59
Group Policy that applies to that new server role in this case would also need to be created that sets
the SQL Services service to
Automatic.
Note:
If additional services are enabled, they may in turn have dependencies that require further
services. All of the services needed for a specific server role are added in the policy for the server role
that it performs within the network.
The system services settings can be configured in Windows Server 2003 at the following location
within the Group Policy Object Editor:
Computer Configuration\Windows Settings\Security Settings\System Services\
This section provides details on the prescribed security options for the three environments defined in
this guide for the MSBP.
Alerter
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
Alerter Disabled Disabled Disabled Disabled
The
Alerter
system service notifies selected users and computers of administrative alerts. Use the
Alerter service to send alert messages to specified users that are connected on the network. To ensure
greater security in the three environments defined in this guide, disable this service. If the service is
stopped, programs that use administrative alerts will not receive them.
Note:
Disabling this service can break functionality in uninterruptible power supply
(UPS) alert messages systems.
Application Layer Gateway Service
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
ALG Manual Disabled Disabled Disabled
The
Application Layer Gateway Service
system service is a subcomponent of the Internet Connection
Sharing (ICS) / Internet Connection Firewall (ICF) service that provides support for independent
software vendors (ISVs) to write protocol plug-ins that allow their proprietary network protocols to pass
through the firewall and work behind ICS. To ensure greater security in the three environments
defined in this guide and to prevent unauthorized computers from acting as Internet gateways,
disable this system service.
Application Management
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
AppMgmt Manual
Disabled Disabled Disabled
The
Application Management
system service provides software installation services, such as Assign,
Publish, and Remove. This service processes requests to enumerate, install, and remove programs
deployed via a corporate network. When
Add/Remove Programs
is clicked
on a computer joined to
a domain, the program calls this service to retrieve the list deployed programs. Most corporations do
not use this system service on servers; instead, they use automated software delivery applications to
distribute software packages. For these reasons, disable this service on the baseline server policy.
ASP .NET State Service