<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avecto.com &#187; Privilege Guard</title>
	<atom:link href="http://www.avecto.com/blog/category/privilege-guard/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.avecto.com/blog</link>
	<description>Windows Privilege Management Blog</description>
	<lastBuildDate>Wed, 09 May 2012 07:36:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Software Licensing for Virtual Desktop Infrastructures and Terminal Servers</title>
		<link>http://www.avecto.com/blog/2012/05/software-licensing-for-virtual-desktop-infrastructures-and-terminal-servers/</link>
		<comments>http://www.avecto.com/blog/2012/05/software-licensing-for-virtual-desktop-infrastructures-and-terminal-servers/#comments</comments>
		<pubDate>Tue, 08 May 2012 15:29:58 +0000</pubDate>
		<dc:creator>Russell Smith</dc:creator>
				<category><![CDATA[Application Control]]></category>
		<category><![CDATA[AppLocker]]></category>
		<category><![CDATA[Privilege Guard]]></category>
		<category><![CDATA[Software Installation]]></category>

		<guid isPermaLink="false">http://www.avecto.com/blog/?p=1640</guid>
		<description><![CDATA[Many organizations waste thousands every year on unused software licences. This occurs for a number of reasons, but not least due to the complexity of Microsoft licensing programmes and the need to track license usage across an ever changing IT &#8230; <a href="http://www.avecto.com/blog/2012/05/software-licensing-for-virtual-desktop-infrastructures-and-terminal-servers/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Many organizations waste thousands every year on unused software licences. This occurs for a number of reasons, but not least due to the complexity of Microsoft licensing programmes and the need to track license usage across an ever changing IT infrastructure. With the growing popularization of virtual desktop infrastructures (VDIs), monitoring license usage has become more challenging as virtual machines (VMs) can be dynamically created for one-off applications, and software installed on-demand from app stores.</p>
<p>Microsoft has recently changed its licensing to help organizations adopt virtualization technologies. The new Windows Virtual Desktop Access (VDA) licenses are a Software Assurance benefit, or can be purchased for $100 per desktop a year. VDAs provide users of Windows PCs the right to install Windows XP, Vista or 7 in up to 4 VMs. If you’re the primary user of a device covered by VDA, Extended Roaming Rights (ERR) allow you to access a VM from devices not licensed under Software Assurance or VDA, providing that they’re located offsite and don’t belong to the company.</p>
<p>To further help the take-up rate for virtualization, Microsoft has 2 licensing suites that package licences for accessing remote desktop servers, the Microsoft Desktop Optimization Pack (MDOP), System Center Configuration Manager (SCCM), Operation Manager (SCOM) and Virtual Machine Manager.</p>
<p>With the flexibility that VDIs provide, licenses for your line-of-business applications need to be monitored more carefully. While Microsoft’s AppLocker application whitelisting technology for Windows 7 is a security feature, preventing users launching untrusted applications and executables, Privilege Guard’s application control not only provides a unified administration interface for Windows 7, Vista and XP, but is also more flexible than AppLocker. Moving beyond security, Privilege Guard application control can also whitelist or blacklist applications by device, using a hostname or IP address.</p>
<p>Privilege Guard allows organizations to add a whitelist of device names to application control policies to prevent users launching programs installed on VMs or physical PCs, which is especially pertinent for VDIs where devices may greatly outnumber users, and organizations can quickly fall out of compliance with a shortfall of licences.</p>
<p>As licensing can be one of the biggest costs for Windows shops, ensuring that you procure only the number necessary is crucial to keep costs low. Virtualization technologies promise to reduce costs by allowing organizations to dynamically provision desktops to users without the high total cost of ownership traditionally associated with desktop PCs. But your efforts to reduce costs could be in vain if software licensing is not kept in check, and this is where Privilege Guard’s superior application control technology can help.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.avecto.com/blog/2012/05/software-licensing-for-virtual-desktop-infrastructures-and-terminal-servers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Self-Provisioned Software Installation with Privilege Guard</title>
		<link>http://www.avecto.com/blog/2012/03/self-provisioned-software-installation-with-privilege-guard/</link>
		<comments>http://www.avecto.com/blog/2012/03/self-provisioned-software-installation-with-privilege-guard/#comments</comments>
		<pubDate>Fri, 23 Mar 2012 10:44:52 +0000</pubDate>
		<dc:creator>Mark Austin</dc:creator>
				<category><![CDATA[Application Control]]></category>
		<category><![CDATA[Least Privilege]]></category>
		<category><![CDATA[Privilege Guard]]></category>
		<category><![CDATA[Software Installation]]></category>

		<guid isPermaLink="false">http://www.avecto.com/blog/?p=1432</guid>
		<description><![CDATA[In addition to elevating the rights of privileged applications and administrative tasks, Privilege Guard can empower users to install approved software. Although most organizations will have some form of centralized software distribution in place, packaging every application for distribution is &#8230; <a href="http://www.avecto.com/blog/2012/03/self-provisioned-software-installation-with-privilege-guard/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>In addition to elevating the rights of privileged applications and administrative tasks, Privilege Guard can empower users to install approved software. Although most organizations will have some form of centralized software distribution in place, packaging every application for distribution is not always economical and often unnecessary. With Privilege Guard you can easily complement your existing software distribution solution to enable standard users to self-provision any corporate approved software or if necessary give some users an even greater level of autonomy and audit their actions.<span id="more-1432"></span></p>
