ENDPOINT MANAGEMENT 1 Information Systems Managers
Total Page:16
File Type:pdf, Size:1020Kb
STAFF SYMPOSIUM SERIES INFORMATION TECHNOLOGY TRACK FACILITATORS Carl Brooks System Manager ‐ Detroit, MI Chapter 13 Standing Trustee – Tammy L. Terry Debbie Smith System Manager – Robinsonville, NJ Chapter 13 Standing Trustee – Al Russo Scot Turner System Manager –Las Vegas, NV Chapter 13 Standing Trustee – Rick Yarnall Tom O’Hern Program Manager, ICF International, Baltimore, MD STACS ‐ Standing Trustee Alliance for Computer Security STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 1 Information Systems Managers Windows 10 Debbie Smith System Manager Regional Staff Symposium ‐ IT Track May 11 and 12, 2017 Las Vegas, NV STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 2 Windows lifecycle fact sheet End of support refers to the date when Microsoft no longer provides automatic fixes, updates, or online technical assistance. This is the time to make sure you have the latest available update or service pack installed. Without Microsoft support, you will no longer receive security updates that can help protect your PC from harmful viruses, spyware, and other malicious software that can steal your personal information. Client operating systems Latest update End of mainstream End of extended or service pack support support Windows XP Service Pack 3April 14, 2009 April 8, 2014 Windows Vista Service Pack 2April 10, 2012 April 11, 2017 Windows 7* Service Pack 1 January 13, 2015 January 14, 2020 Windows 8 Windows 8.1 January 9, 2018 January 10, 2023 Windows 10, July 2015 N/A October 13, 2020 October 14, 2025 * Support for Windows 7 RTM without service packs ended on April 9, 2013. Be sure to install Windows 7 Service Pack 1 today to continue to receive support and updates. STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 3 Windows 10 Pro vs Enterprise STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 4 Initial Config. & Deployment Issues Which version of Windows 10? ◦ HOME version cannot join domain ◦ PRO version (after anniversary update [version 1607]) cannot disable store via GPO (there is a workaround) Will include new ‘features’ with updates ◦ ENTERPRISE version has 2 license models E3 – access to all Windows 10 Enterprise Features ◦ Pay‐as‐you‐go cloud license $7 p/user p/month ($1,932 p/year for 23 users) ◦ Open Business License $294.99 ($6,785 one‐time purchase) E5 –E3 plus Windows Defender Advanced Threat Protection STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 5 Initial Config. & Deployment Issues ◦ If you upgraded to the FREE version of Windows, you got Home or Pro –Enterprise was never free ◦ ENTERPRISE Long Term Servicing Branch (LTSB) Does not include: ◦ Cortana ◦ Windows Store ◦ Edge browser ◦ Photo Viewer ◦ UWP version of Calculator (replaced by classic version) Will not receive any feature updates Gives companies more control over the update process Upgrade license $274.00 p/seat STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 6 Compare Windows Versions STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 7 Compare Windows Versions STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 8 Compare Windows Versions STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 9 Compare Windows Versions STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 10 Compare Windows Versions STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 11 Windows 10 Features Bitlocker > PRO & ENTERPRISE ◦ Upgrade laptops with HOME to PRO to get Bitlocker Device Guard > ENTERPRISE ◦ Helps protect against malware ◦ Helps protect the Windows core from vulnerability and zero‐day exploits ◦ Allows only trusted apps to run Applocker > ENTERPRISE ◦ Whitelist apps that can run on the machine STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 12 Windows 10 Features Managed User Experience > ENTERPRISE ◦ Restrict access to Cortana & Windows Store ◦ Remove and prevent access to Shut Down, Restart, Sleep & Hibernate ◦ Remove Log Off from Start Menu ◦ Remove Frequent Programs from Start Menu ◦ Remove All Programs from Start Menu ◦ Prevent users from customizing Start screen ◦ Prevent changes to Taskbar and Start Menu Direct Access > ENTERPRISE –always‐on VPN STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 13 Initial Config. & Deplyment Issues Uninstall bloatware / games using Scot’s Powershell script ◦ Doesn’t remove everything ◦ Can’t remove store (after anniversary upgrade on Pro) ◦ Even though apps appear to be uninstalled, some come back when new user logs in Sway, Feedback Hub, OneDrive, Paid Wifi & Cellular Must uninstall these