BeyondTrust Solutions

Standard Desktop Configuration

A standard desktop configuration offers an organization many advantages. It significantly enhances network security by establishing uniform computer security settings, facilitating faster application of security patches, and it reduces the costs of administrating desktops. Standard desktop configuration projects must restrict administrator rights on all PCs in order to maintain the standard configurations, as it is impossible to control how users will configure their computers when they are administrators. Additionally any system operating with administrative privileges is at high risk of running or installing, unauthorized applications and being exploited by malware and malicious users.

One of the most visible and successful standard desktop configurations initiatives was undertaken by the US Air Force, and based on its success the US government modeled the Federal Desktop Core Configuration (FDCC) after it. As of February 2008 all Government agencies must comply with the standard Windows XP and Vista security configurations defined in the FDCC. Both of these projects require that users no longer log in with administrator rights in order to prevent users from changing configuration settings that would inadvertently expose the network to vulnerabilities.

With Privilege Manager you can remove administrator rights, preserve a standard desktop image and maintain a productive environment where:

  • Users can run approved applications that require admin rights as a Standard User
  • Users cannot alter the standard desktop security configurations, but can manage approved settings, such as connecting to local printers and defragmenting
  • Computers are better protected against malware and malicious users
  • Users can only install authorized software

Already in use at multiple Air Force locations and many government agencies enforcing the standard configuration requirements, BeyondTrust Privilege Manager facilitates compliance by enabling computer users to log in to Windows without administrative privileges while transparently allowing them to run or install all authorized applications.

More Information
For more information about BeyondTrust Privilege Manager sign up for a webinar.

Solutions

"BeyondTrust Privilege Manager has helped us to meet Air Force standard configuration requirements more efficiently and to eliminate end-user administrative privileges, while decreasing the need for IT support. Privilege Manager enables our end users to continue using numerous applications that require administrative privileges and to perform necessary system tasks such as adding a local printer and defragging the hard drive while still meeting the government mandate. As other government agencies seek to comply with the OMB requirements, their efforts will be made considerably easier by adopting BeyondTrust Privilege Manager."

quoted

- Mike De Bruin,
senior systems engineer with RS Information Systems at Vandenberg Air Force Base in California

Read Press Release
rounded