<p>Although you can authorize individual software packages with Privilege Guard, it may be more appropriate to allow a group of users to install software from a network share, as this is extremely simple to setup and maintain. The users should only be given read and execute access to this share, enabling them to launch any software packages that are made available by the IT department. A couple of simple rules can be added to Privilege Guard to automatically elevate any executables or installer packages that reside in the shared folder.</p>
<div id="attachment_1574" class="wp-caption alignnone" style="width: 561px"><a href="http://www.avecto.com/blog/?attachment_id=1574"><img src="http://www.avecto.com/blog/wp-content/uploads/2012/03/ApprovedSoftwareRules1.png" alt="Approved Software Application Definition" title="Approved Software Application Definition" width="551" height="137" class="size-full wp-image-1574" /></a><p class="wp-caption-text">Approved Software Application Definition</p></div>
<p>You could easily extend this principle to be more granular, such as creating a set of folders within this share for different roles and then ensuring that the software installers are only elevated for the relevant groups of users. </p>
<div id="attachment_1578" class="wp-caption alignright" style="width: 310px"><a href="http://www.avecto.com/blog/?attachment_id=1578"><img src="http://www.avecto.com/blog/wp-content/uploads/2012/03/InstallBlocked-300x171.png" alt="Blocked Software Installation" title="Blocked Software Installation" width="300" height="171" class="size-medium wp-image-1578" /></a><p class="wp-caption-text">Blocked Software Installation</p></div>
<p>This can be taken a stage further by blocking software installers for those users who should not have access to them. You can achieve this by adding a simple “catch all” policy to block all installations from the software share, which should be placed at the end of the policies and applied to all users (policy precedence will ensure that this policy will only match if a higher precedence policy has not matched first). A suitable message should be displayed to the user, with instructions on gaining access to the software, assuming they have a legitimate business purpose. You may optionally allow the user to email a request for an application or you can provide a<br />
hyper-link in the message that directs the user to an appropriate web site, such as a help desk portal.</p>
<div id="attachment_1472" class="wp-caption alignleft" style="width: 299px"><a href="http://www.avecto.com/blog/2012/03/self-provisioned-software-installation-with-privilege-guard/publisherproductrules/" rel="attachment wp-att-1472"><img src="http://www.avecto.com/blog/wp-content/uploads/2012/03/PublisherProductRules-289x300.png" alt="Software Publisher and Product Information" title="Software Publisher and Product Information" width="289" height="300" class="size-medium wp-image-1472" /></a><p class="wp-caption-text">Software Publisher and Product Information</p></div>
<p>You may need to allow some users to install authorized software directly from the internet. The recommend way to define policies for this purpose is to make use of the publisher rule, as opposed to the filename rule, and then combine this with other product rules, as required. For instance, we could allow the user to install all software signed by a particular vendor.</p>
<p>You could extend this rule to make it specific to a particular product by using the product name or product description, and you can optionally include a check for specific versions of the product or a minimum version.</p>
<p>In addition to elevating installation packages you can also specify rules to block the installation of software that you do not want users installing, as some software packages do not require administrative rights to be installed, as they install within the user&#8217;s profile.</p>
<div id="attachment_1524" class="wp-caption alignright" style="width: 310px"><a href="http://www.avecto.com/blog/2012/03/self-provisioned-software-installation-with-privilege-guard/ondemandprompt/" rel="attachment wp-att-1524"><img src="http://www.avecto.com/blog/wp-content/uploads/2012/03/OnDemandPrompt-300x283.png" alt="On Demand Software Installation" title="On Demand Software Installation" width="300" height="283" class="size-medium wp-image-1524" /></a><p class="wp-caption-text">On Demand Software Installation</p></div>
<p>For users with more flexible requirements, you can create an “on demand” policy where users are trusted to make their own decisions on software installations. This should be configured with a custom message, to warn the user of their actions and ask them for a reason, which is then audited. You may optionally force a user to re-authenticate before installing the software to ensure that they self-approved the installation.</p>
<p>Even with an on demand policy you can still prevent these users from installing certain software packages, by creating a higher precedence policy that blocks the installation of any unauthorized software. Alternatively, you can delegate the on-demand installation of software to an appropriate group of staff, such as departmental heads, who would need to authorize the installation on the user’s behalf.</p>
<div id="attachment_1520" class="wp-caption alignright" style="width: 310px"><a href="http://www.avecto.com/blog/2012/03/self-provisioned-software-installation-with-privilege-guard/activexblocked/" rel="attachment wp-att-1520"><img src="http://www.avecto.com/blog/wp-content/uploads/2012/03/ActiveXBlocked-300x171.png" alt="Blocked ActiveX Installation" title="Blocked ActiveX Installation" width="300" height="171" class="size-medium wp-image-1520" /></a><p class="wp-caption-text">Blocked ActiveX Installation</p></div>
<p>Privilege Guard can also handle the installation of ActiveX controls. For ActiveX controls, the primary rule to match on is the URL of the codebase. The URL can point to a specific codebase or a more general URL can be used to match multiple ActiveX controls hosted on a site. It’s a good idea to insert a catch all rule for ActiveX controls that blocks access to any ActiveX controls that have not been defined in the policy. This will provide the user with a corporate message and instructions on how they should request access to the blocked ActiveX control if they have a legitimate business reason for installing it.</p>
<div id="attachment_1523" class="wp-caption alignright" style="width: 310px"><a href="http://www.avecto.com/blog/2012/03/self-provisioned-software-installation-with-privilege-guard/activexinstall/" rel="attachment wp-att-1523"><img src="http://www.avecto.com/blog/wp-content/uploads/2012/03/ActiveXInstall-300x267.png" alt="ActiveX Installation" title="ActiveX Installation" width="300" height="267" class="size-medium wp-image-1523" /></a><p class="wp-caption-text">On Demand ActiveX Installation</p></div>
<p>As with “on demand” software installation, users with more flexible requirements can be authorized to install any ActiveX control. This should be configured with a custom message and audit trail, to ensure that the user is warned of their actions, and you may optionally force the user to re-authenticate. Remember that you can still block access to unauthorized ActiveX controls with a higher precedence policy. </p>
<p>The end user experience is a crucial element when allowing users to self-provision software, whether you are asking a user to justify their actions before proceeding, or blocking the installation of a software package and giving the user meaningful feedback and direction. Small touches, like strong corporate branding in end user messages, ensure that users pay more attention than when presented with a standard Windows message. You can define any number of end user messages in Privilege Guard, with corporate branding, multi-lingual configuration of all text elements and control over many other aspects, such as re-authentication and asking for justification before proceeding. It is always better to display a message that is relevant to a user’s actions, as opposed to a broad generic message, as this will lead to an improved end user experience and a reduction in help desk calls.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.avecto.com/blog/2012/03/self-provisioned-software-installation-with-privilege-guard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Welcome to RSA 2012 &#8211; and the world of 2012 cybersecurity defences</title>
		<link>http://www.avecto.com/blog/2012/03/welcome-to-rsa-2012-and-the-world-of-2012-cybersecurity-defences/</link>
		<comments>http://www.avecto.com/blog/2012/03/welcome-to-rsa-2012-and-the-world-of-2012-cybersecurity-defences/#comments</comments>
		<pubDate>Thu, 01 Mar 2012 10:57:43 +0000</pubDate>
		<dc:creator>Paul Kenyon</dc:creator>
				<category><![CDATA[Desktop Lockdown]]></category>
		<category><![CDATA[Least Privilege]]></category>
		<category><![CDATA[Privilege Guard]]></category>

		<guid isPermaLink="false">http://www.avecto.com/blog/?p=1417</guid>
		<description><![CDATA[With the RSA Security Conference now upon us in the US – and with a welter of really interesting announcements coming out of the San Francisco event – I was intrigued to read a guest column from Art Coviello, the &#8230; <a href="http://www.avecto.com/blog/2012/03/welcome-to-rsa-2012-and-the-world-of-2012-cybersecurity-defences/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>With the RSA Security Conference now upon us in the US – and with a welter of really interesting announcements coming out of the San Francisco event – I was intrigued to read a guest column from Art Coviello, the executive vice president of EMC, the parent company to RSA Security, on Forbes.</p>
<p>Coviello’s comments &#8211; citing the Bob Dylan track, `the times, they are a changin&#8217; &#8211; are bang on the money, especially when he recommends that IT security now needs to be a board level discussion.</p>
<p>This coincides with our thoughts here at Avecto, as the involvement of a board level discussion on security will help IT security managers to determine the `sweet spot&#8217; where the organization has invested in sufficient security to say it has carried out what any reasonable company would do to defend its digital assets.<span id="more-1417"></span></p>
<p>And in today&#8217;s security governance-rich environment, the expensive cost of reaching that sweet spot can be lowered by adopting a multi-layered approach to IT security and so help to ensure that the advantages of one type of security can offset the disadvantage &#8211; namely the weak spots &#8211; of another system.</p>
<p>At the risk of sounding like an accountant, this all comes down to the risk/reward balancing game which Coviello hints at in his column, but with the additional factor of cost entering the equation.</p>
<p>The EMC/RSA chief is, of course, quite correct in his assertion that the security world is changing, but our belief is that it’s not just about balancing risk with security, it&#8217;s also about balancing the cost of the security against the reward in terms of the level of security assurance that the expenditure will generate for a typical company.</p>
<p>And whilst there is no such thing as absolute IT security in today&#8217;s multi-vectored threat landscape, it is clear that multiple layers of defence can often produce a better overall return on investment curve than if just one or two layers of security are involved.</p>
<p>Our experience suggests that treating the governance levels of, for example, the PCI Security Standards Council as a starting point in security terms and working upwards &#8211; depending on the risk/cost/reward stance your organisation is prepared to invest in &#8211; is the best way forward.</p>
<p>And when you factor in Coviello&#8217;s sound advice that you need to continue to evolve your organisation&#8217;s thinking about security &#8211; working on the premise that shared knowledge is a powerful advantage &#8211; you realise that adding extra layers of defenses &#8211; such as a Windows privileged account management system that lowers your security risk profile &#8211; can help tremendously in the risk/cost/reward stakes.</p>
<p>The ideal solution is to apply least privilege principles to as many users as possible, with specific members of staff having limited access to admin facilities and, even then, only on the specific applications they need access to on a regular basis.</p>
<p>Our approach with Windows privilege management is to give users only the access and privileges they need to complete the task at hand. In most cases this will be for specific applications, tasks or scripts, and by assigning specific rights to those applications, you no longer need to give them to users. As Windows security expert Russell Smith, explains in his book ‘Least Privilege Security for Windows7, Vista and XP’, taking away user privileges can be similar to taking a toy away from a small child. Bottom line is that user expectations have a real impact on the security of any organization, so empowering them to perform their role without compromising the integrity or security of their systems makes good financial sense.</p>
