Home > Designing an access control strategy for the Registry
Book Excerpt:
EMAIL THIS LICENSING & REPRINTS

Designing an access control strategy for the Registry

31 Oct 2004 | Sams Publishing

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Designing Security for a Microsoft Windows Server 2003 Network The following excerpt is from Chapter 6 of the MCSE Exam Cram 2 book "Designing security for a Microsoft Windows Server 2003 network" written by Ed Tittel, courtesy of Sams Publishing. Click to purchase, check out the complete book excerpt series or go straight to the practice exam if you think you're ready to be tested.



Designing an access control strategy for the Registry

By default, only administrators have permissions to view or change the Registry. You can assign permissions to each of the keys in the Registry to allow certain users to make changes to the keys. You can also use the system to audit the Registry to determine which users have made changes or even attempted to make changes to the Registry. Your access control strategy for the Registry should include the following:

  • Designing a permission structure for Registry objects
  • Analyzing auditing requirements

Designing a permission structure for registry objects

In Windows Server 2003, all system information is centrally located in the Registry. The information is stored in containers called keys. The two main keys are HKEY_CURRENT_USER and HKEY_LOCAL_MACHINE. One incorrect edit to the information contained in these keys can potentially disable the operating system. For this reason, only administrators should have access to the Registry on most computers. Users indirectly make changes to the Registry when they use GUI tools, such as Control Panel or Display Settings. These changes are much safer than changes made directly to the Registry.

Some applications and some hardware require a Registry edit to function properly. You might want to allow certain users to make the changes to the Registry so that you don't have to make them every time. If you choose to allow a user to make changes to the Registry, you need to ensure that he has the training and the knowledge to make the changes correctly.

You can assign permissions on each key of the Registry in much the same way that you assign permissions to files or folders. To do so, access the Registry using the regedt32.exe or regedit.exe tool, right click the key that you want to change, and click Permissions. The Permissions dialog box opens, as shown in Figure 6.9. You can then add a user and give him the permissions required to make the change. As always, you should only give him the minimum level of permissions required to make the appropriate changes. You can also use Group Policy to assign permissions to multiple users and computers at the same time.

TIP: You should rarely need to give a user Full Control permissions on a Registry key.

Analyzing auditing requirements

You only need to audit the Registry if you feel that someone is making changes to it without your approval. If troubleshooting a problem seems to indicate that a change was made to the Registry that could not have been made by another tool and could not have been made by accident, auditing the Registry is in order. In this case, you should audit the specific key where the change was made. You can set the auditing for the key in the Advanced section of the permissions for the key, as shown in Figure 6.10. In this case, you might want to audit the Everyone group for access to the Registry key because the list should not be large and because you want to ensure that everyone is included in the audit.


Figure 6.9: You can set permissions for each key in the Registry.


Figure 6.10: You can set audit entries in Advanced Security Settings for each key in the Registry.

You've finished all the excerpts. Are you ready to be tested?: Try your hand at these 10 Exam Cram prep questions


Click for the book excerpt series or purchase the book here.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Certifications
Cheap Microsoft licenses for security pros: Microsoft Action Pack
SearchSecurity.com Guide to Infosec Certifications
Employee loyalty slipping for some
Top 10 tech tips of 2004
Exam Cram Quiz #1 Answer Key
Getting certified
Designing security for a backup and recovery strategy
Being selective when analyzing auditing requirements
Benefiting from an MCSE: Security certification
Benefiting from an MCSE: Security certification

Authentication
Windows Server 2008 security aided by NAP and IPsec
Manage administrator rights in Windows Server 2003
Why don't I have proper Windows Server 2003 rights to open a GPO?
How can I prevent Internet access with Windows SBS?
Windows server security management: Security expert roundup
Windows server management with Remote Desktop
File management on a Windows Server 2003 NAS system
Windows Small Business Server 2003 access management
How to grant Microsoft Windows network permissions
Intrusion prevention for Windows network security
Authentication Research

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts