Home > Midmarket IT Security Tips > Windows Security Tactics > Poor Microsoft SharePoint security permissions policies can derail deployments
Midmarket IT Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WINDOWS SECURITY TACTICS

Poor Microsoft SharePoint security permissions policies can derail deployments


Neil Roiter
08.26.2009
Rating: --- (out of 5)


Midmarket Security Strategies and Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Microsoft SharePoint security is not difficult to establish and maintain, as long as your organization has a well thought-out plan for best practices before implementation.

More SharePoint Resources
Security enhancements in Microsoft Essential Business Server 2008: Microsoft Essential Business Server solves major security and network management issues for midmarket companies that are outgrowing Microsoft Small Business Server 2003 and are too small for enterprise solutions.
Microsoft Stirling Beta 2 release includes Exchange SaaS offering: Microsoft continues to meld security and identity management, with the Beta 2 release this week of Stirling, the next generation of its Forefront Security Suite.

SharePoint provides a Web-based portal for content management, collaboration, managing business processes and forms, and search inside the company, as well as reaching out to authorized partners, contractors and other third parties. It's easy to deploy and use, so that business users can manage their sites without constantly relying on IT for help.

Security is not difficult, but issues can arise, primarily over access control if SharePoint permissions are poorly thought out or implemented. External users can also be an issue if they are not properly managed.

This two-part tip will explain five of the most important things experts say you should keep in mind when you design SharePoint security. Part two will cover how to handle external users, authorization and general security issues.

SHAREPOINT SECURITY BEST PRACTICES MUST BALANCE CONTROL AND USABILITY
A common error is simply the failure to create thoughtful SharePoint security best practices in first place.

If the policy is too permissive, users wind up with too much liberty to customize SharePoint sites, especially around access to resources. The evitable consequence is people seeing and/or being able to change documents they shouldn't have those rights to.

This often happens when users ask the help desk to do something for their site. But instead of addressing the specific request, IT responds by simply giving them site admin privileges so they can make the change--and any future changes--without coming back to the help desk. This behavior is typical of overworked IT departments, said Matt Ranlett, principal consultant in Atlanta, Ga.-based Intellinet Corp.'s worker information practice and a Microsoft MVP for SharePoint Server.

On the other extreme are organizations that are so rigid that everything is locked down and every change requires a help desk request. That's bad news for small IT departments and for users who just want to get on with their jobs.

"There needs to be a middle ground," said Ranlett. "There's more art than science to how you grant users permission to make modifications to the design of a site."

Smaller organizations generally don't have to worry about policy control and enforcement across multiple units and SharePoint deployments, so once your organization has configured SharePoint and set appropriate use policies, site admins should pretty much run things on their own.

USE ACTIVE DIRECTORY TO CREATE SECURITY GROUPS
If you are like most midmarket companies, you use Active Directory as your primary user information repository for email distribution groups, user authentication, and application and file access and authorization. Simplify your management of SharePoint identities by either using existing AD security groups or creating new ones and moving them to SharePoint.

You should note that SharePoint is designed to be perfectly workable if you don't have Active Directory. You can create SharePoint groups for authorization privileges and use any LDAP, SQL Server, Oracle, or third-party product for authentication.

A small IT staff doesn't have time to manage users and groups in two places. You can always have the site admin manage individual exceptions in SharePoint, rather than involve IT in an AD change.

"If I want to share information with you and Bob down hall, it's not likely there's an AD group to reflect that," said Neil MacDonald, VP at Stamford, Conn.-based Gartner.

SharePoint doesn't have a centralized rights management interface. It can't generate reports that show what a given user has access to--you would have to check each object (think, 1,000 documents, for example) in SharePoint to see if the user has access. In AD, on the other hand, it's easy to report on user access and replicate rights for new employees or for changing roles.

One caution here: Don't assume your existing AD groups will automatically meet your SharePoint needs. A department AD group or geographic group may be a convenient way to organize employees for authentication and other AD tasks, but may not reflect how people work.

"The problem is AD doesn't necessarily reflect how people share information or want to share information," said MacDonald.

Send comments on this technical tip editor@searchmidmarketsecurity.com.

Join our IT Knowledge Exchange discussion forum; please use the midmarket security tag.


Rate this Tip
To rate tips, you must be a member of SearchMidmarketSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Windows Security Tactics
Five NAC-like endpoint settings enforced with group policy
Windows Firewall with Advanced Security beefs up Windows 7 security
How to examine a DD image on Windows or Linux
How to use Microsoft Windows 7 AppLocker for whitelisting applications
How to automate and apply Microsoft Windows 7 AppLocker rules
Tradeoffs and advantages of network access control with Microsoft NAP
Should you disable IE ESC, or manage it in Windows servers?
Determine your Microsoft Windows patch level
Automating Microsoft Windows patch management with WSUS
Understand the pros and cons of Microsoft Windows 7 DirectAccess

Microsoft identity and access management
Understand the pros and cons of Microsoft Windows 7 DirectAccess
Microsoft SharePoint security hinges on authorization, external user management
How to use Kerberos and Credential manager for Windows single sign-on
Three ways to prioritize endpoint security over perimeter defenses
Microsoft Windows RMS enables granular access control over sensitive data
Microsoft Stirling Beta 2 release includes Exchange SaaS offering
Demystifying identity management
Five key challenges in managing identities
Quiz: Building an identity and access management architecture
From the gateway to the application: Effective access control strategies

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts