On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

March 8th, 2007

BeyondTrust makes standard user usable in Windows

Posted by George Ou @ 4:03 am

Categories: Desktop, Infrastructure, Security, Vista

Tags:

It's a well known fact that almost all IT organizations run their client Windows (typically 2000 or XP) computers in full administrative mode, which violates the fundamental security model of least privilege. The simple reason for this is that running Windows 2000 and XP in standard user mode is too difficult to manage for most businesses, and many "security" applications, like antivirus software or system management software, force the use of administrative privileges or they simply don't work.

Administrative privileges on user computers is the most dangerous thing that can be done from a security standpoint, but it's something that the Windows world has unfortunately gotten use to, while the UNIX, Linux, and Mac OS X world forces users to elevate privileges when needed. Windows Vista is the first Windows OS to default to a non-Administrative user, along with a more graceful way of elevating privileges, but it will take quite some time before businesses start adopting Windows Vista. Even when they do upgrade to Vista, IT departments may not want their users to have to make the decision to elevate permissions using the Vista UAC interface. UAC prompts for standard users in Vista can easily be suppressed globally so that it behaves like Windows 2000 and XP, but that just means we're back to the same problem of not being able to run software that needs administrative privileges. This is where BeyondTrust comes in.

BeyondTrust is an enterprise management solution that manages Windows 2000, XP, Vista, and Server 2003 (needed in terminal server environments).  BeyondTrust Privilege Manager extends the Windows Active Directory Group Policy so that you can set granular, on-the-fly, seamless privilege escalations for specific actions, such as time change, programs, and folders. There is also a free version of Privilege Manager that runs on the local Group Policy so you can use it on an individual machine. This allows people who want to run standard user mode without permission problems to do so at no cost with the local version of Privilege Manager. The enterprise version, which costs $30 per seat (large volume discounts available), simply allows you to manage privilege escalations at the Active Directory level for the entire domain, organizational unit, or individual user. This means you'll be able to set that annoying antivirus package to run in administrator mode but not give the user the administrative rights to get him/her in trouble with persistent rootkits and malware. Note that I qualified that statement with the word "persistent" because Privilege Manager won't prevent malware from nuking user files or putting itself in the local user startup. That kind of damage can at least be cleaned up by deleting and re-creating the local user account, though your data may not be so lucky unless you had it backed up offline somewhere.

For Windows 2000 and XP, Privilege Manager seems to be a great deal for businesses because it vastly improves security and reduces malware cleanup downtime or users hosing their own system with unauthorized software. The value proposition of Privilege Manager for Windows Vista is a bit less certain, but it might even be worth looking at, since your users won't need to deal with the UAC decision process where they might make the wrong choice. Having a way of centrally white-listing what's trusted code worthy of administrator mode and what's not worthy is a valuable management tool.  Of course, Vista UAC can be tweaked in Active Directory Group Policy to only permit privilege escalation of code that's been digitally signed by a trusted source, so that may be a reasonable alternative for preventing users from making bad decisions. But it still prompts the user with UAC authorization, which makes it nontransparent.  I'd suggest giving the free version a test drive to see if it's worth it.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 52 Talkback(s)
Ada not a problem either
There is also a port of the open source version of the GNAT ada compiler to Mac OS X. (Read the rest)
Posted by: fde101 Posted on: 04/20/07 You are currently: a Guest | | Terms of Use
Sounds like a similar concept to ...  bportlock | 03/08/07
Just a front-end for things Windows has allways been able to do  toadlife | 03/08/07
I still don't see much of this model  nucrash | 03/08/07
Try this site  toadlife | 03/08/07
In other words, in the year 2000 Windows was already archaic  YinToYourYang-22527499 | 03/08/07
Yes but now Microsoft has to listen  nucrash | 03/08/07
46 years too late  YinToYourYang-22527499 | 03/08/07
UNIX is not 46 years old  toadlife | 03/08/07
46 years?  nucrash | 03/08/07
Give or take 10 years doesn't change the fact Windows security lags UNIX  YinToYourYang-22527499 | 03/09/07
Your Wrong Again!  ShadeTree | 03/09/07
UNIX history lesson - pass; Windows security - fail  YinToYourYang-22527499 | 03/09/07
YinYang  NonZealot | 03/09/07
Um, not quite  NetArch. | 03/08/07
By the 80s *nix was a museum piece  TonyMcS | 03/08/07
It's called the UNIX wars  YinToYourYang-22527499 | 03/09/07
Funny!  ShadeTree | 03/09/07
Something about which you would know nothing  YinToYourYang-22527499 | 03/09/07
I deny it  NonZealot | 03/09/07
What lies are you referring to?  YinToYourYang-22527499 | 03/09/07
Microsoft hubris  YinToYourYang-22527499 | 03/09/07
Because everything in the movies is spot-on  ImUpAbvIt | 03/09/07
You've hit the nail on the head...  ye | 03/09/07
Thank you very much  nucrash | 03/08/07
Sure thing  georgeou | 03/08/07
Some one gave me this:  nucrash | 03/09/07
Obviously free software trumps security  YinToYourYang-22527499 | 03/09/07
Oh, comparisons, I can do these  nucrash | 03/09/07
Brainwashed tripe  YinToYourYang-22527499 | 03/09/07
With Intel Mac I have all worlds at my fingertips  YinToYourYang-22527499 | 03/09/07
no need to lie  toadlife | 03/09/07
Well if you mean military ADA code, then I guess you're right.  YinToYourYang-22527499 | 03/11/07
MVS is not a problem  fde101 | 04/20/07
Ada not a problem either  fde101 | 04/20/07
We could argue over statistics  NonZealot | 03/08/07
The tools are there  nucrash | 03/08/07
Gartner estimates more than 80% uses Admin for desktops  georgeou | 03/08/07
It's the quickest way to get work done  YinToYourYang-22527499 | 03/09/07
Post something Intelligent to this Post?  nucrash | 03/09/07
Microsoft has done the same.  ye | 03/09/07
lol  toadlife | 03/09/07
You missed two major migrations  georgeou | 03/09/07
It's not a sport, George. It's marketing.  YinToYourYang-22527499 | 03/11/07
Overpaid ignoramus  YinToYourYang-22527499 | 03/11/07
Guilty as Charged  nucrash | 03/09/07
After reading up on this...  toadlife | 03/08/07
Yeah it's nothing revolutionary, just a neat package  georgeou | 03/08/07
Misinformation  frgough | 03/09/07
Word?  toadlife | 03/09/07
My mistake  frgough | 03/09/07
Done  NonZealot | 03/09/07
Oops, I lied  NonZealot | 03/09/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    SmartPlanet

    Click Here