomainA

DC2

DPMBackup

SQL

SharePointFarm

Intranet

SRVSRVExchange

SQL

SharePointFarm

Intranet

SharePointFarm

Intranet

DPMBackup

SQL

SharePointFarm

Extranet

RDPfarm

AD FS

NPSRADIUS

RDP Gateway

SRVSRV

FS

Page 7: Ing. Ondřej Ševeček MCSM:Directory | MVP:Enterprise Security | Certified Ethical Hacker | MCSE:SharePoint…

Kurzy Počítačové školy Gopas na www.gopas.cz

GOC169 - Auditing ISO/IEC 2700xGOC170 - AD Monitoring with SCOM and ACSGOC171 - Active Directory TroubleshootingGOC172 - Kerberos TroubleshootingGOC173 - Enterprise PKIGOC174 - SharePoint Architecture and TroubleshootingGOC175 - Advanced Security

Získejte tričko TechEd 2014za vyplněný hodnotící dotazník.

Počítačová škola Gopas – Vaše IT škola života