Don’t hold your breath for Network Access Protection

Opinion
Nov 22, 20043 mins

* When will we see Network Access Protection in the Windows Server 2003 update?

Alert reader Mike Davis points out that in last week’s look at R2, the Windows Server 2003 update that’s due out next year, I neglected to mention one new feature that he’s especially looking forward to – Network Access Protection (NAP).

NAP is a policy enforcement platform that will be built into the Microsoft Windows operating system to allow network managers to set policies (for example, operating system and anti-virus update policies) that will restrict clients from accessing a network until the clients can prove policy compliance. It’s something all network managers should be looking forward to. But I don’t think it will be out in time for R2’s projected ship date of late 2005.

As Network World’s Microsoft beat reporter John Fontana reported in July (https://www.nwfusion.com/news/2004/0713msnap.html), NAP was being readied for inclusion in R2 in part to catch up with the Cisco offering of Network Admission Control (NAC), which was intended to do the same thing. Fontana noted that, although a plethora of partners for NAP were announced, Cisco was conspicuous by its absence.

Then, late last month, Microsoft and Cisco caught many off guard (but, for some reason, generated little press coverage) when they announced their intention to work together to integrate the two separate and largely incompatible technologies – NAP and NAC -for security-policy enforcement on the desktop.

While this was great news for security vendors that thought they might have to write two completely different versions of their products, as well as for network managers who thought they would be forced to choose between the two competing technologies, it did come at a price. And that price was a delay in shipping the policy enforcement engine that’s at the heart of NAP (and NAC, for that matter). While it may become a special release add-on to Windows Server 2003 sometime in 2006 (or even 2007), it’s more likely we won’t see it until the next server operating system (the one codenamed “Longhorn”), slated for late 2007 or possibly in 2008. Sorry, Mike.

There won’t be a second Windows Networking newsletter this week as we all take a break to celebrate the American Thanksgiving. For those of you who feel the need to read more about the Redmond behemoth, let me suggest you take a gander at the new Web log (https://radio.weblogs.com/0141875/2004/11/08.html) started by Active Directory eminence grise Kim Cameron. He’s the guy who deserves all the credit (or all the blame, depending on your point of view) for Microsoft Identity Information Server (MIIS). See you next week.