Home > Information Security Tips > Tech tips > Should you disable IE ESC, or manage it in Windows servers?
Security UK Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

TECH TIPS

Should you disable IE ESC, or manage it in Windows servers?


Neil Roiter
10.05.2009
Rating: --- (out of 5)


Security UK Tips and Expert Advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Microsoft introduced Internet Explorer Enhanced Security Configuration (IE ESC) in Windows Server 2003 (it's in Windows Server 2008 as well). IE ESC follows the "secure by default" mantra and locks down IE security settings to limit server exposure to Web attack. Yet, if you do a Google search for "Internet Explorer Enhanced Security Configuration," 11 of the first 20 returns are to articles telling you how to disable IE ESC.

In this tip, we'll look at why some admins think IE ESC is more trouble than it's worth and why you might want to stick with it despite some of the hassles associated with it.

The issue with IE ESC is the classic balance of utility vs. security. IE ESC strengthens Microsoft Windows server security by preventing the insecure, but too uncommon practice of browsing the Web on a server. But, the strict configurations lead many administrators to disable IE ESC. IE ESC's strong security settings can interfere with the normal operation of legitimate websites, applications and Universal Naming Convention (UNC) paths to intranet resources, such as scripts and executable files. It doesn't prevent you from going to the sites, but does block most file downloads, and prevents running multimedia, scripts and ActiveX components.

The Microsoft solution is to allow explicit website exceptions in IE trusted zones. However, in all but the simplest environments, you'll need to set up a process for identifying and nominating exceptions, which may mean working with user groups in some cases, and periodically updating them as needed -- yet another chore for overworked IT admins.

And yet, you will be less secure if you disable IE ESC. The rationale may be that, as an admin, you know what you're doing and you'll be very, very careful and only go to trusted websites. The question is: How many people have admin privileges on the server, and are they all as cautious as you?

For simple use cases such as file servers and domain controllers, said John Savill, advisory architect for EMC's Microsoft consulting practice and 10-time Microsoft MVP, there are only a few sites, such as MS Update, the hardware vendor site and the antivirus update you need to consider as trusted exceptions. You can whittle that down further if you manage AV updates centrally and use Windows Server Update Services or System Center Configuration Manager so the server doesn't need an Internet connection to Microsoft for updates.

What's more, while most hardware vendors will use ActiveX to scan a server for driver versions and install updates, that's just one more potential security exposure or another set of exceptions to administer in IE ESC.

"It comes down to laziness if admins can't be bothered to log off, access what they need by a client and copy files to the server," Savill said.

Terminal services create an interesting case, in which you may decide to enable IE ESC for admins and disable it for users. Typically, end users don't have direct access to the server. But enabling IE ESC on terminal servers could cause a lot of headaches and help desk calls if Web apps stop working properly, since the users are accessing the application directly via Windows Server. Savill said it's possible, but difficult to enable IE ESC for admins and disable it for users in Windows Server 2003. It's difficult to distinguish between admins and users, he said, and requires a lot of difficult manual work with Group Policies.

However, if you use Windows Server 2008, it's a simple selection in the Server Manager GUI.

If terminal services are only being used for a single app, say an ERP program, you may want to exclude the browser altogether, he said. If they need Internet access, you may need to accept the risk, because unlike administrators, they have limited user privileges.

"If it's their main desktop, you may have issues with restricting them if they need Internet access," Savill said. "You may have problems: 'How much can I really lock this thing down?'"

More complex servers require careful and somewhat detailed management, especially if you are managing IE ESC on multiple servers, some with different trusted website requirements. Rather than configure IE ESC on each machine, Savill said, use Group Policy in Active Directory to centrally control settings, both for changes and new installations.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.co.UK.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Tech tips
Code complexity analysis: How to keep it simple
How to use Windows XP Mode in Windows 7
Understand role-based access control in Microsoft Exchange 2010
Avoid common Web application firewall configuration errors
SQL injection detection tools and prevention strategies
Cross-site scripting explained: How to prevent attacks
How to automate and apply Microsoft Windows 7 AppLocker rules
How to use Microsoft Windows 7 AppLocker for whitelisting applications
Scanning with N-Stalker offers basic Web application security assessment
Microsoft Windows 7 DirectAccess pros and cons

Platform and OS Security Management
Microsoft issues advisory on new IE security vulnerability
Microsoft patches SMB flaws, Hyper-V problem in big update
Microsoft blue screen affecting few corporate PCs
Microsoft to fix 26 flaws in Windows, Office
Thin-client technologies surge thanks to easier security, says Deloitte
Microsoft issues critical security update, blocks IE 6 attacks
How to use Windows XP Mode in Windows 7
Microsoft to patch single Windows 2000 vulnerability
How to prevent memory dump attacks
Microsoft gives Internet Explorer a major security overhaul

Web Application Security
Social networking risks, benefits for enterprises weighed by RSA panel
How to prevent Adobe hacks from affecting your organisation
Securing Web applications with Web application firewalls
CISOs take measured steps to reduce social media risks
Google to pay for Chrome browser vulnerabilities
Facebook, McAfee partner to fix social network security issues
PDF attack code complicates security analysis, skirts detection
Annual security reports offer some hope
Firefox, Opera, Safari browsers top list of high risk software
Active PDF attacks target Reader, Acrobat zero-day vulnerability

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Serious Organized Crime Agency  (SearchSecurityUK.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



UK Data Security Solutions: Data Privacy, Identity Theft, Data Loss
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts