Microsoft Windows Common Criteria Evaluation

[Pages:39]Windows 10 and Windows Server GP OS Operational Guidance

Microsoft Windows Common Criteria Evaluation

Microsoft Windows 10 Fall Creators Update Microsoft Windows Server (Fall Creators Update)

Common Criteria Supplemental Admin Guidance

Document Information

Version Number Updated On

0.6 March 20, 2018

Microsoft? 2018 Page 1 of 39

Windows 10 and Windows Server GP OS Operational Guidance Microsoft? 2018 Page 2 of 39

Windows 10 and Windows Server GP OS Operational Guidance

The information contained in this document represents the current view of Microsoft Corporation on the issues discussed as of the date of publication. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information presented after the date of publication. This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, AS TO THE INFORMATION IN THIS DOCUMENT. Complying with all applicable copyright laws is the responsibility of the user.This work is licensed under the Creative Commons Attribution-NoDerivs-NonCommercial VLicense (which allows redistribution of the work). To view a copy of this license, visit or send a letter to Creative Commons, 559 Nathan Abbott Way, Stanford, California 94305, USA. Microsoft may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from Microsoft, the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property. The example companies, organizations, products, people and events depicted herein are fictitious. No association with any real company, organization, product, person or event is intended or should be inferred. ? 2018 Microsoft Corporation. All rights reserved. Microsoft, Active Directory, Visual Basic, Visual Studio, Windows, the Windows logo, Windows NT, and Windows Serverare either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. The names of actual companies and products mentioned herein may be the trademarks of their respective owners.

Microsoft? 2018 Page 3 of 39

Windows 10 and Windows Server GP OS Operational Guidance

TABLE OF CONTENTS

1

INTRODUCTION .......................................................................................................................................................................................................................................................9

1.1 1.2 1.2.1 1.2.2

EVALUATED WINDOWS EDITIONS AND HARDWARE PLATFORMS .............................................................................................................................................................................................9 CONFIGURATION .........................................................................................................................................................................................................................................................9 EVALUATED CONFIGURATION ............................................................................................................................................................................................................................................................. 9 WINDOWS 10 S ............................................................................................................................................................................................................................................................................. 13

2

MANAGEMENT FUNCTIONS...................................................................................................................................................................................................................................14

3

MANAGING AUDITS ..............................................................................................................................................................................................................................................15

3.1 3.2 3.2.1

AUDIT EVENTS ..........................................................................................................................................................................................................................................................15 MANAGING AUDIT POLICY...........................................................................................................................................................................................................................................20 ADMINISTRATOR GUIDANCE ............................................................................................................................................................................................................................................................. 20

4

MANAGING TLS.....................................................................................................................................................................................................................................................22

4.1 4.1.1 4.1.2 4.1.3 4.1.4 4.2 4.2.1

ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................22 CIPHER SUITE SELECTION ................................................................................................................................................................................................................................................................. 22 CERTIFICATE NAME COMPARISON ..................................................................................................................................................................................................................................................... 23 ROOT CERTIFICATES ........................................................................................................................................................................................................................................................................ 23 MANAGING SIGNATURE ALGORITHMS................................................................................................................................................................................................................................................ 24 USER GUIDANCE .......................................................................................................................................................................................................................................................24 WINDOWS 10 ENTERPRISE, WINDOWS 10 PRO, WINDOWS 10 HOME, AND WINDOWS 10 S .................................................................................................................................................................... 24

5

MANAGING ACCOUNT LOCKOUT POLICY................................................................................................................................................................................................................24

Microsoft? 2018 Page 4 of 39

Windows 10 and Windows Server GP OS Operational Guidance

5.1

ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................24

6

MANAGING SMART CARD LOGON .........................................................................................................................................................................................................................25

7

MANAGING WINDOWS HELLO - WINDOWS 10 ENTERPRISE, WINDOWS 10 PRO, WINDOWS 10 HOME, AND WINDOWS 10 S...................................................................................25

