Microsoft Security Newsletter
Welcome to the Microsoft Security Newsletter - a monthly newsletter for IT professionals and developers bringing security news, guidance, updates, and community resources direct to your inbox. If you have suggestions or comments about the Microsoft Security Newsletter, please send us your feedback. To view an online version of this newsletter, please click here. If you would like to receive less technical security news, guidance and updates, please subscribe to the Microsoft Security for Home Computer Users Newsletter.

Viewpoint
The Evolution of Identity  
By Michael Atalla, Group Product Manager, Microsoft Corporation
Identity is at the crux of the security challenges we face in responding to individuals' and organizations' imperative to connect. The way you address this challenge can determine how quickly your organization can realize pervasive, seamless connectivity to applications, information, and services. Take a measured approach and begin by learning more about the five key areas of identity.

Top Stories
At RSA Conference 2007, top executives from Microsoft outlined a vision for secure and easy "anywhere access" and a commitment to working with the industry to evolve networks, protection, and identity in an effort to achieve that vision for customers. Microsoft also announced a series of product developments, initiatives, and industry alliances including the upcoming availability of Microsoft Identity Lifecycle Manager 2007, the public beta of Microsoft Forefront Server Security Management Console, support for Extended Validation SSL certificates in Microsoft Internet Explorer 7, and new collaboration with industry partners to help combat phishing. Visit the Microsoft at RSA Web site for details and links to conference videos.
Microsoft Identity Lifecycle Manager (ILM) 2007 simplifies managing the life cycle of a user's digital identity by providing identity synchronization, certificate management, and user provisioning from a single solution. Learn more about this new product and the Microsoft identity lifecycle management vision by visiting the Microsoft ILM 2007 Web site and trying the product demo.
The U.S. Energy Policy Act of 2005, passed by the U.S. Congress July 2005, extended Daylight Saving Time (DST) in the United States. As a result, beginning in 2007, DST will start three weeks earlier (on March 11, 2007) and end one week later (on November 4, 2007), resulting in a new DST period that is four weeks longer than previously observed. Read this article for more information on the impact of this "extended DST period" and for recommended preparation steps.
The Fundamental Computer Investigation Guide for Windows provides U.S.-based IT professionals with information about the best practices and tools they need to investigate suspicious use of their organizations' computers and networks. The guide helps customers determine when to turn an investigation over to law enforcement and provides guidance on how to collect, preserve, analyze, and report on key data they uncover in their investigations -- using methods that will stand up in a court of law.
An array of new and in-development technologies is helping IT and security staffers automate security in ways that weren't possible a few years ago. As you consider your next security investments, keep an eye on these emerging technologies: USB tokens, built-in biometrics, self-aware Web applications, encrypted hard drives, and built-in mobile device protection.

Security Guidance
This article provides information to help you install Windows Rights Management Services (RMS) with Service Pack 2 (SP2) in an organization with an existing RMS deployment. Organizations that are deploying RMS for the first time can deploy RMS with SP2 by following the guidelines in Planning an RMS Deployment and Deploying an RMS System in this same documentation collection.
This collection of technical papers is designed to help organizations understand identity and access management issues and related solutions that can be achieved with Microsoft technologies in heterogeneous IT environments. Several code samples and configuration files accompany each paper.
Certificate Services is the essential component of a Windows-based public key infrastructure (PKI). If you deploy an application that is PKI-aware and you want to make use of the security capabilities offered by PKI, you will need Certificate Services. Read this article to learn how Certificate Services covers the request, issuance, enrollment, publication, maintenance, revocation, and expiration of certificates, and how it provides information assurance, meaning that measures are taken to safeguard aspects of information and information systems.
Microsoft Internet Security and Acceleration (ISA) Server 2006 provides controlled secure access between networks, and serves as a Web caching proxy providing fast Web response and offload capabilities, as well as secure Web publishing for remote access. Its multilayered architecture and advanced policy engine provide detailed control of the balance between the level of security you need and the resources that are required. This article provides guidelines for deploying ISA Server with best performance and adequate capacity.
This white paper details how to use ISA Server as an IPsec gateway or proxy within a Server and Domain Isolation solution, from preparation to installation and configuration, and includes best practices to keep in mind during the process. It is written for enterprise technical decision makers, IT administrators, and architects who want to gain a better understanding of the processes and implementation of ISA Server as an IPsec gateway or proxy to extend IPsec interoperability.
Whale's Intelligent Application Gateway is a comprehensive and customizable system based on a Secure Sockets Layer (SSL) virtual private network (VPN) connectivity platform to manage and secure application and network resource access. Read this article and learn more about the Intelligent Application Gateway, which consists of four elements: a SSL VPN platform, endpoint security, application security, and a unified policy management framework.
Learn how the Active Directory Federation Services (ADFS) solution in Windows Server 2003 R2 helps administrators enable organizations to share a user's identity information securely by addressing some of the commonly faced challenges.

This Month's Security Bulletins
Critical:
Important:

MVP Update
MVP of the Month: Rand Morimoto   
Microsoft MVP Rand Morimoto has been in the computer industry for more than 30 years and is the president of Convergent Computing, an information technology and security consulting firm recognized by Microsoft as "Partner of the Year – West Region" in 2006. A Ph.D. and Microsoft Certified Systems Engineer (MCSE), Rand is the author of a couple dozen books from Sams Publishing, including Windows 2003 Unleashed and Exchange 2007 Unleashed. Rand is also an advisor to the White House on Cyber-Security. He meets with the President of the United States every two weeks, and is the lead diplomat for the U.S. State Department, creating international consensus on Cyber-terrorism.
By Rand Morimoto, Ph.D., Microsoft MVP, MCSE
In this article, Microsoft MVP Rand Morimoto describes how his consulting group designed and implemented a Windows Rights Management Services (RMS) solution for a large corporate customer seeking a method to protect "sensitive" e-mails from being forwarded outside the organization.

Microsoft Product Lifecycle Information
Find information about your particular products on the Microsoft Product Lifecycle Web site.
See a List of Supported Service Packs: Microsoft provides free software updates for security and nonsecurity issues for all supported service packs.

Security Events and Training
It's more than what you learn. It's the impact you make when you get back to the office. Attend Tech-Ed 2007, June 4-8, in Orlando, FL, to learn how to more proactively and effectively protect your organization from attacks. Get in-depth information and advice from some of the best Microsoft and third-party security experts in the industry to take back and implement in your own organization. Register by April 6 and save US$200.
If you want to build a comprehensive SSL-secured access platform that will help you extend and manage the reach of your information systems, Check out these webcasts and other resources for in-depth guidance on edge solutions including ISA Server 2006 and the Whale Intelligent Application Gateway (IAG).
Get ready for Windows Vista, the new Microsoft desktop operating system. During these free webcasts, learn more about key Windows Vista product features and explore deployment, security, management, and productivity. See how advancements in security and reliability, along with operational efficiencies, can give you and your users confidence in your organization's PCs. During live webcasts, get answers to your Windows Vista during the question and answer session. Also, take part in our Windows Vista virtual labs and apply what you've learned in a guided, hands-on environment.