as logged in user STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 14 Windows Update Issues Cannot turn off updates in PRO version (can defer) Set up ACTIVE HOURS so your machine doesn’t restart in the middle of the day (or in court) (Settings > Update & Security) If you set your WIFI connection to ‘METERED’ Windows *should not* run updates Set CHOOSE HOW UPDATES ARE DELIVERED (Settings > Update & Security > Advanced Options) and turn off updates to/from other computers on network STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 15 Group Policy Settings If your Windows Server version is prior to 2016, download ADMX for GPO templates ◦ There are 2 downloads –1 for machines running pre‐ anniversary update, and 1 for post STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 16 Group Policy Settings Security and functionality ◦ Prevent OneDrive Use ◦ Turn Off Cortana ◦ Turn Off App Updating ◦ Turn off Store (ENTERPRISE version only) Workaround: Disallow access to store software ◦ Remove Store Icon from Taskbar ◦ Turn off Live Tile Notification ◦ Set Interactive Login (CTRL + ALT + DEL) and Login Message ◦ Turn off Action Center STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 17 Privacy Settings Everything in all categories off (unless necessary) ◦ Privacy > General: Opt‐out of personalized ads in browser Stop Cortana from getting to know you Turn off your location Never send Windows feedback Anniversary update changed previous settings back to default STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 18 Privacy Settings: Account Sync If you login with a Microsoft account, syncing settings may include sending passwords to Microsoft: TURN THIS OFF ◦ Settings > Accounts > Sync your settings STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 19 Information Systems Managers Endpoint Management Carl W. Brooks Manager of Information Systems Regional Staff Symposium ‐ IT Track May 11 and 12, 2017 Las Vegas, NV STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 1 Endpoint Devices Internet‐capable, TCP/IP network‐ capable Hardware Server Tablets Desktop Thin clients Laptops Virtual Machines Smart phones STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 2 Endpoint Security In network security, endpoint security refers to a methodology of protecting the corporate network when accessed via remote devices such as laptops or other wireless and mobile devices. Each device with a remote connection to the network creates a potential entry point for security threats. webopedia.com STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 3 Endpoint Management Asset Control Endpoint Security Software Management Back Up Your Data Communicate & Document Important Information Redundancy STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 4 Asset Control Eliminate “Ghost” assets Conduct physical asset inventories Tag assets appropriately Use the right labels for the job STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 5 Inventory Software Snipe‐IT ◦ www.snipeitapp.com PDQ Inventory ◦ www.adminarsenal.com Open AudIT ◦ www.open‐audit.org Spiceworks ◦ www.spiceworks.com STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 6 Asset Disposal Repurpose or Dispose Wipe Data Removing Tags Removing from Inventory Removing from Premises ◦ Charity Organization ◦ Recycle ◦ Destroy \Shred ◦ Buy Back STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 7 Support Strategies Trustee and staff ◦In Office ◦At Court ◦At Home ◦On the Road 3rd Party Support\vendors Debtors\Trainees Visitors and Auditors STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 8 Strategies for supporting auditors and visitors ◦ Access to network for Internet, printing, Case data ◦ File transfer electronic files ◦ Credentialed access to network computer, case management software, ECF/PACER, Wi‐Fi/Internet STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 9 Endpoint Security • Physical Security • Window/Desktop • Patch management firewall • Anti‐virus, SPAM, • Risk/vulnerability Malware assessment • Browser Plugins • Security policy management • Endpoint Loss and Recovery STAFF SYMPOSIUM IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 10 STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 11 Security Considerations Using Computers (Dos and the Don’ts) Personal device uses Access to email USB charging, connections to Trustee Equipment Access to Wi‐Fi, LAN, VPN, Internet Two‐Factor authentication STAFF SYMPOSIUM ‐ IT TRACK 5/11/2017 SESSION 4 ‐ ENDPOINT MANAGEMENT 12 The Weakest Link: People A leakage can be avoided if the person involved can have better