<p>As Coviello says in his column, as cyber threats escalate, we must invest in building a cybersecurity workforce with the requisite skills to defend enterprises, governments, and critical infrastructures.</p>
<p>And whilst – again as the EMC/RSA chief against observes &#8211; these individuals need a 360-degree view of security that combines computer science, risk assessment, analytics, digital forensics, and human behaviour – it should also be clear that the addition of multiple layers of security can only enhance the risk/cost/reward ratios.</p>
<p>Even if you’re not a board level professional, that should still make you smile.</p>
<p>&nbsp;</p>
<p>For more on Art Coviello&#8217;s words of wisdom: <a href="http://onforb.es/yk5f32">http://onforb.es/yk5f32</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.avecto.com/blog/2012/03/welcome-to-rsa-2012-and-the-world-of-2012-cybersecurity-defences/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unsecured PCs Can Put Your Critical Infrastructure at Risk</title>
		<link>http://www.avecto.com/blog/2012/02/unsecured-pcs-can-put-your-critical-infrastructure-at-risk/</link>
		<comments>http://www.avecto.com/blog/2012/02/unsecured-pcs-can-put-your-critical-infrastructure-at-risk/#comments</comments>
		<pubDate>Tue, 21 Feb 2012 12:05:29 +0000</pubDate>
		<dc:creator>Russell Smith</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Application Control]]></category>
		<category><![CDATA[Desktop Lockdown]]></category>
		<category><![CDATA[Least Privilege]]></category>
		<category><![CDATA[Privilege Guard]]></category>

		<guid isPermaLink="false">http://www.avecto.com/blog/?p=1411</guid>
		<description><![CDATA[In an ideal world, critical IT systems should never rely on the security of lesser devices. But in practice, computer networks are complicated and many dependencies exist, some of which are more desirable than others, and eliminating all unwanted dependencies &#8230; <a href="http://www.avecto.com/blog/2012/02/unsecured-pcs-can-put-your-critical-infrastructure-at-risk/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>In an ideal world, critical IT systems should never rely on the security of lesser devices. But in practice, computer networks are complicated and many dependencies exist, some of which are more desirable than others, and eliminating all unwanted dependencies is a difficult task.</p>
<p>Windows member servers – i.e. those joined to an Active Directory (AD) domain – and workstations depend on domain controllers (DCs) to manage certain aspects of their security. This is a necessary dependency where a less important device relies on a more critical system.</p>
<p>Unwanted security dependencies tend to appear on networks unexpectedly. For instance, a PC becomes infected with a virus because the user was tricked into running a malicious executable, and an unpatched vulnerability is exploited. As a result, the Exchange Server is also infected and subsequently shut down by the virus. Though we can argue both the PC and server should have been patched, in this situation the server was unlikely to have been infected if the PC had remained secure.<span id="more-1411"></span></p>
<p>I was recently reminded about the DNS Changer trojan that first appeared in 2008 and mutated into various different forms. The virus attempts to change a PC’s DNS settings to redirect internet traffic, and failing that, scans the local network in an effort to discover the admin credentials and change the DNS configuration of gateway routers. This is an unfortunate example of where a critical network device becomes dependent on a PC for its security, in turn compromising the integrity of all devices connected to the router. Another variant of the trojan sets up a DHCP server on infected PCs and attempts to intercept DHCP requests on the local network and respond with bogus DNS settings to devices looking for valid DNS configuration.</p>
<p>To change DNS configuration on Windows, administrative rights are required; so a standard user account stops DNS Changer dead in its tracks. Secondly, with application whitelisting in place, DNS Changer wouldn’t be able to run at all, preventing it from scanning the network for vulnerable devices.</p>
<p>While SANS Internet Storm Center issued reactive advice at the time to block traffic to IP addresses known to host the malicious DNS servers, a proactive approach to prevent PCs being infected in the first place is always preferable. Antivirus should also be capable of stopping DNS Changer, but why rely solely on AV to protect your systems, especially with the speed at which malware mutates and sophisticated techniques used to evade detection.</p>
<p>Users often think that what happens on their network-connected PC or other device cannot affect the security of other systems, let alone critical servers and network hardware. But as you’ve read in this blog post, users and management should understand that once a device is connected to the network it does not exist in isolation, and least privilege security and application whitelisting technologies, such as those provided by Avecto Privilege Guard, are needed to protect the IT infrastructure at large.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.avecto.com/blog/2012/02/unsecured-pcs-can-put-your-critical-infrastructure-at-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Policy Filtering for Computers and Remote Clients</title>
		<link>http://www.avecto.com/blog/2012/02/policy-filtering-for-computers-and-remote-clients/</link>
		<comments>http://www.avecto.com/blog/2012/02/policy-filtering-for-computers-and-remote-clients/#comments</comments>
		<pubDate>Mon, 20 Feb 2012 16:05:20 +0000</pubDate>
		<dc:creator>Kris Zentek</dc:creator>
				<category><![CDATA[Privilege Guard]]></category>

		<guid isPermaLink="false">http://www.avecto.com/blog/?p=1370</guid>
		<description><![CDATA[For version 3.0, we have redesigned the how Policy Filters are configured and applied. Two distinct benefits came out of this. Granular targeting is now a lot more intuitive in terms of applying combinations of Policy Filters. It is now &#8230; <a href="http://www.avecto.com/blog/2012/02/policy-filtering-for-computers-and-remote-clients/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>For version 3.0, we have redesigned the how Policy Filters are configured and applied. Two distinct benefits came out of this.</p>
