Windows 7 Security: Helping Enable the Mobile Workforce

Along with 17,000+ other security- minded professionals, I’m at RSA in San Francisco this week. For those who are not familiar with the RSA Conference, it’s the premier information security conference of the year. It attracts the best and brightest security folks from around the world. In addition, it is a great place to keep up with what’s going on in the information security marketplace. I’m at RSA to not only see what’s going on in the industry, but to also talk about some of the cool new security features in Windows 7.

We’re really excited about Windows 7’s new security features. This next OS is built upon the proven security technologies in Windows Vista and provides a fundamentally secure computing platform. We not only utilized enhanced Security Development Lifecycle (SDL) process during planning, development and testing but we also have worked to make the security features more discoverable, usable and manageable. These enhancements give Windows 7 the expanded security offerings to provide the necessary security controls to help mobile workers access the information they need to be productive, wherever and whenever they need it.

There is a lot of new stuff in Windows 7, but let me highlight some of those things that go into helping the mobile worker…

Multiple Active Firewall Policies

In Windows Vista, firewall policy is based on the “type” of network connection established—such as Home, Work, Public, or Domain (the fourth, hidden type.) This can be a security problem for IT professionals since mobile users will connect to multiple networks while on the road. For example, let’s say I get connected to the Internet through a “Public” network. As a result, the “Public” firewall policy is applied to the computer. Now, if I want to connect to the Microsoft corporate network via my VPN, the IT configured firewall settings for accessing the “Domain” corporate network cannot be applied because the first network type (and thus the firewall settings) had already been set.

Windows 7 gets rid of this IT pain through support for multiple active firewall policies. This enables my PC to obtain and apply domain firewall profile information regardless of other networks that may be active on the PC. Now IT Pros can simplify connectivity and security policies by maintaining a single set of rules for both remote clients and clients that are physically connected to the corporate network and know that the rules are appropriately applied.

image

DirectAccess

When I travel or am day-extending by working from home, I tend to need a lot of access to the corporate Intranet. As you can imagine, we use SharePoint a lot and a large number of our Line of Business applications are all Web- enabled. The result: I have to use our corporate VPN a lot. Unfortunately, it’s always an interruption for me to stop what I am doing and to fire up my VPN connection.

Windows 7 works in conjunction with Windows Server 2008 R2 to make working outside of the office simpler and less frustrating with DirectAccess. DirectAccess works by automatically establishing a bi-directional connection from client computers to the corporate network. As a result, as a remote user I have seamless, secure access to the corporate network anytime I am connected to the Internet, without having to manually initiate a traditional VPN connection. This helps make me more productive and allows me to focus on my work and not the remote access technology. Now whenever and wherever I travel, I can not only access my corporate email, but also open Intranet sites, shared drives, use line-of-business applications, and have full access to corporate resources that I need to do my job without having to manually create my VPN tunnel.

From a security perspective, DirectAccess is built on a foundation of proven, standards-based technologies like IPv6 and IPSec. IPsec is utilized to authenticate both the computer and user. This allows IT the capability to manage the computer even before I log on. IT can also optionally require me to authenticate with a smart card. IPsec is also utilized to provide encryption for communications across the Internet with encryption algorithms such as AES.

DirectAccess also has a cool benefit for IT Pros as well, since it provides an always on, secure mechanism to remotely manage and update the PCs of their mobile workforce. Whenever my laptop has Internet connectivity it is directly connected to the Microsoft corporate network. This gives IT more opportunity to distribute software updates and policies to me and other mobile workers and helps keep our machines free of malware and other unwanted software.

BranchCache

DirectAccess is great for the mobile worker, but what about the remote worker who works out in a branch office location? I’ve worked in many a branch office and the one thing they all seem to have in common is limited network bandwidth. Accessing large files in a branch office is always a slow, frustrating affair for me. I, like most users, prefer a snappy network and quick downloads. All the waiting that I have to do-- or you have to do -- is just lost productivity that, at the end of the day, can hurt the company’s bottom line.

Windows 7 incorporates BranchCache, another technology that works in conjunction with Windows Server 2008 R2, which helps make network responsiveness of applications and data housed within your data center feel snappy. This gives users in remote, branch offices the experience of working as if they were on the local area network (LAN) of the server they are accessing.

BranchCache also helps reduce the utilization of the wide area network (WAN). When BranchCache is enabled, a copy of any data accessed from Intranet Web sites and/or file servers is cached locally within the branch office. When another client on the same network requests the file, the client downloads it from the local cache without downloading the same content across the WAN.

The key thing for me is that it makes access to static data quick and it is all done without decreasing the security of that data. Access controls are enforced on cached files in the same way they are on original files.

BitLocker To Go

While here at RSA, it is inevitable that I will need to share data with one of my trusted partners or customers. My primary method of transferring data is to use one of the half dozen or so USB sticks I carry around in my backpack. Over time, these USB sticks end up with all sorts of different data and documents on them. As a security guy, I worry about what would happen if I lost one of these USB sticks. What if I have some confidential or customer data on one of them?

Windows 7 helps address the continued threat of data leakage with introduction of BitLocker To Go: an extension to BitLocker in Windows Vista that allows me to encrypt the disk volume of removable storage devices with a password and/or a digital certificate stored on a smart card.

BitLocker To Go was designed to facilitate the secure sharing of data on removable storage devices and was designed to work on any standard removable storage device. No special, proprietary hardware is required. So now, whether you are traveling with your laptop, sharing large files with a trusted partner, or taking work home, you can feel secure that your data is safe. Both traditional BitLocker and BitLocker To Go protected devices help ensure that only authorized users can read the data, even if the media is lost, stolen, or misused.

One last thing worth mentioning -- I can use BitLocker To Go to share data with a Windows user who is running Windows Vista or Windows XP through the BitLocker To Go Reader. This application is installed by default on removable storage volumes and allows read-only access on older versions of Windows while still allowing you to help protect your USB sticks.

AppLocker

While I feel good about protecting my data with BitLocker in case it is lost or stolen, data can still be lost due to malware or other unwanted software. When I talk to customers about keeping malware off of their systems, we always end up talking about desktop lockdown and the first topic of desktop lockdown is always removing administrative access from a majority of users. This is a great first step for any organization to take; however, workers today bring software from home, download applications from the Internet (intentional and unintentional), and access new programs through email. Many of these applications don’t need system- wide, administrative access to install or run. The result is a higher incidence of malware infections, more help desk calls, and difficulty in ensuring that only approved, licensed software is installed and utilized.

Windows 7 has a new application control solution in AppLocker. AppLocker gives control back to IT administrators and helps them eliminate unknown and unwanted software in their environment. AppLocker can be configured through Group Policy and can help manage those applications that run on corporate PCs, helping keep your organization’s data safe and your enterprise PCs manageable. AppLocker works by intercepting kernel calls that try to create new processes or load libraries and making sure that the code in question has been allowed to execute.

image

AppLocker just might be my favorite security feature in Windows 7, for it not only provides security protections but as an ex-IT Pro I really appreciate the operational and compliance benefits as well. Things like:

  • Keeping unlicensed, vulnerable software from running in the desktop environment, including stopping workers from running applications that needlessly use consumer network bandwidth or otherwise impact the enterprise computing environment.
  • Easing enterprise software deployments and maintenance through effective desktop configuration management.
  • AppLocker allows users to install and run approved applications and software updates based upon their business needs.
  • Helping ensure a company’s desktop environment is in compliance with corporate policies and industry regulations such as PCI DSS, Sarbanes-Oxley, HIPAA, Basel II, and others.

More to Come

This is just a small part of what’s in Windows 7 from a security perspective, and just the tip of the iceberg for the features I’ve described. Stay tuned for more information on what’s going on at RSA and more information on the cool new security technologies in Windows.


Comments

  1. Posted on: April 20, 2009 at 3:28PM  

    Which versions of Windows 7 include these security features? Enterprise and Ultimate?

  2. Posted on: April 20, 2009 at 3:35PM  

    DirectAccess, BranchCache, AppLocker and BitLocker are available in the Enterprise and Ultimate SKUs.

  3. Posted on: April 21, 2009 at 12:04AM  

    DirectAccess sounds like a really great feature, I hope its as easy to use as it sounds, because people at the small company I work for have been badgering our IT department to move to Sharepoint and VPN technologies for what seems like an eternity.

    It's a real shame we haven't because it would allow so many people to work remotely, and really at least 50% or more of our staff could work remotely.  When I think of all the money we could save in building overhead, and increased worker productivity .... I really don't know why my company hasn't moved forward and embraced this technology more.  That's life I guess!

  4. Posted on: April 21, 2009 at 8:21AM  

    Question: Will AppLocker allow me to audit what is installed?  e.g. I approve Adobe software.  I might want to limit CS3 to only a dozen computers at a time.  Will this help with that sort of licensing?  Or is this simply a white list of what apps are allowed to be installed/run?  

    Is this white list per computer or per user in the AD?

  5. Posted on: April 21, 2009 at 9:29AM  

    Guest mode in Windows 7 (seldom mentioned) is also a pretty good feature that helps to keep of unwanted software and malware. I just wish DirectAccess and BranchCache worked with workgroups-joined PCs and DirectAccess didn't require R2 on the server (wish it was backported to Server 2008 RTM which RTMed just a year before). Also, the internet is just like a WAN, why not enable BranchCache for distributing Windows updates across a workgroup network through peer-to-peer method?

  6. Posted on: October 02, 2009 at 3:24AM  

    thank you very good very good article

Trackbacks

  1. Posted by: WinGeek.com on April 20, 2009 at 3:29PM

    Today Paul Cooke posted an overview of Windows 7 security features for mobile users. In his post he highlighted

  2. Posted by: linkfeedr » Blog Archive » Windows 7 Security: Helping Enable the Mobile Workforce - RSS Indexer (beta) on April 20, 2009 at 4:14PM

    Pingback from  linkfeedr » Blog Archive » Windows 7 Security: Helping Enable the Mobile Workforce - RSS Indexer (beta)

  3. Posted by: Windows 7 security explained | win7connect - A website dedicated to Microsoft Windows 7 on April 20, 2009 at 4:49PM

    Pingback from  Windows 7 security explained | win7connect - A website dedicated to Microsoft Windows 7

  4. Posted by: Ouch | Tech Site on April 20, 2009 at 6:10PM

    Pingback from  Ouch | Tech Site

  5. Posted by: Windows 7 Security: Helping Enable the Mobile Workforce - Windows … « Security on April 20, 2009 at 6:54PM

    Pingback from  Windows 7 Security: Helping Enable the Mobile Workforce - Windows … «  Security

  6. Posted by: Windows 7 Security: Helping Enable the Mobile Workforce - Windows … | www.windows7vista.com on April 20, 2009 at 8:54PM

    Pingback from  Windows 7 Security: Helping Enable the Mobile Workforce - Windows … | www.windows7vista.com

  7. Posted by: Windows 7 Security: Helping Enable the Mobile Workforce - Windows … | Windows Mobile Software on April 20, 2009 at 9:19PM

    Pingback from  Windows 7 Security: Helping Enable the Mobile Workforce - Windows … | Windows Mobile Software

  8. Posted by: Sixth SenseS » Windows 7 Security: Helping Enable the Mobile Workforce - Windows … on April 20, 2009 at 10:10PM

    Pingback from  Sixth SenseS  » Windows 7 Security: Helping Enable the Mobile Workforce - Windows …

  9. Posted by: Tech News, Resources from Blogosphere - 21 April 09(8) | Best Webhosting on April 20, 2009 at 10:50PM

    Pingback from  Tech News, Resources from Blogosphere - 21 April 09(8) | Best Webhosting

  10. Posted by: pontoinfo.info » Windows 7 Security: Helping Enable the Mobile Workforce - Windows … on April 21, 2009 at 2:05AM

    Pingback from  pontoinfo.info  » Windows 7 Security: Helping Enable the Mobile Workforce - Windows …

  11. Posted by: pontoinfo.info » Windows 7 Security: Helping Enable the Mobile Workforce - Windows … on April 21, 2009 at 2:05AM

    Pingback from  pontoinfo.info  » Windows 7 Security: Helping Enable the Mobile Workforce - Windows …

  12. Posted by: WindowsObserver.com » Windows Vista Google Alerts for 20 April 2009 on April 21, 2009 at 3:45AM

    Pingback from  WindowsObserver.com   » Windows Vista Google Alerts for 20 April 2009

  13. Posted by: M??s seguridad en Windows 7 | islaBit on April 21, 2009 at 4:07AM

    Pingback from  M??s seguridad en Windows 7 | islaBit

  14. Posted by: Windows 7 Security and Mobile Workforce on April 21, 2009 at 4:23AM

    Pingback from  Windows 7 Security and Mobile Workforce

  15. Posted by: Windows 7 “mejora” en Seguridad « on April 21, 2009 at 5:18AM

    Pingback from  Windows 7 “mejora” en Seguridad «

  16. Posted by: Windows 7 Security: Helping Enable the Mobile Workforce|Join Our Story!|AngNetwork Blog on April 21, 2009 at 8:42AM

    Pingback from  Windows 7 Security: Helping Enable the Mobile Workforce|Join Our Story!|AngNetwork Blog

  17. Posted by: Die Sicherheit in Windows 7 | silicon.de on April 21, 2009 at 8:57AM

    Pingback from  Die Sicherheit in Windows 7 | silicon.de

  18. Posted by: Microsoft Discusses Windows 7 Security on April 21, 2009 at 11:24AM

    Pingback from  Microsoft Discusses Windows 7 Security

  19. Posted by: Windows Security Blog on April 21, 2009 at 12:43PM

    I attended Scott Charney’s keynote this morning at RSA – Moving Towards End to End Trust: A Collaborative

