{"id":1007,"date":"2013-10-07T20:51:38","date_gmt":"2013-10-07T18:51:38","guid":{"rendered":"http:\/\/sccmfaq.wordpress.com\/?p=1007"},"modified":"2013-10-07T20:51:38","modified_gmt":"2013-10-07T18:51:38","slug":"sccm-2012-compliance-settings-really","status":"publish","type":"post","link":"https:\/\/blog.hosebei.ch\/?p=1007","title":{"rendered":"SCCM 2012 &#8211; Compliance Settings, really?"},"content":{"rendered":"<p>Hey, here&#8217;s Martin, did you ever come to the Point, where you should implement compliance Settings in System Center 2012 Configuration Manager (Artist formerly known as &#8220;Desired Configuration Management&#8221;)?<br \/>\nAnd further, did you also thought, how to get all of those compliance Settings? Microsoft publish the so-called &#8220;Security Compliance Manager&#8221; which will be the Support to achieve our Goal!<!--more--><br \/>\nWell what do you Need?<br \/>\n-Microsoft Security Compliance Manager (http:\/\/technet.microsoft.com\/en-us\/library\/cc677002.aspx)<br \/>\n-SQL Server (Otherwise it will install a SQL Express 2008 on your Machine, check if your OS is supported; Windows 8.1 isn&#8217;t \ud83d\ude42 )<\/p>\n<p>And&#8230; that&#8217;s it. Let&#8217;s start, I have it already installed in an existing SQL instance, and through the installation, a new database called XTrans is created:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance01.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-1009\" alt=\"Compliance Database\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance01.png\" width=\"262\" height=\"164\" \/><\/a><br \/>\nAfter a successful Installation you can start the &#8220;Security Compliance Manager&#8221; (SCM), the program will start and you can select the appropriate Options:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance02.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1010\" alt=\"SCM Startup\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance02.png?w=300\" width=\"300\" height=\"270\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance02.png 933w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance02-300x270.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance02-768x691.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nIn this example, I will use a Windows Server 2012 Hyper-V Security template as baseline, because the virtualization layer is a good Point to start with compliance, thus they are hosting our environment. So click on Windows Server 2012 to open the tree, and select &#8220;WS2012 Hyper-V Security&#8221;:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance03.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1011\" alt=\"Hyper-V Compliance Settings 01\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance03.png?w=300\" width=\"300\" height=\"239\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance03.png 1049w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance03-300x239.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance03-1024x816.png 1024w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance03-768x612.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nYour Focus should now Change to the middle of the console, where you already get 203 Settings to use. You can now decide to use this set, and Export it to use it in SCCM, then you can scroll down a Little bit, this will be explained. Otherwise, if you decide to use SCM for the Single Point of Management, what would be a good Option, then you have to duplicate the baseline:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance04.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1013\" alt=\"Dublicate Baseline\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance04.png?w=300\" width=\"300\" height=\"166\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance04.png 831w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance04-300x167.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance04-768x427.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nAfter giving an unique Name and an excellent description, click on Save and you can use your custom baseline:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance05.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1014\" alt=\"Custom Baseline\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance05.png?w=300\" width=\"300\" height=\"70\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance05.png 1038w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance05-300x70.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance05-1024x240.png 1024w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance05-768x180.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nNow you are able to Change any Settings and also to add more Settings, or delete some:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance06.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1015\" alt=\"Compliance Settings Add\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance06.png?w=91\" width=\"91\" height=\"300\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance06.png 209w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance06-91x300.png 91w\" sizes=\"auto, (max-width: 91px) 100vw, 91px\" \/><\/a><br \/>\nIn this example, I only set the Print Spooler to &#8220;Disabled&#8221;, and set the severity to &#8220;Important&#8221;:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance07.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1016\" alt=\"Disable Print Spooler\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance07.png?w=300\" width=\"300\" height=\"142\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance07.png 840w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance07-300x143.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance07-768x365.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nI also add a Setting to the baseline, but first, I create a new Settings Group, I will Name it General:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance08.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1018\" alt=\"Add Setting Group\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance08.png?w=300\" width=\"300\" height=\"164\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance08.png 841w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance08-300x165.