The most trusted source for computer security training, certification and research.



select a course
Sydney, Australia - August 5 - 10, 2007
Global Information Assurance Certification

Best IT Security return on Investment.
-Mario Chiock, Schlumberger

SECURITY 505

Securing Windows

Sunday 5 August - Friday 10 August 2007
Jason Fossen, SANS Faculty Fellow
6 CPE Credits Per Day

The Securing Windows course is a comprehensive curriculum for securing Windows networks. This program brings the confusing complexity of Windows security into clear focus by starting with foundational security services, such as Active Directory and Group Policy, and advancing in a logical progression to particular products or features which rely on these foundations, such as IIS and IPSec. This track provides best practices for security, hands-on exercises, extensive documentation/screenshots, a CD-ROM of security scripts, and an objective account of Windows security (neither bashing Microsoft nor toeing the party line).

This track will also prepare you for the GIAC Certified Windows Security Administrator (GCWN) certification exams, and many of the MCSE:Security exams as well.

You are encouraged to bring a Windows Server 2003 Enterprise Edition laptop or virtual machine with you, but this is not required. The instructor will demonstrate the skills discussed in the course and the manuals include numerous screenshots.

  • Who Should Attend
    • Anyone who manages a Windows network
    • Those who want to go beyond their MCSE training
    • Anyone whose IIS web server is in danger of compromise
    • Anyone who is planning to deploy Active Directory, Group Policy, IPSec or a PKI
  • A Sampling of Topics
    • What's New In Windows Vista?
    • BitLocker Drive Encryption
    • User Account Control
    • IPSec and the Windows Firewall
    • Active Directory Design
    • Delegation of Authority in AD
    • Secure Dynamic DNS
    • Group Policy Design
    • Security Templates and SECEDIT.EXE
    • PKI Installation and Management
    • Encrypting File System (EFS)
    • Smart Cards for EFS
    • IPSec VPNs and RRAS
    • RADIUS for VPNs and Wireless
    • Wi-Fi Protected Access (WPA)
    • Securing IIS Web Applications
    • Securing WebDAV on IIS
    • Windows Scripting: WMI and ADSI

I learned more here in six days than I could in a year in terms of breadth of knowledge.
-Stephen Yuhas, TESSCO Technologies

Author Statement

Microsoft might be faulted for many things, but lack of ambition is definitely not one of them. Active Directory, PKI, Group Policy, User Account Control, BitLocker, ISA Server, VPNs, etc. all make for a completely new Windows landscape that is vastly more interesting (and complex) than the old Windows 98/NT world. You can do some incredible things with Windows now, and in Security 505 that‹s what we‹re going to do. We‹ll see how to set it all up and secure it against malicious insiders and Internet hackers. We‹ll also talk a lot about how to automate as much of the work as possible (like with Group Policy) so that you won‹t have to spend endless hours each week doing repetitive tasks. I‹m constantly updating the courseware and adding new tools to the CD-ROM so that we can cover everything important in just six days. I promise you, those six days will go by fast!
- Jason Fossen

Jason Fossen on YouTube — Securing Windows