  20. Posted by: End to End Trust and Windows 7 | Windows Seven 7 on April 21, 2009 at 1:20PM

    Pingback from  End to End Trust and Windows 7 | Windows Seven 7

  21. Posted by: End to End Trust and Windows 7 | Windows Seven 7 on April 21, 2009 at 1:22PM

    Pingback from  End to End Trust and Windows 7 | Windows Seven 7

  22. Posted by: End to End Trust and Windows 7 | Windows Seven 7 on April 21, 2009 at 1:23PM

    Pingback from  End to End Trust and Windows 7 | Windows Seven 7

  23. Posted by: TechNet Flash Feed on April 21, 2009 at 3:24PM

    The Windows Security Blog features a great high-level look by Paul Cooke at the security features in

  24. Posted by: CommunityDNS News Bits, April 21, 2006. « CommunityDNS’s Blog on April 21, 2009 at 3:25PM

    Pingback from  CommunityDNS News Bits, April 21, 2006. « CommunityDNS’s Blog

  25. Posted by: End to End Trust and Windows 7 | Windows 7 Information, News, Downloads, Support Forums on April 22, 2009 at 1:53AM

    Pingback from  End to End Trust and Windows 7 | Windows 7 Information, News, Downloads, Support Forums

  26. Posted by: Windows Workshop » Blog Archive » Windows 7 - novita’ per quanto riguarda la sicurezza on April 22, 2009 at 6:50AM

    Pingback from  Windows Workshop      » Blog Archive           » Windows 7 - novita’ per quanto riguarda la sicurezza

  27. Posted by: End to End Trust and Windows 7 | Windows 7 Latest News Leaks Downloads on April 22, 2009 at 11:27AM

    Pingback from  End to End Trust and Windows 7 | Windows 7 Latest News Leaks Downloads

  28. Posted by: Windows 7: More Secure, Less Annoying | Technology News on April 22, 2009 at 5:52PM

    Pingback from  Windows 7: More Secure, Less Annoying | Technology News

  29. Posted by: Windows 7 Security: Helping Enable the Mobile Workforce - Windows … « Security on April 22, 2009 at 8:19PM

    Pingback from  Windows 7 Security: Helping Enable the Mobile Workforce - Windows … «  Security

  30. Posted by: Windows 7'nin T?m G?venlik Yenilikleri - Forum Ti on April 23, 2009 at 4:35AM

    Pingback from  Windows 7'nin T?m G?venlik Yenilikleri - Forum Ti

  31. Posted by: Windows 7'de g?venlik yenilikleri - Teknoloji ve Webmaster Platformu on April 23, 2009 at 8:03AM

    Pingback from  Windows 7'de g?venlik yenilikleri - Teknoloji ve  Webmaster Platformu

  32. Posted by: Windows 7'nin t?m g?venlik yenilikleri burada - SDN on April 23, 2009 at 9:34AM

    Pingback from  Windows 7'nin t?m g?venlik yenilikleri burada - SDN

  33. Posted by: En g??venlisi Windows 7! | Volkan B??LG??L?? Ki??isel Web Sayfas?? - VoLqaN OFFICIAL WEB PAGE / www[dot]volkanbilgili[dot]com on April 23, 2009 at 10:24AM

    Pingback from  En g??venlisi Windows 7! | Volkan B??LG??L?? Ki??isel Web Sayfas?? - VoLqaN OFFICIAL WEB PAGE / www[dot]volkanbilgili[dot]com

  34. Posted by: En güvenlisi Windows 7! | Mirc, Türkçe mirc, mirc indir, mırc, mirç on April 23, 2009 at 10:53AM

    Pingback from  En güvenlisi Windows 7! | Mirc, Türkçe mirc, mirc indir, mırc, mirç

  35. Posted by: En G?venlisi Windows 7 on April 23, 2009 at 11:12AM

    Pingback from  En G?venlisi Windows 7

  36. Posted by: En g?venlisi Windows 7! - Keyfi Alem.Net - Alemin En Keyiflisi on April 23, 2009 at 12:02PM

    Pingback from  En g?venlisi Windows 7! - Keyfi Alem.Net - Alemin En Keyiflisi

  37. Posted by: En g??venlisi Windows 7! | Nexthaber.com Teknoloji Bilim ve Uydu Haberleri on April 23, 2009 at 1:33PM

    Pingback from  En g??venlisi Windows 7! | Nexthaber.com Teknoloji Bilim ve Uydu Haberleri

  38. Posted by: You Get The . Info » End to End Trust and Windows 7 - 98th Edition on April 23, 2009 at 4:45PM

    Pingback from  You Get The . Info » End to End Trust and Windows 7 - 98th Edition

  39. Posted by: En g??venlisi Windows 7! | Gerekligereksiz.net on April 23, 2009 at 5:42PM

    Pingback from  En g??venlisi Windows 7! | Gerekligereksiz.net

  40. Posted by: SystemRoot Bilgi D??nyas?? » Blog Archive » En g??venlisi Windows 7! on April 24, 2009 at 11:52AM

    Pingback from  SystemRoot Bilgi D??nyas??  » Blog Archive   » En g??venlisi Windows 7!