* Why you should take a look at DirectoryLockdown for your Active Directory environment
endif; ?>My good friends at NetPro Computing in Phoenix have just released Version 3 of DirectoryLockdown for Active Directory, a tool that could be very useful to you.
It’s a tool designed to “watch the watchers” or “guard against the guards” – the directory administrators. Now if that’s you, please listen before you get all huffy and fire off a nasty e-mail to me. Yes, the tool is designed to protect against malicious damage. But it also protects against inadvertent damage – and that’s far more likely in my experience. Additionally, it gives you the audit trail and documentation you need to prove that you’ve done what you say you’ve done, no more and certainly no less.
Identity and the directories that are the repositories for identity information are quickly coming under control of government regulatory bodies all over the world. It’s very important, if you wish to maintain your livelihood and your freedom from incarceration, that not only can you document what happens to the identity information under your control but also that you take the necessary steps to protect that information from accidental and deliberate corruption.
DirectoryLockdown is the only security solution available for Windows 2000 and Windows Server 2003 that monitors the Configuration and Schema Naming Contexts (NC) of Active Directory for unauthorized changes. DirectoryLockdown protects against denial-of-service issues, security breaches, and reliability and service interruptions caused by unauthorized changes to the Configuration and Schema NCs. Used in conjunction with strict change control policies, DirectoryLockdown ensures protection against potentially damaging infrastructure changes and security breaches.
DirectoryLockdown is what changes NetPro’s Active Directory Lifecycle Suite into the new “Secure Active Directory Lifecycle Suite.” This is almost a “must-have” tool for anyone in a regulated industry as well as for those with fairly large, delegated administrative infrastructures.
While DirectoryLockdown was originally designed to protect against an inherent flaw in Windows 2000 Server Active Directory Forests (see editorial link below) – which has been partially mitigated with the release of Windows Server 2003 – the risks and damage potential of deliberate or inadvertent directory corruption should be enough to at least draw you to examine DirectoryLockdown.
NetPro’s Christine McDermott also wants to remind us that the Directory Experts Conference on Active Directory is coming up in late March in Washington, D.C. It’s not too early to plan on being there – not only to hear more about NetPro’s offerings but also to hear from all of Microsoft’s directory experts. Details at: https://www.netpro.com/events/decadspring04/index.cfm .




