Secure your Infrastructure Monitoring with SCOM

Published Mar 02 2021 09:44 PM 5,320 Views
Microsoft

Recent high profile cyberattacks have highlighted the importance of having strong standards and features built into infrastructure monitoring and management tools. Microsoft System Center Operations Manager (SCOM) offers world class monitoring capabilities and includes powerful built-in security features.

 

Our increased focus on customers security concerns have led us to include enhancements to many security related features in recent SCOM update rollups. We know that organizations have strict controls and best practices and we want to ensure that our customers have the right tools to prevent attacks and gain peace of mind. Here are some of SCOM’s security offerings.

 

Bhavna_Appayya_0-1614748281431.png

 

A new addition to SCOM 2019 was increasing out of the box security configuration through support for group managed service accounts (gMSA).Group Managed Service Accounts (gMSA) has been a very popular capability because it alleviates the need for password management – now all accounts used in SCOM can be gMSA. A detailed guide on how to configure gMSA accounts in lieu of your existing SCOM accounts is provided here. 

Another important best practice is to disable interactive and remote interactive sessions for service accounts. SCOM 2019 supports hardening of service accounts and does not require granting the “Allow log on locally” user right for several accounts. The default configuration on SCOM 2019 Management Servers, Gateways, and Agents, is that service accounts and RunAs accounts will now leverage the “Log on as a Service” user right, and no longer require the “Log on locally” user right.

An additional security feature in SCOM is that Run As account credentials can also be distributed to computers that you specify, see details here  . Automatically distributing Run As account according to discovery could introduce a security risk, which is why customers can opt for a more secure option of manually selecting the computers to which the credentials will be distributed .

 

Authentication in Operations Manager

 

SCOM implements a default set of authentication protocols, including Kerberos, NTLM, Transport Layer Security/Secure Sockets Layer (TLS/SSL) as part of an extensible architecture. In addition, some protocols are combined into authentication packages such as Negotiate and the Credential Security Support Provider. These protocols and packages enable authentication of users, computers, and that in turn ensures access to resources in a secure manner.

SCOM also mandates a least privileged model for its security account matrix. The least privileged model is a best practice in IT security and the concept is that any user, service, or process should have only the bare minimum privileges necessary to execute the required task. Mandating this principle reduces the risk of attackers gaining access to sensitive data by compromising low level user accounts or devices.

 

Auditing in Operations Manager

 

We recently introduced Management pack change tracking, a feature that allows enhanced audit tracking capabilities in SCOM. Management Packs are essentially the arteries of SCOM that help the core of SCOM function well. They include monitoring configurations and data collection parameters tailored for specific applications and services. Management packs are released by both Microsoft and third-party vendors for a range of tools and applications that need to be monitored in the customer’s landscape.

SCOM allows to be defined giving access rights to perform actions on the monitored objects. These roles can be defined to determine who can potentially change monitoring settings for applications and services through Management Packs. A profile is defined on a group of users which impose Role-based security and limit privileges that users have for various aspects of Operations Manager. The change tracking feature allows the administrators to do an easy root cause analysis as and when required to keep track of what changes are being done by which user and when.

 

Security is built-into SCOM

 

To help customers deploy the latest security protocols, we enable Transport Layer Security (TLS) protocol version 1.2 for System Center Operations Manager management groups. In support of our commitment to use best-in-class encryption, SCOM’s engineering team is continually upgrading our cryptographic infrastructure. Customers can configure the Web console and Reporting server to use Secure Sockets Layer (SSL) connections to ensure that both incoming requests and outbound responses are encrypted prior to transmission.

System Center Operations Manager provides layers of protection built into the product to safeguard against security breaches. SCOM follows Microsoft’s Software Development Lifecycle(SDL) policy , which considers security and privacy throughout all phases of the development process. The SCOM team uses Microsoft approved SDL tools like BinSkim, CredScan, Codesign Validation, and Anti malware to perform security checks for each line of code they produce. In addition to these tools and to add further protection, our code is also encrypted with Secure Hash Algorithm 2 (SHA-2).

We are very proud to offer a product like System Center Operations Manager, one that continues to support evolving industry security needs and strives to keep our customers safe and productive.

%3CLINGO-SUB%20id%3D%22lingo-sub-2180736%22%20slang%3D%22en-US%22%3ESecure%20your%20Infrastructure%20Monitoring%20with%20SCOM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2180736%22%20slang%3D%22en-US%22%3E%3CP%20class%3D%22lia-align-justify%22%3ERecent%20high%20profile%20cyberattacks%20have%20highlighted%20the%20importance%20of%20having%20strong%20standards%20and%20features%20built%20into%20infrastructure%20monitoring%20and%20management%20tools.%20Microsoft%20System%20Center%20Operations%20Manager%20(SCOM)%20offers%20world%20class%20monitoring%20capabilities%20and%20includes%20powerful%20built-in%20security%20features.%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3EOur%20increased%20focus%20on%20customers%20security%20concerns%20have%20led%20us%20to%20include%20enhancements%20to%20many%20security%20related%20features%20in%20recent%20SCOM%20update%20rollups.%20We%20know%20that%20organizations%20have%20strict%20controls%20and%20best%20practices%20and%20we%20want%20to%20ensure%20that%20our%20customers%20have%20the%20right%20tools%20to%20prevent%20attacks%20and%20gain%20peace%20of%20mind.%20Here%20are%20some%20of%20SCOM%E2%80%99s%20security%20offerings.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Bhavna_Appayya_0-1614748281431.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F260403i34D76188DF1D3BE8%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Bhavna_Appayya_0-1614748281431.png%22%20alt%3D%22Bhavna_Appayya_0-1614748281431.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3EA%20new%20addition%20to%20SCOM%202019%20was%20increasing%20out%20of%20the%20box%20security%20configuration%20through%20support%20for%20%3CSTRONG%3Egroup%20managed%20service%20accounts%20(gMSA).%3C%2FSTRONG%3E%3CSPAN%20style%3D%22font-family%3A%20inherit%3B%22%3EGroup%20Managed%20Service%20Accounts%20(gMSA)%20has%20been%20a%20very%20popular%20capability%20because%20it%20alleviates%20the%20need%20for%20password%20management%20%E2%80%93%20now%20all%20accounts%20used%20in%20SCOM%20can%20be%20gMSA.%20A%20detailed%20guide%20on%20how%20to%20configure%20gMSA%20accounts%20in%20lieu%20of%20your%20existing%20SCOM%20accounts%20is%20provided%20%3C%2FSPAN%3E%3CA%20style%3D%22font-family%3A%20inherit%3B%20background-color%3A%20%23ffffff%3B%22%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsystem-center%2Fscom%2Fsupport-group-managed-service-accounts%3Fview%3Dsc-om-2019%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehere.%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3EAnother%20important%20best%20practice%20is%20to%20disable%20interactive%20and%20remote%20interactive%20sessions%20for%20service%20accounts.%20SCOM%202019%20supports%20hardening%20of%20service%20accounts%20and%20does%20not%20require%20granting%20the%20%E2%80%9CAllow%20log%20on%20locally%E2%80%9D%20user%20right%20for%20several%20accounts.%20The%20default%20configuration%20on%20SCOM%202019%20Management%20Servers%2C%20Gateways%2C%20and%20Agents%2C%20is%20that%20service%20accounts%20and%20RunAs%20accounts%20will%20now%20leverage%20the%20%E2%80%9CLog%20on%20as%20a%20Service%E2%80%9D%20user%20right%2C%20and%20no%20longer%20require%20the%20%E2%80%9CLog%20on%20locally%E2%80%9D%20user%20right.%3C%2FP%3E%0A%3CP%3EAn%20additional%20security%20feature%20in%20SCOM%20is%20that%20Run%20As%20account%20credentials%20can%20also%20be%20distributed%20to%20computers%20that%20you%20specify%2C%20see%20details%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsystem-center%2Fscom%2Fmanage-security-dist-target-runas-profiles%3Fview%3Dsc-om-2019%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ehere%3C%2FA%3E%26nbsp%3B%20.%20Automatically%20distributing%20Run%20As%20account%20according%20to%20discovery%20could%20introduce%20a%20security%20risk%2C%20which%20is%20why%20customers%20can%20opt%20for%20a%20more%20secure%20option%20of%20manually%20selecting%20the%20computers%20to%20which%20the%20credentials%20will%20be%20distributed%20.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAuthentication%20in%20Operations%20Manager%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3ESCOM%20implements%20a%20default%20set%20of%20authentication%20protocols%2C%20including%20Kerberos%2C%20NTLM%2C%20Transport%20Layer%20Security%2FSecure%20Sockets%20Layer%20(TLS%2FSSL)%20as%20part%20of%20an%20extensible%20architecture.%20In%20addition%2C%20some%20protocols%20are%20combined%20into%20authentication%20packages%20such%20as%20Negotiate%20and%20the%20Credential%20Security%20Support%20Provider.%20These%20protocols%20and%20packages%20enable%20authentication%20of%20users%2C%20computers%2C%20and%20that%20in%20turn%20ensures%20access%20to%20resources%20in%20a%20secure%20manner.%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3ESCOM%20also%20mandates%20a%20least%20privileged%20model%20for%20its%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsystem-center%2Fscom%2Fplan-security-accounts%3Fview%3Dsc-om-2019%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Esecurity%20account%3C%2FA%3E%20matrix.%20The%20least%20privileged%20model%20is%20a%20best%20practice%20in%20IT%20security%20and%20the%20concept%20is%20that%20any%20user%2C%20service%2C%20or%20process%20should%20have%20only%20the%20bare%20minimum%20privileges%20necessary%20to%20execute%20the%20required%20task.