<ol>
<li>Granular targeting is now a lot more intuitive in terms of applying combinations of Policy Filters.</li>
<li>It is now a lot easier for us to add additional filters to Privilege Guard.</li>
</ol>
<p>The new Computer Filter allows you to target Privilege Guard Policies based on the hostname or the IP Address of the endpoint. This can be used as an alternative to, or in combination with, Group Policy based computer targeting.<span id="more-1370"></span></p>
<div id="attachment_1371" class="wp-caption alignnone" style="width: 310px"><a href="http://www.avecto.com/blog/2012/02/policy-filtering-for-computers-and-remote-clients/filters-2/" rel="attachment wp-att-1371"><img class="size-medium wp-image-1371" title="30UI_PolicyFilter" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/Filters1-300x196.png" alt="Policy Filters in 3.0" width="300" height="196" /></a><p class="wp-caption-text">Policy Filters in 3.0</p></div>
<p>Hostnames can be defined as an explicit list in each Computer Policy or, if you use a naming convention within your infrastructure, you can use wildcards to target a wider scope of computers.</p>
<p>If you prefer to use IP Addresses, then these can also be defined as explicit lists. You can also add wild cards and ranges to any octet in the IP Address, for example:</p>
<div id="attachment_1372" class="wp-caption alignnone" style="width: 310px"><a href="http://www.avecto.com/blog/2012/02/policy-filtering-for-computers-and-remote-clients/ip-address/" rel="attachment wp-att-1372"><img class="size-medium wp-image-1372" title="30UI_IPADDRESS" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/IP-Address-300x162.png" alt="Apply IP Address Filters using Wildcards" width="300" height="162" /></a><p class="wp-caption-text">Apply IP Address Filters using Wildcards</p></div>
<p>In addition to local computers, Privilege Guard Policies can also target privileges based on remote clients connecting via Remote Desktop Services. This means that privileges can be granted or revoked depending on the relative location of the user.</p>
<p>For example, you can now grant admin rights for an application, script or task to a user who is connecting from within the corporate network (based on IP Address), but prohibit admin rights to the same user if they are connecting through a tunnelled VPN.</p>
<p>Used in combination with application whitelisting, the Computer Filter can also be used to restrict access to corporate applications licensed under volume license and client license agreements.</p>
<p>We will be adding more filters to Privilege Guard throughout 2012, so make sure you subscribe to our blog and keep up to date with new developments from Avecto!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.avecto.com/blog/2012/02/policy-filtering-for-computers-and-remote-clients/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Allow Standard Users to Unlock Shared Workstations</title>
		<link>http://www.avecto.com/blog/2012/02/allow-standard-users-to-unlock-shared-workstations/</link>
		<comments>http://www.avecto.com/blog/2012/02/allow-standard-users-to-unlock-shared-workstations/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 09:49:37 +0000</pubDate>
		<dc:creator>Kris Zentek</dc:creator>
				<category><![CDATA[Desktop Lockdown]]></category>
		<category><![CDATA[Privilege Guard]]></category>

		<guid isPermaLink="false">http://www.avecto.com/blog/?p=1311</guid>
		<description><![CDATA[It is not uncommon for office based computer users to lock their desktop at the end of the working day, instead of shutting it down, maybe just force of habit from bygone days of long logon times. If they are &#8230; <a href="http://www.avecto.com/blog/2012/02/allow-standard-users-to-unlock-shared-workstations/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>It is not uncommon for office based computer users to lock their desktop at the end of the working day, instead of shutting it down, maybe just force of habit from bygone days of long logon times. If they are using a Windows domain joined desktop, this poses a problem, because only they can unlock it again and so the desktop is rendered unusable by other users.</p>
<p>If you operate a hotdesk or other shared workstation environment then there&#8217;s a good chance your users are regularly experiencing this problem, and historically there were three solutions:</p>
<ol>
<li>Call IT Support and ask them to ‘unlock’ the desktop for you (local administrators are the only users who can force the logged-on session to logoff).</li>
<li>Hard reset the desktop (which can lead to data corruption, data loss, etc).</li>
<li>Grant computer users local admin rights.</li>
</ol>
<p>None of these solutions were ideal, as they all came at a cost – either through increased helpdesk calls, or the <a href="http://www.avecto.com/solutions/security">hidden costs of users possessing excessive rights.</a></p>
<p>A new feature added to Privilege Guard 3.0, Shared Workstation Unlock, allows you to set policy on which end users are able to unlock a shared workstation or who is not allowed to unlock a workstation. So as well as empowering standard users, you can also restrict local administrators.<span id="more-1311"></span></p>
<p>Shared Workstation Unlock is driven by Privilege Guard Policies, and leverages the flexible filtering rules that define when and where policy is applied. So granting or revoking Shared Workstation Unlock privileges can be based on any combination of:</p>
<ul>
<li>User name and user group membership</li>
<li>Computer name or IP Address</li>
<li>Date and time range</li>
<li>Time expiry date</li>
</ul>
<p>Configuring Shared Workstation Unlock is easy, and anyone accustomed with Group Policy settings should find the logic familiar. For any Privilege Guard Policy, open the Policy Options dialog and you will find a tri-state option under Workstation:</p>

<a href='http://www.avecto.com/blog/2012/02/allow-standard-users-to-unlock-shared-workstations/attachment/1/' title='V3_Unlock_Menu'><img width="150" height="150" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/1-150x150.png" class="attachment-thumbnail" alt="Access settings from &#039;Policy Options...&#039; menu" title="V3_Unlock_Menu" /></a>