Upcoming Security Webcasts
Friday, February 23, 10:00 AM Pacific Time
Friday, February 16, 1:00 PM Pacific Time
This webcast will provide an overview of information on Microsoft products and resources available to help businesses prepare for the U.S. government-mandated change to Daylight Saving Time. Microsoft Information Technology will share the results of the company’s own internal testing and approach to updating systems.
Microsoft On-Demand Security Webcasts
Bill Gates and Craig Mundie Keynote at RSA Conference 2007: Advancing Trust in Today’s Connected World
In this video from RSA Conference 2007, Microsoft Chairman Bill Gates and Chief Research & Strategy Officer Craig Mundie engage in an onstage dialogue about the challenges created for the security industry by pervasive Internet connectivity, and what Microsoft and the rest of the industry must do to protect customers and help them use technology to its fullest potential.
Microsoft Vision and Strategy for Identity and Access Management
Identity and access (IDA) in connected systems has gone beyond a technical concern and become a top business issue as organizations look to reduce security risk, decrease operational costs, satisfy regulatory requirements, and deepen their electronic relationships with customers and partners. In this session, learn about Microsoft vision for identity and access technology, including the evolution of Active Directory (AD), Microsoft Identity Integration Server (MIIS), Windows CardSpace, and CLM.
Identity and Access Webcasts and Virtual Labs
This webcast and virtual lab series is designed to educate technical decision makers and IT professionals about Microsoft IDA solution areas centered around Windows RMS, ADFS, MIIS, CLM, and AD.
Interactive Security Webcast Calendar
Join upcoming security webcasts in a dynamic, interactive format.
For IT Professionals: TechNet Webcasts
How to Define and Configure Endpoint Security Policies with the Intelligent Application Gateway (Level 300)
Tuesday, February 20, 9:00 AM Pacific Time
Uri Lichtenfeld, Whale-Director, Whale Communications, Inc.
Overview of Microsoft Edge Secure Access Technologies (Level 300)
Wednesday, February 21, 9:00 - 10:00 AM Pacific Time
Uri Lichtenfeld, Whale-Director, Whale Communications, Inc.
24 Hours of Exchange Server 2007 (Part 10 of 24): Recipient Management, Policies, and Permissions (Level 200)
Wednesday, February 21, 11:30 AM - 12:30 PM Pacific Time
Harold Wong, Senior Technology Specialist, Microsoft Corporation
Securing Remote Access to SharePoint Products and Technologies, Exchange Server, and Microsoft Dynamics (Level 300)
Thursday, February 22, 9:00 - 10:00 AM Pacific Time
Uri Lichtenfeld, Whale-Director, Whale Communications, Inc.
Providing Comprehensive Partner and Remote Worker Access with Secure Extranets (Level 300)
Friday, February 23, 9:00 -10:00 AM Pacific Time
Uri Lichtenfeld, Whale-Director, Whale Communications, Inc.
24 Hours of Exchange Server 2007 (Part 11 of 24): Messaging Policies and Compliance (Level 200)
Friday, February 23, 11:30 AM - 12:30 PM Pacific Time
Harold Wong, Senior Technology Specialist, Microsoft Corporation
Identity and Access Solutions in Windows Server "Longhorn" (Level 300)
Tuesday, February 27, 11:30 AM Pacific Time
Laura Robinson, Technical Solution Provider (TSP) – Directory and Identity, Microsoft Corporation
Configuring Certificate Lifecycle Manager (Level 200)
Tuesday, February 27, 1:00 PM Pacific Time
Jack Kabat, Program Manager, Microsoft Corporation
24 Hours of Exchange Server 2007 (Part 12 of 24): Configuring Edge Transport Servers (Level 200)
Wednesday, February 28, 11:30 AM - 12:30 PM Pacific Time
Harold Wong, Senior Technology Specialist, Microsoft Corporation
Deploying Internet Protocol Security (IPsec) with Windows Vista (Level 200)
Wednesday, February 28, 1:00 PM Pacific Time
Chris Avis, TechNet Presenter, Microsoft Corporation
Best Practices for Maintaining Windows Rights Management Services (RMS) (Level 100)
Thursday, March 1, 11:00 AM Pacific Time
Tim Upton, President, Titus
24 Hours of Exchange Server 2007 (Part 13 of 24): Maintaining Anti-Spam Systems (Level 200)
Friday, March 2, 11:30 AM Pacific Time
Harold Wong, Senior Technology Specialist, Microsoft Corporation
24 Hours of Exchange Server 2007 (Part 14 of 24): Maintaining Antivirus (Level 200)
Wednesday, March 7, 11:30 AM Pacific Time
Harold Wong, Senior Technology Specialist, Microsoft Corporation
24 Hours of Exchange Server 2007 (Part 15 of 24): Using Internet Security and Acceleration (ISA) Server 2006 for Secure Exchange Server Publishing (Level 200)
Friday, March 09, 2007, 11:30 AM Pacific Time
Harold Wong, Senior Technology Specialist, Microsoft Corporation
Exchange Server 2007 Guided Labcast Series (Part 5 of 8): Remote Client Access with Exchange Server 2007 (Level 200)
Monday, March 12, 11:30 AM Pacific Time
Harold Wong, Senior Technology Specialist, Microsoft Corporation
Information About Microsoft March Security Bulletins (Level 200)
Wednesday, March 14, 11:00 AM Pacific Time
Christopher Budd, CISA, CISM, CISSP, ISSMP Security Program Manager, PSS Security, Microsoft Corporation and Mike Reavey, Lead Security Program Manager, Microsoft Corporation
24 Hours of Exchange Server 2007 (Part 16 of 24): Outlook Web Access in Exchange Server 2007 (Level 200)
Wednesday, March 14, 11:30 AM Pacific Time
Harold Wong, Senior Technology Specialist, Microsoft Corporation
For Developers: MSDN Webcasts
Authentication and Authorization with ASP.NET 2.0 (Level 200)
Tuesday, February 20, 11:00 AM Pacific Time
Dominick Baier, Microsoft MVP, Least Privilege
Live from Redmond: Best Practices: A Look at Developer ASP.NET AJAX Security Mistakes
Thursday, February 22, 9:00 AM Pacific Time
Caleb Sima, Co-founder and CTO, SPI Dynamics; Billy Hoffman, Lead Security Researcher, SPI Dynamics; and Joe Stagner, Program Manager, Web Community team
Creating Intranet Applications That Respect Protected Mode
Thursday, February 22, 10:00 AM Pacific Time
Introduction to the Authentication and Membership Controls of ASP.NET 2.0 (Level 300)
Friday, February 23, 1:00 PM Pacific Time
Bill Sheldon, Principal Engineer, InterKnowlogy
Managing PHP and PHP Applications with Internet Information Services (Level 200)
Wednesday, February 28, 10:00 AM Pacific Time
Drew Robbins, Developer Evangelist, Microsoft Corporation
Customizing ASP.NET 2.0 Authentication and Membership (Level 300)
Friday, March 2, 1:00 PM Pacific Time
Bill Sheldon, Principal Engineer, InterKnowlogy
Using Code Access Security and Partial Trust with ASP.NET (Level 200)
Tuesday, March 6, 10:00 AM Pacific Time
Dominick Baier, Microsoft MVP, Least Privilege

