01 · Starting point
Situation
IT staff needed a practical understanding of new Windows 7 features, PowerShell and the secure use of encryption, certificates and group policies.
Constraints
- Changes within an already established IT environment
- Short, clearly scoped engagement
- Internal system and operating details remain confidential
02 · Responsibility
My scope of responsibility
I ran training sessions and built a test lab for security mechanisms, custom ADMX templates and group policies.
- I trained IT staff on Windows 7, PowerShell, EFS and certificates.
03 · Technical work
Documented scope of work
Key decisions
Demonstrate security features hands-on in a controlled lab. Encryption and policies are only used securely once administrators can see impact, recovery and misconfiguration for themselves.
- I set up a BitLocker test lab and demonstrated secure usage scenarios.
- I created GPOs with custom ADMX templates.
04 · Technical context
Technology in use
Windows 7
Windows 7 was part of the documented toolset in this Security & Recovery engagement.
PowerShell
PowerShell was part of the documented toolset in this Security & Recovery engagement.
EFS
EFS was part of the documented toolset in this Security & Recovery engagement.
BitLocker
BitLocker was part of the documented toolset in this Security & Recovery engagement.
Certificates
Certificates was part of the documented toolset in this Security & Recovery engagement.
ADMX
ADMX was part of the documented toolset in this Security & Recovery engagement.
05 · Factual basis
Evidence and limits
The team gained a practical foundation for the controlled use of core Windows security features.
- Role
- Windows Security Consultant
- Period
- October 2011 — November 2011
Lesson from the engagement
Security training only convinces once administrators have worked through protection and recovery in the lab themselves.
Confidentiality note: Internal architecture and operating data of this engagement are not published.