%20Mandating%20this%20principle%20reduces%20the%20risk%20of%20attackers%20gaining%20access%20to%20sensitive%20data%20by%20compromising%20low%20level%20user%20accounts%20or%20devices.%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAuditing%20in%20Operations%20Manager%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3EWe%20recently%20introduced%3CSTRONG%3E%20Management%20pack%20change%20tracking%3C%2FSTRONG%3E%2C%20a%20feature%20that%20allows%20enhanced%20audit%20tracking%20capabilities%20in%20SCOM.%20Management%20Packs%20are%20essentially%20the%20arteries%20of%20SCOM%20that%20help%20the%20core%20of%20SCOM%20function%20well.%20They%20include%20monitoring%20configurations%20and%20data%20collection%20parameters%20tailored%20for%20specific%20applications%20and%20services.%20Management%20packs%20are%20released%20by%20both%20Microsoft%20and%20third-party%20vendors%20for%20a%20range%20of%20tools%20and%20applications%20that%20need%20to%20be%20monitored%20in%20the%20customer%E2%80%99s%20landscape.%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3ESCOM%20allows%20to%20be%20defined%20giving%20access%20rights%20to%20perform%20actions%20on%20the%20monitored%20objects.%20These%20roles%20can%20be%20defined%20to%20determine%20who%20can%20potentially%20change%20monitoring%20settings%20for%20applications%20and%20services%20through%20Management%20Packs.%20A%20profile%20is%20defined%20on%20a%20group%20of%20users%20which%20impose%20Role-based%20security%20and%20limit%20privileges%20that%20users%20have%20for%20various%20aspects%20of%20Operations%20Manager.%20The%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsystem-center%2Fscom%2Fmanagement-pack-change-tracking%3Fview%3Dsc-om-2019%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Echange%20tracking%20feature%3C%2FA%3E%20allows%20the%20administrators%20to%20do%20an%20easy%20root%20cause%20analysis%20as%20and%20when%20required%20to%20keep%20track%20of%20%3CSTRONG%3Ewhat%20%3C%2FSTRONG%3Echanges%20are%20being%20done%20by%20%3CSTRONG%3Ewhich%3C%2FSTRONG%3E%20user%20and%20%3CSTRONG%3Ewhen.%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3E%3CSTRONG%3ESecurity%20is%20built-into%20SCOM%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3ETo%20help%20customers%20deploy%20the%20latest%20security%20protocols%2C%20we%20enable%20%3CSTRONG%3ETransport%20Layer%20Security%20(TLS)%20protocol%20version%201.2%3C%2FSTRONG%3E%20for%20System%20Center%20Operations%20Manager%20management%20groups.%20In%20support%20of%20our%20commitment%20to%20use%20best-in-class%20encryption%2C%20SCOM%E2%80%99s%20engineering%20team%20is%20continually%20upgrading%20our%20cryptographic%20infrastructure.%20Customers%20can%20configure%20the%20Web%20console%20and%20Reporting%20server%20to%20use%20Secure%20Sockets%20Layer%20(SSL)%20connections%20to%20ensure%20that%20both%20incoming%20requests%20and%20outbound%20responses%20are%20encrypted%20prior%20to%20transmission.%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3ESystem%20Center%20Operations%20Manager%20provides%20layers%20of%20protection%20built%20into%20the%20product%20to%20safeguard%20against%20security%20breaches.%20SCOM%20follows%20Microsoft%E2%80%99s%20Software%20Development%20Lifecycle(SDL)%20policy%20%2C%20which%20considers%20security%20and%20privacy%20throughout%20all%20phases%20of%20the%20development%20process.%20The%20SCOM%20team%20uses%20Microsoft%20approved%20%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fsecurityengineering%2Fsdl%2Fresources%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ESDL%20tools%3C%2FA%3E%20like%20BinSkim%2C%20CredScan%2C%20Codesign%20Validation%2C%20and%20Anti%20malware%20to%20perform%20security%20checks%20for%20each%20line%20of%20code%20they%20produce.%20In%20addition%20to%20these%20tools%20and%20to%20add%20further%20protection%2C%20our%20code%20is%20also%20encrypted%20with%20%3CSTRONG%3ESecure%20Hash%20Algorithm%202%20(SHA-2)%3C%2FSTRONG%3E.%3C%2FP%3E%0A%3CP%20class%3D%22lia-align-justify%22%3EWe%20are%20very%20proud%20to%20offer%20a%20product%20like%20System%20Center%20Operations%20Manager%2C%20one%20that%20continues%20to%20support%20evolving%20industry%20security%20needs%20and%20strives%20to%20keep%20our%20customers%20safe%20and%20productive.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2180736%22%20slang%3D%22en-US%22%3E%3CP%3ERecent%20high%20profile%20cyberattacks%20have%20highlighted%20the%20importance%20of%20having%20strong%20standards%20and%20features%20built%20into%20infrastructure%20monitoring%20and%20management%20tools.%20Microsoft%20System%20Center%20Operations%20Manager%20(SCOM)%20offers%20world%20class%20monitoring%20capabilities%20and%20includes%20powerful%20built-in%20security%20features.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2180736%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESCOM%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESystem%20Center%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESystem%20Center%20Operations%20Manager%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Co-Authors
Version history
Last update:
‎Mar 14 2021 09:48 PM
Updated by: