Microsoft to Revamp Windows Security

Microsoft to Revamp Windows Security

Written By
Dennis Fisher
Dennis Fisher
Nov 24, 2003
3 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Microsoft Corp. is preparing a series of major changes to the security capabilities in the Windows client and server platforms, and they will further lock down the companys flagship operating systems.

In separate service packs due over the next six months, the Redmond, Wash., software developer plans to add several security features to Windows XP and Windows Server 2003, according to company officials here at Comdex last week. Microsoft also plans to harden the client by turning off more services by default.

The biggest change will be in the server product, which will get a feature that can prevent unsecured machines from connecting to corporate networks.

The changes result from discussions that Microsoft executives have been having with customers about ways to improve the security of the companys products.

The modifications wont stop with Windows, according to officials. Microsoft plans to add new security features to other products, including SQL Server, in the coming months, they said.

Service Pack 1 for Windows Server 2003, which is due to enter beta testing in the early part of next year, will include a function to check every device attempting to connect to the network.

The server will query the security configuration of the device and try to confirm that anti-virus software is running and that current patches are installed. If discrepancies are found, the software will notify the user and offer instructions on correcting the problems.

Administrators will have the ability to define companywide policies on what security is required on client devices.

All this is intended to prevent cyber-attacks and other breaches and is an extension of the overall change in the way Microsoft officials and engineers think about security—a process that began almost two years ago when the company launched its Trustworthy Computing initiative. In addition to working to write more secure code, the company is working on other ways to make its software more difficult to attack.

“This is a beginning—something that will ultimately engender a new generation of secure software,” said Jonathan Perera, senior director in the Security Business Unit at Microsoft. “We have to take a wide range of approaches. The most important thing Microsoft can do is improve the base-line security of our software. Were thinking that through at the design stage at a far greater level.”

The quarantine feature in Windows Server 2003 reflects a trend in the security industry at large. Several companies sell stand-alone solutions that perform this function, and Cisco Systems Inc. last week announced it will include similar functionality in some of its routers next year.

Windows XP will also get security upgrades, courtesy of Service Pack 2, which should be in beta by the end of the year, according to Microsoft officials.

Most of the changes will concern ICF (Internet Connection Firewall), which is a part of XP. The firewall will be enabled by default in the new service pack, and Microsoft plans to make ICF more like a corporate firewall than a personal one.

Administrators will have the ability to manage all ICFs in their organization from a central location. Customers will also have the option of running ICF in tandem with other firewalls, something that wasnt possible before.

Microsoft customers say that the company seems to be headed in the right direction with most of these changes and updates but that there is still plenty of room for improvement.

“The proposed solution of using a denied log-on to the network is a little late in the [graphical identification and authentication] process. If this occurs after the user provides credentials and logs in, thats bad,” said Mark Deason, director of IT at Silverside Equipment Inc., in Reno, Nev.

“Microsoft has some so-so tools already. If they were integrated better together, like [Software Update Services] and Automatic Updates, with a watchdog service before the system goes online, that could be quite powerful to help promote change,” Deason said.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.