Microsoft Security Newsletter
Welcome to the Microsoft Security Newsletter - a monthly newsletter for IT professionals and developers bringing security news, guidance, updates, and community resources direct to your inbox. If you have suggestions or comments about the Microsoft Security Newsletter, please send us your feedback. To view an online version of this newsletter, please click here.

Viewpoint
Microsoft Is Committed to Network Access Control Interoperability  
By Mike Schutz, Group Product Manager, Security and Access Products, Microsoft Corporation
For the past two years, there has been much hype around the term "network access control". Read this article and learn how Microsoft is working with industry leaders across networking and security as well as collaborating with Cisco on interoperable architecture for Microsoft Network Access Protection (NAP) and Cisco Network Admission Control (NAC).

Top Stories
Cisco Systems Inc. and Microsoft Corp. are delivering on their previously stated commitment to provide customers and partners with clear guidance on how Cisco NAC and Microsoft NAP will interoperate. A technical white paper released by the two companies describes the architecture and provides details on how to integrate the embedded security capabilities of the Cisco network infrastructure with those of Windows Vista and the future version of Microsoft Windows Server, code-named "Longhorn."
BrowserShield, a research project from Microsoft Research’s Redmond lab, offers significant advances in collaring the malevolent forces that haunt the World Wide Web. Work on BrowserShield began in the spring of 2005, and the current project tackles the challenge of cleansing the dynamic content of a Web page (such as embedded JavaScript code) through script rewriting and vulnerability-driven filtering. Learn why the cliché “the best offense is a good defense” rings true with BrowserShield.
Microsoft Forefront Client Security provides unified virus and spyware protection for business desktops, laptops, and server operating systems that is easier to manage and control. Through simplified administration and integration with existing infrastructure, Forefront Client Security helps you protect your business with greater confidence and efficiency. Learn more about the product, watch the video demo, and sign up for the public beta.

Security Guidance
By Nathan Bigman, User Education Lead, ISA Server, Microsoft Corporation
Microsoft Internet Security and Acceleration (ISA) Server 2006 and ISA Server 2004 provide virtual private network (VPN) security functionality for roaming clients. Learn how, as part of this functionality, you can establish thorough control over newly connected clients, placing them in quarantine until they meet corporate connectivity standards.
Read this white paper for a detailed description of the components of the NAP architecture, how it works, and how it allows third-party software vendors and system integrators to create complete solutions for system health-validated network access. For a webcast version of this white paper, click here.
This white paper provides a detailed description of how Internet Protocol Security (IPsec) enforcement in the Network Access Protection platform works to provide system health validation and enforcement for IPsec-secured communication.
Read this white paper for a description of how to configure NAP health requirements and enforcement behavior using the Network Policy Server (NPS) in Windows Server "Longhorn."
Follow the instructions in this white paper to demonstrate IPsec enforcement in a test lab consisting of four computers.
Follow the instructions in this white paper to demonstrate VPN enforcement in a test lab consisting of four computers.
Follow the instructions in this white paper to demonstrate Dynamic Host Configuration Protocol (DHCP) enforcement in a test lab consisting of three computers.
Check out this blog and get the latest NAP news directly from the NAP engineering team at Microsoft.

This Month's Security Bulletins
Critical:
Important:
Moderate:

MVP Update
MVP of the Month: Rodrigo Immaginario  
Rodrigo Immaginario has been working in the field of computer science, and on infrastructure projects in particular, since 1994. In recent years, he has specialized in security solutions for the Microsoft environment and has worked on security-related projects with clients including the Commission of the Brazilian Army in Washington. Rodrigo possesses several certifications including MCSE:Security, MCSA:Security, MCSE (NT, W2K, W2K3), MCSA (W2K, W2K3), and MCT. He is currently the Manager of Technology for the Universidade de Vila Velha (UVV), where he recently coordinated a postgraduate course on .NET.
By Rodrigo Immaginario, Security MVP and Chief Information Officer, Universidade de Vila Velha
In today's environment, in which remote access, wireless networking, and the integration of several branches and distributed systems is a reality in most companies, it is important to know who your users are and what devices they are using to access your network. Learn about one way to address this problem using Server and Domain Isolation based on Microsoft Windows Internet Protocol security (IPsec) and Group Policy.

Partners with Expertise in Security Solutions
ManageSoft is a leading, privately-held provider of intelligent solutions that help enterprises deploy, secure, and manage their client software and computing infrastructures. ManageSoft's Security solution supports Microsoft NAP by helping specify remediation steps and automate corrective actions to issue compliant health certificate for network endpoints.
Together, Microsoft and its partners will develop a wide array of applications and end-to-end solutions to better serve customers. Find out more about the industry leaders who have announced their support for Network Access Protection, including vendors in areas such as client security, patch management, networking, and system integration. For information on how to become a NAP partner, send an inquiry to asknap@microsoft.com with "partner program" in the subject line.

Microsoft Product Lifecycle Information
Find information about your particular products on the Microsoft Product Lifecycle Web site.
See a List of Supported Service Packs: Microsoft provides free software updates for security and nonsecurity issues for all supported service packs.

Security Events and Training
Security is a common and ever-present concern for both users and developers. With MSDN Security Virtual Labs, quickly evaluate or learn how to secure applications, and optimize and automate security through a series of guided, hands-on labs which can be completed in 90 minutes or less. MSDN Virtual Labs do not require any installation and are available to you free and on demand.
By automating management, IT departments can reduce operational costs while increasing security. Use these resources to get in-depth information about identity and access management--the simplified, secure sharing of digital identities across security boundaries. Find out how to provide a secure environment for managing user identities, authentication methods, and access rights across an organization's internal and external users.

Upcoming Security Webcasts
Microsoft On Demand Security Webcasts
Support Webcast: Network Access Protection Platform Architecture
This webcast discusses the NAP platform architecture in Windows Server code-named "Longhorn" and in Windows Vista, the components of client architecture and of server architecture, and how NAP works for various enforcement methods.
Network Access Protection for Windows Server Code-Named "Longhorn" and Windows Vista Viruses, worms, and malicious software are costly disruptions to today’s business processes. Customers seek a flexible solution that allows them to enforce policies across varied connection scenarios, using the network infrastructure already in place. Listen to this webcast for an overview of the Network Access Protection framework of technologies and learn how NAP is a solution set that emphasizes policy-based network access.
Interactive Security Webcast Calendar
Upcoming security webcasts in a dynamic, interactive format.
For IT Professionals: TechNet Webcasts
User Account Control (Level 200)
Monday, September 18, 2006, 9:00-10:00 AM Pacific Time
Matthew Hester, TechNet Presenter, Microsoft Corporation
How Microsoft IT Defends Against Spam, Viruses, and E-Mail Attacks (Level 300)
Tuesday, September 19, 2006, 9:30-10:30 AM Pacific Time
Omesh Desai, Microsoft IT Systems Engineer, Microsoft Corporation
Enabling Trusted Communications and Health Policy Enforcement with Network Access Protection (Level 300)
Tuesday, September 19, 2006, 1:00-2:30 PM Pacific Time
Gene Ferioli, Program Manager, Microsoft Corporation
Agility Now (Part 03 of 10): Making Identity and Access Management a Reality with Successful Implementation
Wednesday, September 20, 2006, 9:30-11:00 AM Pacific Time
John Weston, TechNet speaker, Microsoft Corporation
Introduction to Terminal Services in Windows Server Code-Named "Longhorn"
Thursday, September 21, 2006, 1:00-2:30 PM Pacific Time
Alex Balcanquall, Technical Product Manager, Microsoft Corporation
How Microsoft IT Optimizes Client Security by Using Windows Vista (Level 300)
Tuesday, September 26, 2006, 9:30-10:30 AM Pacific Time
Andre Howard, Microsoft IT Technologist, Microsoft Corporation, and Ben Shy, Microsoft IT Engineer, Microsoft Corporation
Identity Management in Windows Server 2003 R2 Active Directory Federation Services (Level 200)
Friday, September 29, 2006, 9:00-10:30 AM Pacific Time
John Baker, TechNet Presenter, Microsoft Corporation
Agility Now (Part 06 of 10): Secure, Manageable Messaging (Level 200)
Wednesday, October 11, 2006, 9:30-11:00 AM Pacific Time
Harold Wong, Senior Technology Specialist, Microsoft Corporation
For Developers: MSDN Webcasts
Live From Redmond: ASP.NET: Security Tips & Tricks for ASP.NET Developers
Thursday, September 28, 2006, 9:00 AM Pacific Time
Joe Stagner, Program Manager, Web Community team, Microsoft Corporation

Security Newsletter
Volume 3, No. 9

September 2006
In This Issue:
Viewpoint
Top Stories
Security Guidance
This Month's Security Bulletins
MVP Update
Partners with Expertise in Security Solutions
Microsoft Product Lifecycle Information
Security Events and Training
Upcoming Security Webcasts
Security Program Guide
Learn Security On the Job
Learning Paths for Security - Microsoft Training References and Resources
Upcoming Chats
Network Access Protection in Windows Vista and Windows Server "Longhorn"
September 14, 2006, 2:30 PM Pacific Time
Windows Vista Group Policy - Updates and Troubleshooting
September 28, 2006, 10:00 AM Pacific Time
View a listing of upcoming technical chats
Free In-Person Events
Connect with experts at TechNet Security Briefings
Security Blogs
Michael Howard RSS
Eric Lippert RSS
Jesper Johansson RSS
Eric Fitzgerald RSS
Steve Lamb RSS
MSRC Blog RSS
ACE Team RSS
Jeff Jones RSS
Windows Vista Security RSS
Security Newsgroups
General Security issues/questions
Open with newsreader
Virus issues/questions 
Open with newsreader
ISA Server
Open with newsreader
Windows 2000: Security
Open with newsreader
Windows XP: Security Administration
Open with newsreader
SQL Server: Security
Open with newsreader
Windows Server 2003 option
Community Web Sites
IT Pro Security Community
Security Newsgroups
More related communities
Additional Security Resources
Security Help and Support for IT Professionals
New and Improved Microsoft TechNet Troubleshooting and Support Page
Microsoft Security Glossary
TechNet Security Web Site
MSDN Security Developer Center 
Sign-Up for the Microsoft Security Notification Service
Security Bulletin Search Page
Home Users: Protect Your PC
MCSE/MCSA: Security Certifications
Subscribe to TechNet
Register for TechNet Flash IT Newsletter
Subscribe to MSDN
© 2006 Microsoft Corporation. All rights reserved. Microsoft, MSDN, Outlook, Windows, Windows Server, and Windows Vista are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. All other trademarks are property of their respective owners.

Digital Signatures Help Make Microsoft Security Newsletters More Secure
To help increase your security, Microsoft will soon begin digitally signing all of its security newsletters with the Internet standard, Secure Multipurpose Internet Mail Extensions (S/MIME). This means that if you use Microsoft Outlook, or another full-featured e-mail program, you have an added assurance that the e-mail newsletter came from Microsoft and has not been tampered with. However, many Web-based e-mail programs and some other e-mail programs do not support digital signing with S/MIME. To learn more, please see how digital signatures help make Microsoft security newsletters more secure.

To cancel your subscription to this newsletter, reply to this message with the word UNSUBSCRIBE in the Subject line. You can also unsubscribe at http://www.microsoft.com/info/unsubscribe.htm. You can manage all your Microsoft.com communication preferences at this site.

Legal Information.

This newsletter was sent by the Microsoft Corporation
1 Microsoft Way
Redmond, Washington, USA
98052

Sign up for other newsletters | Unsubscribe | Update your profile
© 2006 Microsoft Corporation  Terms of Use | Trademarks | Privacy Statement
Microsoft