- play_arrow JIMS Overview
- play_arrow How JIMS works
- play_arrow How to Install JIMS
- play_arrow JIMS Administrative User Interface
Prerequisites – Security Hardening
SUMMARY This section explains how to restrict access for system accounts with JIMS.
Set up JIMS – Identity Aware Network
Follow the below steps to set up JIMS to offer an identity aware network:
- Define service accounts and enforcement point credentials.
- Install JIMS.
- Configure JIMS to connect to all your Active Directory services.
- Configure JIMS to use the identity producers of your choice.
- Configure the required integrations such as Juniper Secure Edge or Security Director Cloud and so on.
- Enroll all your SRX Series Firewalls into JIMS.
Configure Limited-Permission User Accounts
Follow these steps for a new user account:
- From the Start menu, select Active Directory Users and Computers.
- Navigate to the Users container in the forest.
- Right-click Users and select New Users.
- Specify a descriptive first and middle name or any Windows 2000 username.
- Specify a password according to your organization’s password policy.
- Clear the User must change password at next login check box.
- Select the User cannot change password check box.
- Select the Password never expires check box.
Add Limited Permission User Accounts to Active Directory Groups
To add each new user account to an Active Directory group:
- Select the Built-in option.
- Select the Event Log Readers group and add the JIMS-EventLogRemoteAccess account.
- Select the Distributed COM Users group and add the JIMS-PC-Probe account.
- Select the Remote Management Users group and add the JIMS-PC-Probe account.
- Select the Domain Admins group and add the JIMS-PC-Probe account.
Define Group Policies for Limited Permission User Accounts
To define group policies for each new user account:
- From the Start menu, select Group Policy Management.
- On the Group Policy Manager tab/window, select the forest and Default Domain Policy. Right-click Default Domain Policy and select Edit.
- Select Computer Configuration> Policies> Windows Settings> Security Settings >Local Policies> User Rights Assignment.
- Select Deny Logon locally, select Define these policy settings, and add the new user account.
- Select Deny Logon through Remote Desktop Services, select Define these policy settings., and add the new user account.
- Select Deny Logon through Terminal Services, select Define these policy settings, and add the new user account.
- Select Deny logon as a batch job, select Define these policy settings, and add the new user account.
- Select Deny Logon as a service, select Define these policy settings, and add the new user account .