<a href='http://www.avecto.com/blog/2012/02/allow-standard-users-to-unlock-shared-workstations/attachment/2/' title='V3_Unlock_Dialog'><img width="150" height="150" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/2-150x150.png" class="attachment-thumbnail" alt="Configuration options for managing unlock privileges" title="V3_Unlock_Dialog" /></a>

<ul>
<li><strong>Not Configured</strong> – Privilege Guard will ignore this policy and move on to the next policy.</li>
<li><strong>User can unlock a shared workstation</strong> – Privilege Guard will allow the user to unlock the shared workstation.<strong></strong></li>
<li><strong>User cannot unlock a shared workstation</strong> – Privilege Guard will prevent the user from unlocking the shared workstation.<strong></strong></li>
</ul>
<p>Shared Workstation Unlock significantly reduces support costs by allowing standard users to unlock desktops in shared workstation environments without having to grant local admin rights.<strong></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.avecto.com/blog/2012/02/allow-standard-users-to-unlock-shared-workstations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UI Enhancements in Version 3.0</title>
		<link>http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/</link>
		<comments>http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/#comments</comments>
		<pubDate>Tue, 07 Feb 2012 10:06:13 +0000</pubDate>
		<dc:creator>Kris Zentek</dc:creator>
				<category><![CDATA[Privilege Guard]]></category>

		<guid isPermaLink="false">http://www.avecto.com/blog/?p=1270</guid>
		<description><![CDATA[Time to show off the new Management Console in Privilege Guard 3.0! One of the many key differences that set Privilege Guard apart from the rest of the field is our UI and how policies are configured. Not being one &#8230; <a href="http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Time to show off the new Management Console in Privilege Guard 3.0!</strong></p>
<p><strong></strong>One of the many key differences that set Privilege Guard apart from the rest of the field is our UI and how policies are configured. Not being one to rest on our laurels, we’ve listened a lot to our customers, and injected a lot of innovation onto the 3.0 UI. I hope you’ll agree that the results are impressive!</p>
<p>We have a diverse range of customers, including large corporations managing hundreds of thousands of desktops. The Privilege Guard policies for such large rollouts, as you can imagine, are quite complex, so it’s important to understand how we can continue to simplify their initial creation and on-going maintenance.</p>
<p>The entire console has been given an overhaul, and here are just a few of the highlights…<span id="more-1270"></span></p>
<p><strong>Summary Views</strong><br />
This is a feature we introduced to Application groups in V2.8. The positive feedback we got led to the rollout of summary views to the rest of the management console. I’ll let the pictures do the talking.</p>

<a href='http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/policies/' title='V3UI_Policies'><img width="150" height="150" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/policies-150x150.png" class="attachment-thumbnail" alt="Policies View in Version 3.0" title="V3UI_Policies" /></a>
<a href='http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/filters/' title='V3UI_PolicyFilters'><img width="150" height="150" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/filters-150x150.png" class="attachment-thumbnail" alt="Policy Filters View in Version 3.0" title="V3UI_PolicyFilters" /></a>
<a href='http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/policyrules/' title='V3UI_PolicyRules'><img width="150" height="150" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/policyrules-150x150.png" class="attachment-thumbnail" alt="Policy Rules View in Version 3.0" title="V3UI_PolicyRules" /></a>
<a href='http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/appgroups/' title='V3UI_AppGroups'><img width="150" height="150" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/appgroups-150x150.png" class="attachment-thumbnail" alt="Application Groups View in Version 3.0" title="V3UI_AppGroups" /></a>
<a href='http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/messages/' title='V3UI_Messages'><img width="150" height="150" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/messages-150x150.png" class="attachment-thumbnail" alt="Messages View in Version 3.0" title="V3UI_Messages" /></a>
<a href='http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/tokens/' title='V3UI_Tokens'><img width="150" height="150" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/tokens-150x150.png" class="attachment-thumbnail" alt="Tokens View in Version 3.0" title="V3UI_Tokens" /></a>

<p>All views offer an alternate &#8216;Detailed&#8217; view, which will show configuration settings in a color coded table format. Whatever your preference is, you can easily set it from the Views drop-down  menu.</p>
<p><strong>Instant Search and Drilldown</strong><br />
Another feature originally introduced in 2.8, instant search in Application Groups, has been expanded across the entire policy. All areas of the console now include an instant search box, from the top level node for policy wide searches, down to searches within specific areas.</p>
<p>As you start typing, the console automatically switches to a results view displaying settings that match your text entry. The more you type, the more refined the results become. The results view will also highlight where the matching property is.</p>
<div id="attachment_1278" class="wp-caption alignnone" style="width: 310px"><a href="http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/search/" rel="attachment wp-att-1278"><img class="size-medium wp-image-1278" title="V3UI_Search" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/search-300x218.png" alt="Instant Search in Version 3.0" width="300" height="218" /></a><p class="wp-caption-text">Instant Search in Version 3.0</p></div>
<p>In this example, I have entered the word ’disk’ into the top level instant search box. You can see that matches have been found within the ‘Admin tasks’ application group, as well as the policies where that group has been used. Instant search will find matches in any area of your settings.</p>
<p>When you have found the setting or property you are looking for, simply double click it to drill down into the actual setting.</p>
<p><strong>Instant Message Previews</strong><br />
Another key advantage of Privilege Guard is powerful end user messaging. Our unique message customization feature allows you to personalize almost every aspect of the message box, from text strings, colors and styles to full corporate branding. You can also define which features and elements are used for each custom message you create.</p>
<div id="attachment_1274" class="wp-caption alignnone" style="width: 310px"><a href="http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/messagepreview/" rel="attachment wp-att-1274"><img class="size-medium wp-image-1274" title="V3UI_MessagePreviews" src="http://www.avecto.com/blog/wp-content/uploads/2012/02/messagepreview-300x218.png" alt="Message Previews in Version 3.0" width="300" height="218" /></a><p class="wp-caption-text">Message Previews in Version 3.0</p></div>
<p>To simplify the creation and updating of custom messages, we have added instant preview. So as you are making changes to your message, the preview updates in real-time to help you create the exact look and feel you require. If you want to see the message is action, just click on the instant preview.</p>
<p>So the leading solution for managing privileges has just got a whole lot better looking. Why choose between style and substance, when you can have both!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.avecto.com/blog/2012/02/ui-enhancements-in-version-3-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privilege Guard 3.0 is here!</title>
		<link>http://www.avecto.com/blog/2012/02/privilege-guard-3-0-is-here/</link>
		<comments>http://www.avecto.com/blog/2012/02/privilege-guard-3-0-is-here/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 11:11:55 +0000</pubDate>
		<dc:creator>Kris Zentek</dc:creator>
				<category><![CDATA[Privilege Guard]]></category>

		<guid isPermaLink="false">http://www.avecto.com/blog/?p=1259</guid>
		<description><![CDATA[I am pleased to announce that version 3.0 is now available for download. This release is the product of many months of development, and is packed with new features and enhancements. Keep an eye on our blog over the coming &#8230; <a href="http://www.avecto.com/blog/2012/02/privilege-guard-3-0-is-here/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I am pleased to announce that version 3.0 is now available for download. This release is the product of many months of development, and is packed with new features and enhancements. Keep an eye on our blog over the coming days and weeks as we explore them in more detail.</p>
<p>For now, make sure you read up on <a href="http://www.avecto.com/whats-new">What’s new in Privilege Guard 3.0</a></p>
<p>We at Avecto pride ourselves on being a dynamic, agile software house, and for listening to and working closely with our customers. Collaboration is key to maintaining Privilege Guard’s position as the leading solution for delivering least risk desktops and servers, and my thanks go to everyone who contributed to version 3.0.<span id="more-1259"></span></p>
<p>Special thanks of course must go to our development and QA teams for delivering high quality, innovative software, on time, and to specification. A great start to a very exciting 2012!</p>
<p>You can download Privilege Guard 3.0 by <a href="http://www.avecto.com/your-account/downloads">visiting the downloads page</a>. If you aren’t already a customer, make sure you <a href="http://pages.avecto.com/register">register for a free evaluation</a>. As always, we are keen to hear your thoughts!</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.avecto.com/blog/2012/02/privilege-guard-3-0-is-here/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privilege Guard 3.0 Reporting Pack Preview</title>
		<link>http://www.avecto.com/blog/2011/12/privilege-guard-3-0-reporting-pack-preview/</link>
		<comments>http://www.avecto.com/blog/2011/12/privilege-guard-3-0-reporting-pack-preview/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 10:16:55 +0000</pubDate>
		<dc:creator>Mark Austin</dc:creator>
				<category><![CDATA[Event Forwarding]]></category>
		<category><![CDATA[Privilege Guard]]></category>
		<category><![CDATA[WinRM]]></category>

		<guid isPermaLink="false">http://www.avecto.com/blog/?p=1148</guid>
		<description><![CDATA[Last week I gave you a sneak preview of Privilege Guard 3.0, which will be released at the start of the New Year. We will also be releasing two new add on modules for Privilege Guard, and today I want &#8230; <a href="http://www.avecto.com/blog/2011/12/privilege-guard-3-0-reporting-pack-preview/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Last week I gave you a sneak preview of Privilege Guard 3.0, which will be released at the start of the New Year. We will also be releasing two new add on modules for Privilege Guard, and today I want to give you a preview of the Reporting Pack module.</p>
<p>A critical component of any privilege management solution is the audit trail, which can be used to generate compliance reports and fine tune policies. Privilege Guard logs a variety of events to the local application event log on each endpoint and these events can then be centrally collected using Microsoft Event Forwarding.</p>
<p>Event Forwarding uses Windows Remote Management (WinRM) and enables you to collect events from remote computers and store them in the forwarded event log of a central event collector server. It is an extremely scalable architecture, which is why the Privilege Guard Reporting Pack has been built around this technology. The new Privilege Guard Event Collector software is simply installed on one or more event collector servers and it will automatically aggregate Privilege Guard events and upload them to a SQL Server.<span id="more-1148"></span></p>
<p>The Privilege Guard Reporting Pack includes a rich set of preconfigured dashboards and reports for executed applications, elevated applications, blocked applications and discovered applications. The latter gives you a breakdown of the applications in your environment that require admin rights to run and those that only require standard user rights. The dashboards and reports all utilize SQL Reporting Services, which allows you to access the reports from a web browser.</p>
<p>Each dashboard provides information on the top 10 applications, a breakdown of applications by publisher and an activity timeline. The timeframe for a dashboard can be switched between 24 hours, 7 days, 30 days and 12 months, to allow recent activity or trends to be displayed. You can drilldown on the graphs within each dashboard to view detailed application reports. Reports can further be filtered on event type, user, computer, application details and date ranges.</p>
<div id="attachment_1201" class="wp-caption alignnone" style="width: 398px"><a href="http://www.avecto.com/blog/2011/12/privilege-guard-3-0-reporting-pack-preview/pgreportingdashboard/" rel="attachment wp-att-1201"><img class="size-full wp-image-1201   " title="Privilege Guard Reporting Dashboard" src="http://www.avecto.com/blog/wp-content/uploads/2011/12/PGReportingDashboard.jpg" alt="" width="388" height="397" /></a><p class="wp-caption-text">Privilege Guard Reporting Dashboard</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.avecto.com/blog/2011/12/privilege-guard-3-0-reporting-pack-preview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privilege Guard 3.0 Sneak Peek</title>
		<link>http://www.avecto.com/blog/2011/12/privilege-guard-3-0-sneak-peek/</link>
		<comments>http://www.avecto.com/blog/2011/12/privilege-guard-3-0-sneak-peek/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 16:32:51 +0000</pubDate>
		<dc:creator>Mark Austin</dc:creator>
				<category><![CDATA[Privilege Guard]]></category>

		<guid isPermaLink="false">http://www.avecto.com/blog/?p=1079</guid>
		<description><![CDATA[As we approach the end of 2011, the Avecto product development team have been busy putting the finishing touches to Privilege Guard 3.0, along with two brand new modules for Privilege Guard &#8211; the Privilege Guard Reporting Pack and the &#8230; <a href="http://www.avecto.com/blog/2011/12/privilege-guard-3-0-sneak-peek/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>As we approach the end of 2011, the Avecto product development team have been busy putting the finishing touches to Privilege Guard 3.0, along with two brand new modules for Privilege Guard &#8211; the Privilege Guard Reporting Pack and the Privilege Guard McAfee ePO Integration Pack. On the run up to Christmas we’ll be giving you a sneak preview of all this exciting new technology, which you can get your hands on at the start of the New Year.</p>
<p>First up is Privilege Guard 3.0, with a new look management console that is both striking to look at and wonderfully intuitive. As you move beyond the obvious visual enhancements, you will find full search capabilities, which allow you to quickly locate policy items and navigate to them with ease.<span id="more-1079"></span></p>
<div id="attachment_1084" class="wp-caption alignleft" style="width: 650px"><a href="http://www.avecto.com/blog/2011/12/privilege-guard-3-0-sneak-peek/pg30frontscreen/" rel="attachment wp-att-1084"><img class="size-large wp-image-1084" title="Privilege Guard 3.0 Management Console" src="http://www.avecto.com/blog/wp-content/uploads/2011/12/PG30FrontScreen-1024x767.png" alt="Privilege Guard 3.0 Management Console" width="640" height="479" /></a><p class="wp-caption-text">Privilege Guard 3.0 Management Console</p></div>
<div id="attachment_1087" class="wp-caption alignnone" style="width: 650px"><a href="http://www.avecto.com/blog/2011/12/privilege-guard-3-0-sneak-peek/pg30search/" rel="attachment wp-att-1087"><img class="size-large wp-image-1087" title="Privilege Guard 3.0 Search" src="http://www.avecto.com/blog/wp-content/uploads/2011/12/PG30Search-1024x767.png" alt="Privilege Guard 3.0 Search" width="640" height="479" /></a><p class="wp-caption-text">Privilege Guard 3.0 Search</p></div>
<p>As you dig deeper you will find many improvements to the core product. The new policy filters section makes it possible to restrict policies based on any combination of users and groups, computer names and IP addresses (including the ability to check remote desktop connections), time of day and expiry time.</p>
<div id="attachment_1083" class="wp-caption alignnone" style="width: 650px"><a href="http://www.avecto.com/blog/2011/12/privilege-guard-3-0-sneak-peek/pg30filters/" rel="attachment wp-att-1083"><img class="size-large wp-image-1083" title="Privilege Guard 3.0 Filters" src="http://www.avecto.com/blog/wp-content/uploads/2011/12/PG30Filters-1024x767.png" alt="Privilege Guard 3.0 Filters" width="640" height="479" /></a><p class="wp-caption-text">Privilege Guard 3.0 Filters</p></div>
<p>The comprehensive messaging system has always set the Privilege Guard solution apart from all other privilege management solutions when it comes to the end user experience. With beautifully rendered message previews, a new message designer and even more capabilities, the experience just got even better in version 3.0. You can now let departmental administrators authorize applications for users, or control and audit support desk personnel, who need to gain administrative access to a user’s desktop.</p>
<div id="attachment_1086" class="wp-caption alignnone" style="width: 650px"><a href="http://www.avecto.com/blog/2011/12/privilege-guard-3-0-sneak-peek/pg30messagepreview/" rel="attachment wp-att-1086"><img class="size-large wp-image-1086" title="Privilege Guard 3.0 Message Preview" src="http://www.avecto.com/blog/wp-content/uploads/2011/12/PG30MessagePreview-1024x767.png" alt="Privilege Guard 3.0 Message Preview" width="640" height="479" /></a><p class="wp-caption-text">Privilege Guard 3.0 Message Preview</p></div>
<div id="attachment_1085" class="wp-caption alignnone" style="width: 650px"><a href="http://www.avecto.com/blog/2011/12/privilege-guard-3-0-sneak-peek/pg30message/" rel="attachment wp-att-1085"><img class="size-large wp-image-1085" title="Privilege Guard 3.0 Message Design" src="http://www.avecto.com/blog/wp-content/uploads/2011/12/PG30Message-1024x767.png" alt="Privilege Guard 3.0 Message Design" width="640" height="479" /></a><p class="wp-caption-text">Privilege Guard 3.0 Message Design</p></div>
<p>We’ve also introduced more application validation options, including parent process checks, and the ability to limit child inheritance to a subset of applications, ensuring that Privilege Guard continues to be the most powerful and flexible privilege management solution on the market.</p>
<p>For shared workstation environments, Privilege Guard can be configured to enable standard users to unlock a workstation, an operation that would usually be restricted to local administrators.</p>
<p>Keep tuned to the Avecto blog over the coming days, as we preview the new Reporting Pack and the new McAfee ePO Integration Pack.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.avecto.com/blog/2011/12/privilege-guard-3-0-sneak-peek/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

