Managing Image Security
It is important to properly secure boot and installation images to prevent their unauthorized use. A fully configured image might include corporate applications and data, proprietary configurations, and even codes and keys required to activate line of business (LOB) applications.
One way to prevent unauthorized installations is by controlling the clients that are allowed to receive images. You can accomplish this through pre-staging, in which clients are registered with AD DS through the use of a globally unique identifier (GUID). Another method is to enable administrative approval for client installations. Finally, you can restrict images by user as shown in the following procedure.
To configure an image file's access control list (ACL), perform the following steps:
- Right-click the image and then click Properties.
- On the User Permissions tab, configure the ACL and then click OK. The image's ACL must give a user Read and Execute permissions for the user to be able to install the image. In the following screenshot, members of the Installations group can install the image secured by this ACL.
Note In addition to securing individual images, you can secure image groups. Right-click an image group, click Security, and then configure the group's ACL on the Security tab. By default, images in an image group inherit the group's permissions.
In this tutorial:
- Configuring Windows Deployment Services
- Introducing Windows Deployment Services
- Service Architecture
- PXE Services
- Operating Modes
- Legacy Mode
- Mixed Mode
- Native Mode
- Planning for Windows Deployment Services
- Choosing a Version of Windows Deployment Services
- New Features of Windows Deployment Services in Windows Server 2008 R2
- Server Requirements
- Client Computer Requirements
- DHCP Requirements
- Routing Requirements
- Capacity Requirements
- Installing Windows Deployment Services
- Windows Server 2003
- Windows Server 2008 R2
- Windows 7 Configuring Deployment Services
- Preparing Discover Images
- Windows Importing Images
- Importing Boot Images
- Importing Install Images
- Managing and Deploying Driver Packages
- Deploying Driver Packages to Clients Using Method 1
- Deploying Driver Packages to Clients Using Method 2
- Deploying Driver Packages to Clients Using Method 3
- Managing Driver Groups and Driver Packages
- Adding Driver Packages to Boot Images
- Managing Image Security
- Pre-staging Client Computers
- Configuring Administrator Approval
- Windows 7 Installing
- Capturing Custom Images
- Creating Multicast Transmissions
- Performing Multicast Deployment
- Using Windows Deployment Services with Microsoft Deployment Toolkit