Specifications
26
• Whenusingsmartcardreadersandtokens,avoidassigningmanyoralloftheReaderorTokenfile
groupstogether.
Whilsttheycanbeusedtogether,morecompatibilityandeasiertroubleshootingisensuredusingjust
thespecifictokenorreaderfilesrequiredforagroupofmachines.
• Using$autoboot$us
erassignedtomachinespermanentlyforconveniencetobypassprebootlogon
asanormaleverydayoperationalclient–thereisNOsecurityindoingthis.
Thisresultsinendusersneverseeingthepre‐bootauthenticationscreen.Thereareseveralperceived
benefitstothisapproach:
‐Nousertraining
‐Nohelpdeskcallsforpassw
ordresets
‐Noadministrativeworktomapuserstomachines
‐Mostauditorssimplyrequirethatyouproveencryption,notstrongauthentication
However,thereisonemajorrisktothisapproachthatshouldoutweighalltheperceivedbenefits:the
dataisnotsecure.Ifanunauthoriseduserwantedtheda
tafromthedrive,theywouldsimplypress
thepowerbuttonandgettotheWindowsGINA.Fromthere,thereanumberofknownattacksto
accessWindows.
Instead,secureyourdatabyremoving$autoboot$userswhennotneeded(forexample,afterrolling
outaWindowsupdate).Forc
eanauthenticationtoencrypteddata.
• Usingone$autoboot$userfortoomanymachines.
Insteadusemoreautobootuserstoreducethemultipleconnectionsandloadontheautobootuser
objectinthedatabase.
Autobootuserisjustlikeanormaluserobjectinthedatabase.Soiftheaccountisacces
sedbytoo
manyendpointsatonce,itsobjectcouldbecomelockedontheservercausingerrorswiththeobject
orclient.
Asaruleofthumb,donotallowmorethan100machinestouseasingleautobootaccount.Thiscan
varywildlydependingonserverload,configurationan
doptimisation.Ofcourse,ifconcurrencyis
highandtheserverisoftenbusy,reducethisnumbermuchmore.Onetoolthatcanhelpisthe
AutoDomainpowertool.Thiscanaddandremoveindividualautobootuserstomachinesifnecessary
fordeployment.AutoDomainisnotcoveredbythisdocument.
Also,ad
dbackupautobootaccounts.Then,iftheautobootaccountisremovedfromtheendpointby
accident‐andthereisabackupaccountinplace‐theusercanremainblissfullyunaware.Theboot
codewilllookthroughallautobootusersuntilitfindsonetouse.
Soaddmorethanonefo
rexample:
$autoboot$0001,$autoboot$0002,$autoboot$0003etc.
Note:atleastversion5.2oraboveisrequiredforthistowork.
ForfurtherinformationonusingAutobootusersortheAutoDomainpowertoolcontactMcAfee
representativeswhocanarrangeMcAfeeProfessionalServicestoassist.