WARNING: If you use the convert utility, it will set the ACLs for the converted drive to Everyone:Full Control.

Before you edit the registry, make sure you understand how to restore it if a problem occurs. The value should be set to 1 to allow only administrators to install printer drivers on servers and domain controllers.

Subscribe to the Microsoft Security Notification Service WARNING: You MUST keep on top of new security issues as they rise. In general, longer passwords are stronger than shorter ones, and passwords with several character types (letters, numbers, punctuation marks, and non-printing ASCII characters, generated by using the Alt key and three-digit

  • It could cause major corruption of the installation and you may need to reformat the hard drive in order to start again.
  • The user must log off and log on again to cause the device or devices to be allocated.
  • Doing so will cause unpredictable results, including possible loss of system functionality.
  • For a complete list of security patches, consult http://www.microsoft.com/technet/security/default.mspx.
Set up your network adapter. (This may require a driver disk from the manufacturer.) Once the adapter is installed and configured, right-click on the "Network Neighborhood" icon on the desktop and To restrict the ability of users to plant Trojan horse programs: Use the Registry Editor to find the following keys: Hive HKEY_LOCAL_MACHINE\SOFTWARE Key Microsoft\Windows\CurrentVersion Values Run, RunOnce, Uninstall (if present), AEDebug

The Service information dialog will appear. Hive HKEY_LOCAL_MACHINE\SYSTEM Key CurrentControlSet\Control\LSA Value Name NotificationPackages Type REG_MULTI_SZ Change Add the string passfilt.dll to the list Configure the Administrator account Because the Administrator account is built in to every copy https://hippo.colorado.edu/info/ipsetup/staticip_setup.cgi?os=winnt4 To turn this on, use the Account Policy dialog in User Manager for Domains, then select the "Account lockout" radio button.

These keys allow you to regulate which types of authentication the DC will accept, For complete details, see KB article 147706; it's important to balance the increased security gained from restricting NT Lan Manager (NTLM) authentication is significantly stronger than plain LM authentication. If using Windows NT 4.0 in VirtualBox, press Ctrl+Delete (default mapping) to use the Ctrl+Alt+Delete function. Never leave the password field blank.

At install time this key is empty; set ACLs to prevent its misuse. \Software\Microsoft\Windows\Current Version\Explorer Everyone:Read Apply to entire tree \Software\Microsoft\Windows\Current Version\Embedding Installers: Change Everyone: Read Apply to entire tree \Software\Microsoft\Windows\Current It's a good idea (but not essential) to come up with a password to your computer to prevent unauthorized access. 6 Consider adding an emergency repair disk which can be used Create windows NT 4 set-up disks The Windows NT 4 set-up disks can be created from the Windows NT (workstation or server) cd.

DO NOT insert the numbers inserted above - they are just for example purposes. Information on contacting Microsoft Product Support is available at http://support.microsoft.com/support/contact/default.asp.

Depending on your needs and your hardware configuration, you can do any of the following: Consider removing the system's floppy and CD-ROM drives to prevent booting from them. Hive HKEY_LOCAL_MACHINE\SYSTEM Key \CurrentControlSet\Control\Session Manager Value Name ProtectionMode Type REG_DWORD Value 1 Secure additional base named objects This step is necessary to heighten security of additional base named objects such as This tool, passprop.exe, allows you to turn on complex password checking and to lock out the administrator account: The /complex switch turns on a requirement that all passwords must have at Which files should I download?

Which files should I download?

This prevents denial-of-service attacks against that protocol, improves your overall server performance, and safeguards you against protocol-specific exploits. (To unbind protocols, use the Bindings tab of the Network control panel; if

For this tutorial, NTFS was used. Server Operators) Generate security audits (no one)Do not assign to any user.

What level of physical security is appropriate? However, on a systems with MULTIPLE network-boards (Ethernet/Token-Ring/MULTIPLE Dial-Up AdapterS), it is now possible to configure the protocols to be used with the network-adapters by adjusting the Bindings.We are almost done:

Be sure to consider fire protection, electrical service, and physical access to the machine as part of your physical security planning. These values take effect at the next logon.