7.1 7.1.1 7.2 7.2.1 7.2.2

MANAGING BIOMETRIC AUTHENTICATION.......................................................................................................................................................................................................................25 USER GUIDANCE............................................................................................................................................................................................................................................................................. 25 MANAGING PIN AUTHENTICATION................................................................................................................................................................................................................................25 ADMINISTRATOR GUIDANCE ............................................................................................................................................................................................................................................................. 25 USER GUIDANCE............................................................................................................................................................................................................................................................................. 25

8

MANAGING PASSWORDS AND PASSWORD POLICY ................................................................................................................................................................................................26

8.1

ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................26

9

MANAGING CERTIFICATES .....................................................................................................................................................................................................................................27

9.1 9.1.1 9.1.2 9.1.3 9.1.4 9.2 9.2.1

ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................27 CLIENT CERTIFICATES....................................................................................................................................................................................................................................................................... 27 ROOT CERTIFICATES ........................................................................................................................................................................................................................................................................ 27 CERTIFICATE VALIDATION................................................................................................................................................................................................................................................................. 28 CERTIFICATE ENROLLMENT ............................................................................................................................................................................................................................................................... 28 USER CERTIFICATES....................................................................................................................................................................................................................................................29 USER GUIDANCE............................................................................................................................................................................................................................................................................. 30

10

MANAGING SCREEN LOCK AND SESSION TIMEOUT.................................................................................................................................................................................................30

Microsoft? 2018 Page 5 of 39

Windows 10 and Windows Server GP OS Operational Guidance

10.1 10.2 10.2.1

ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................30 USER GUIDANCE .......................................................................................................................................................................................................................................................31 WINDOWS 10 ENTERPRISE, WINDOWS 10 PRO, WINDOWS 10 HOME, AND WINDOWS 10 S .................................................................................................................................................................... 31

11

MANAGING LOCAL AREA NETWORK ......................................................................................................................................................................................................................32

11.1 ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................32

12

MANAGING BLUETOOTH .......................................................................................................................................................................................................................................32

12.1 ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................32 12.2 USER GUIDANCE - WINDOWS 10 ENTERPRISE, WINDOWS 10 PRO, WINDOWS 10 HOME, AND WINDOWS 10 S..............................................................................................................................33

13

MANAGING USB....................................................................................................................................................................................................................................................33

13.1 ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................33

14

MANAGING UPDATES............................................................................................................................................................................................................................................33

14.1 ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................33 14.2 WINDOWS SERVER ....................................................................................................................................................................................................................................................34 14.3 USER GUIDANCE .......................................................................................................................................................................................................................................................34

15

MANAGING THE FIREWALL ....................................................................................................................................................................................................................................34

15.1 ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................34

Microsoft? 2018 Page 6 of 39

Windows 10 and Windows Server GP OS Operational Guidance

16

MANAGING DOMAINS...........................................................................................................................................................................................................................................35

16.1 ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................35

17

MANAGING TIME ..................................................................................................................................................................................................................................................35

17.1 17.1.1 17.1.2

ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................35 MANAGING DATE AND TIME ............................................................................................................................................................................................................................................................ 35 MANAGING THE TIME SERVICE ......................................................................................................................................................................................................................................................... 35

18

MANAGING WI-FI..................................................................................................................................................................................................................................................36

18.1 ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................36

19

MANAGING REMOTE ADMINISTRATION ................................................................................................................................................................................................................36

19.1 ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................36

20

MANAGING SOFTWARE RESTRICTION POLICIES......................................................................................................................................................................................................37

20.1 ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................37

21

MANAGING LOGON BANNER.................................................................................................................................................................................................................................38

21.1 ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................38

22

MANAGING HIBERNATION ....................................................................................................................................................................................................................................38

Microsoft? 2018 Page 7 of 39

Windows 10 and Windows Server GP OS Operational Guidance

22.1 ADMINISTRATOR GUIDANCE ........................................................................................................................................................................................................................................38

23

DEVELOPING APPLICATIONS ..................................................................................................................................................................................................................................39

Microsoft? 2018 Page 8 of 39

................
................

In order to avoid copyright disputes, this page is only a partial summary.

Google Online Preview   Download