Security Newsletter
Volume 4, No. 2

February 2007
In This Issue:
Viewpoint
Top Stories
Security Guidance
This Month's Security Bulletins
MVP Update
Microsoft Product Lifecycle Information
Security Events and Training
Upcoming Security Webcasts
Security Program Guide
Learn Security On the Job
Learning Paths for Security - Microsoft Training References and Resources
Upcoming Chats
View a listing of upcoming technical chats
Free In-Person Events
Connect with experts at TechNet Security Briefings
Security Blogs
Michael Howard RSS
Eric Lippert RSS
Eric Fitzgerald RSS
Steve Lamb RSS
MSRC Blog RSS
ACE Team RSS
Jeff Jones RSS
Windows Vista Security RSS
User Account Control Team RSS
Solution Accelerators - Security & Compliance RSS
Security Newsgroups
General Security issues/questions
Open with newsreader
Virus issues/questions 
Open with newsreader
ISA Server
Open with newsreader
Windows 2000: Security
Open with newsreader
Windows XP: Security Administration
Open with newsreader
SQL Server: Security
Open with newsreader
Windows Server: Security
Open with newsreader
Other Security Newsgroups
Community Web Sites
IT Pro Security Community
Security Newsgroups
Related Communities
Additional Security Resources
Security Help and Support for IT Professionals
TechNet Troubleshooting and Support Page
Microsoft Security Glossary
TechNet Security Center
MSDN Security Developer Center 
Midsize Business Security Center
Sign-Up for the Microsoft Security Notification Service
Security Bulletin Search Page
Home Users: Protect Your PC
MCSE/MCSA: Security Certifications
Subscribe to TechNet
Register for TechNet Flash IT Newsletter
Subscribe to MSDN
© 2007 Microsoft Corporation. All rights reserved. Microsoft, Active Directory, Microsoft Dynamics, Forefront, Internet Explorer, MSDN, Outlook, SharePoint, Windows, Windows CardSpace, Windows Server, and Windows Vista are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. The names of actual companies and products mentioned herein may be the trademarks of their respective owners.

To cancel your subscription to this newsletter, reply to this message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe at http://www.microsoft.com/info/unsubscribe.htm. You can manage all your Microsoft.com communication preferences at this site.

Legal Information.

This newsletter was sent by the Microsoft Corporation
1 Microsoft Way
Redmond, Washington, USA
98052

Sign up for other newsletters | Unsubscribe | Update your profile
© 2007 Microsoft Corporation  Terms of Use | Trademarks | Privacy Statement
Microsoft