BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Some People Collect Stamps, I Collect Least Privilege Rules

Posted February 17, 2012    Peter McCalister

As I guide folks through setting up and using PowerBroker Windows Desktops I’m always thinking ahead, past the, ‘Phase 1′ deployment. A big part of this is sorting out your rule set, (Policies that dictate what elevation an application receives, or whether it is even allowed to execute), into collections.

A collection is a folder you create within your GPO where you put ‘like’ application rules into, or rules specific to a particular group. In other words, you may choose to create a collection for In-House created applications, or one containing a set of rules for Adobe software. In other cases, where you do need deeper control over who gets a set of rules, you can create a collection named after this group, for instance, Accounting, Engineering, Marketing, etc. In this latter case, you combine the convenience of collections with the control of Item-Level Targeting, just like what you use with MS Group Policy Preferences. I’ll cover this more in-depth in a future post. For now think of Item-Level Targeting like the Security Filtering available in the MS Group Policy Management Console on steroids.

Whether you are just starting out with PowerBroker Windows Desktops or have been using the software to either mitigate the risk associated with over-privileged users or reduce support costs with under-privileged ones for awhile, think about your enterprise and how you can use collections.

Do you have rules now that you put into a separate GPO because you need to make sure they only apply to certain situations?
Do you have a list of rules and are having trouble remembering what all of them deal with?

Maybe you’re like me and just need to put everything in it’s place. These are just a few of the reasons to use collections. If you want more information on applying collections to your environment, just give us a call; we’re here 24 hours a day/7 days a week.

Leave a Reply

Additional articles

VMware Hardening Guidelines-img3

How to Audit VMware ESX and ESXi Servers Against the VMware Hardening Guidelines with Retina CS

Posted February 27, 2015    BeyondTrust Research Team

Retina CS Enterprise Vulnerability Management has included advanced VMware auditing capabilities for some time, including virtual machine discovery and scanning through a cloud connection, plus the ability to scan ESX and ESXi hosts using SSH. However, in response to recent security concerns associated with SSH, VMware has disabled SSH by default in its more recent…

Tags:
, , , ,
dave-shackleford-headshot

Privileged Passwords: The Bane of Security Professionals Everywhere

Posted February 19, 2015    Dave Shackleford

Passwords have been with us since ancient times. Known as “watchwords”, ancient Roman military guards would pass a wooden tablet with a daily secret word engraved from one shift to the next, with each guard position marking the tablet to indicate it had been received. The military has been using passwords, counter-passwords, and even sound…

Tags:
, , ,
Privileged Account Management Process

In Vulnerability Management, Process is King

Posted February 18, 2015    Morey Haber

You have a vulnerability scanner, but where’s your process? Most organizations are rightly concerned about possible vulnerabilities in their systems, applications, networked devices, and other digital assets and infrastructure components. Identifying vulnerabilities is indeed important, and most security professionals have some kind of scanning solution in place. But what is most essential to understand is…

Tags:
, , , , ,