Threats and Vulnerabilities Mitigation

This page provides information for the IT professional about features and technologies that provide layered defenses against malicious software threats and intrusions through a strategy of prevention, isolation, and recovery.

Communication with the Internet

Internet Explorer Security

Microsoft Forefront

Microsoft Forefront is a collection of business security products that helps provide protection for an organization's network infrastructure.

  • Microsoft Forefront Product Overview
    This document describes the following products and provides additional resources for each: Microsoft Forefront Client Security, Microsoft Forefront Security for Exchange Server, Microsoft Forefront Security for SharePoint, Microsoft Internet Security and Acceleration Server, and Intelligent Application Gateway 2007.
  • Microsoft Forefront Client Security Technical Library
    The technical library provides information for evaluating, installing, deploying, troubleshooting, securing, and operating Forefront Client Security.
  • Forefront Security for SharePoint Technical Library
    The technical library provides information for evaluating, installing, deploying, and operating Forefront Security for SharePoint.

Network Access Protection

The Network Access Protection (NAP) platform is a computer health policy enforcement technology that provides system health–validated access to private networks. It provides an integrated way of detecting the health state of a network client that is attempting to connect to or communicate on a network and isolating that network client until the health requirements have been met.

  • Introduction to Network Access Protection
    This page provides a download of the NAP introduction document, which describes the components of NAP and explains how NAP works.
  • Network Access Protection Architecture
    This page provides a download of the NAP architecture document, which describes NAP platform architecture, NAP client architecture, and NAP server-side architecture, in addition to how NAP works.

Threats and Countermeasures Guide

User Account Control

User Account Control (UAC) reduces the exposure and attack surface of the operating system by requiring that all users run in standard user mode. This limitation minimizes the ability for users to make changes that could destabilize their computers or inadvertently expose the network to viruses through undetected malicious software that has infected their computer.

Windows Defender

Windows Defender is real-time protection software used for the detection and mitigation of spyware and other potentially unwanted software. It helps protect computers running Windows Vista, Windows XP with Service Pack 2 (SP2), or Windows Server 2003 with Service Pack 1 (SP1).

Windows Firewall with Advanced Security

Beginning with the Windows Vista and Windows Server 2008 operating systems, configuration of both Windows Firewall and Internet Protocol security (IPsec) are combined into a single tool, the Windows Firewall with Advanced Security Microsoft Management Console (MMC) snap-in.