securing windows 7 32/64 bit in a domain environment

Firestrider

New member
Hey I need your guys' sugguestions on what to do to secure windows 7 in a domain environment

what we've done so far is set most people to a standard user, set UAC to the second notch from the top, have DEP enabled for third party programs, have the default policy set in windows firewall advanced (is this controlled by sysadmin?), disabled fast user switching, and have a daily scan antivirus with central console and biweekly reports emailed (symantec endpoint).

Of course we try to keep all software up to date with separate updaters (like flash and acrobat) and windows updates through WSUS. IE8 is also in protected mode. Is there anything else we can do?
 

My Computer

Computer Manufacturer/Model Number
Intel WBIBX10J
OS
Linux (Debian, Android)
CPU
Intel Core i7 860
Motherboard
Intel DP55WB
Memory
2x 2GB Kingston DDR3-1333
Graphics Card(s)
AMD Radeon HD 5750
Sound Card
Realtek ALC888
Monitor(s) Displays
2x Dell Inc. E248WFP
Screen Resolution
3840x1200
Hard Drives
Intel X25-V
Samsung HD103SJ
PSU
Corsair CX400
Case
Silverstone GD05
Cooling
Stock
Keyboard
Dell Inc. Bluetooth Wireless
Internet Speed
30 Mbps
Hey I need your guys' sugguestions on what to do to secure windows 7 in a domain environment

what we've done so far is set most people to a standard user, set UAC to the second notch from the top, have DEP enabled for third party programs, have the default policy set in windows firewall advanced (is this controlled by sysadmin?), disabled fast user switching, and have a daily scan antivirus with central console and biweekly reports emailed (symantec endpoint).

Of course we try to keep all software up to date with separate updaters (like flash and acrobat) and windows updates through WSUS. IE8 is also in protected mode. Is there anything else we can do?

I would hope that you have someone MCSE certified handling the set up of this domain. That person should be able to handle it without a problem. If it is security you are worried about, find someone with a CISSP certification.
 

My Computer

OS
Windows 7 Home Premium x64
CPU
Intel Core 2 Quad Q9450 @ 3.2GHz
Motherboard
Asus P5Q PRO Turbo
Memory
4GB DDR2-800
Graphics Card(s)
MSI Radeon HD 5850
Sound Card
Creative Labs Audigy2 ZS
Monitor(s) Displays
Samsung 225BW
Hard Drives
(2) 1TB Samsung F1, (2) 1.5TB Samsung F2, 1TB Samsung F2, 2TB Samsung F3
PSU
Corsair HX650
Case
Antec Nine Hundred
Really I'm just looking for what can be done on workstations and laptops and implemented in an operating system image, as I only work as help desk support. Anything that needs to be done by group policy I can ask our system administrator.
 

My Computer

Computer Manufacturer/Model Number
Intel WBIBX10J
OS
Linux (Debian, Android)
CPU
Intel Core i7 860
Motherboard
Intel DP55WB
Memory
2x 2GB Kingston DDR3-1333
Graphics Card(s)
AMD Radeon HD 5750
Sound Card
Realtek ALC888
Monitor(s) Displays
2x Dell Inc. E248WFP
Screen Resolution
3840x1200
Hard Drives
Intel X25-V
Samsung HD103SJ
PSU
Corsair CX400
Case
Silverstone GD05
Cooling
Stock
Keyboard
Dell Inc. Bluetooth Wireless
Internet Speed
30 Mbps
Back
Top