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance08-768x422.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nWhen clicking on &#8220;Add&#8221; in the right side of the console beyond &#8220;Setting&#8221;, the &#8220;Add Settings&#8221;-Wizard appears, here can I add more Settings to my baseline. The GUI is not very good, that&#8217;s why I would Point out, that there exist 22 pages for Windows Server 2012 (you might want to use the filter search). I choose to not require Ctrl-Alt-Del to Logon interactively:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance09.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1019\" alt=\"Add Setting\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance09.png?w=300\" width=\"300\" height=\"185\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance09.png 975w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance09-300x186.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance09-768x476.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nClick on &#8220;Add&#8221; to finish the wizard. Afterwards you can Change the behaviour of the added Setting. I changed the value to enabled and the severity to Optional:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance10.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1020\" alt=\"Add compliance setting\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance10.png?w=300\" width=\"300\" height=\"92\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance10.png 821w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance10-300x92.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance10-768x236.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nYou can add more and more Settings to your baseline if you want. For this example, I have changed and added enough, now I will Export the baseline, and Import it to SCCM.<\/p>\n<p>Here Comes the Export of the Baseline. Be sure that you have selected your custom baseline in the tree on the left side of the console. The click on &#8220;SCCM DCM 2007 (.cab)&#8221; beyond Export. Even if you are using SCCM 2012, it will definitely work:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance11.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1023\" alt=\"Export Baseline\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance11.png?w=300\" width=\"300\" height=\"230\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance11.png 1072w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance11-300x230.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance11-1024x786.png 1024w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance11-768x590.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nAnd in the SCCM 2012 Console, you can now Import your designed baseline. Go to &#8220;Asset and Compliance&#8221;  &#8220;Compliance Settings&#8221;  &#8220;Configuration Baseline&#8221;, with a right-click, the menu opens, and you can select &#8220;Import configuration Data&#8221;:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance12.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1024\" alt=\"SCCM Baseline Import\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance12.png?w=202\" width=\"202\" height=\"300\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance12.png 385w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance12-202x300.png 202w\" sizes=\"auto, (max-width: 202px) 100vw, 202px\" \/><\/a><br \/>\nClick on &#8220;Add&#8221; and select your exported Baseline from SCM, because your cab-File is not digitally signed, a warning will be shown. The wizard should Looks like this:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance13.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-1027\" alt=\"Import Baseline SCCM\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance13.png?w=300\" width=\"300\" height=\"263\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance13.png 720w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance13-300x264.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nIn the summary you can recognize your Setting Groups:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance15.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance15.png?w=300\" alt=\"Import Summary\" width=\"300\" height=\"262\" class=\"aligncenter size-medium wp-image-1028\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance15.png 720w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance15-300x262.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nIf everything was imported, you will see the success Status:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance16.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2013\/10\/compliance16.png?w=300\" alt=\"Successful Import\" width=\"300\" height=\"263\" class=\"aligncenter size-medium wp-image-1029\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance16.png 717w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2013\/10\/compliance16-300x264.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\nAfter finishing the wizard, you can modify the Settings again, or set remediation. Mind to document any changes made in SCCM, when using DCM as the Single Point of Management. And then, you can deploy your baseline as any baselines created before.<br \/>\nThe SCM allows you to control your Settings on a easy way, and publish them to different Systems (Group Policy, SCCM, Excel).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hey, here&#8217;s Martin, did you ever come to the Point, where you should implement compliance Settings in System Center 2012 Configuration Manager (Artist formerly known as &#8220;Desired Configuration Management&#8221;)? And further, did you also thought, how to get all of those compliance Settings? Microsoft publish the so-called &#8220;Security Compliance Manager&#8221; which will be the Support [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[35,40],"tags":[],"class_list":["post-1007","post","type-post","status-publish","format-standard","hentry","category-sccm-2012","category-tools"],"_links":{"self":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/1007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1007"}],"version-history":[{"count":0,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/1007\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}