I do some consulting work for Microsoft, one of the projects I've been
helping with in recent years is the Security Compliance Manager: SCM includes
security baselines for Windows Server 2008, Windows Server 2008 R2, SQL
2008, and SQL 2008 R2. You can export the Windows baselines in several
formats including group policy objects which you can than import into AD DS
and apply to your servers. You can also apply them locally to stand alone
servers using the Local Policy Tool that is included with SCM. The SQL
baselines can be applied using PowerShell rather than group policy.

I've been researching SharePoint 2010 extensively for the past few weeks,
I'm hoping to help Microsoft create a security guide and security baseline
for SharePoint 2010 but that project won't kick off until next year, and
only if funding is approved. At this point, nobody has a comprehensive guide
for 2010. DISA has a pretty good checklist for SharePoint 2007, but it mixes
database and OS configuration into the SharePoint checklist and obviously it
doesn't include stuff that's new in 2010 such as claims based
authentication. Neither NSA nor NIST have anything and I don't believe they
are planning on SharePoint 2010 guidance right now. I'm sure that the Center
for Internet Security is considering adding SharePoint 2010 to their list of
checklists but I don't believe that they have started working on it yet.

I suggest that you investigate SCM and if you like what you find that you
join Microsoft Connect and sign up for Beta reviews of future SCM baselines,
that would get you the earliest access to Microsoft's guidance for
SharePoint 2010 should they decide to publish a guide for it. I believe this
is the link for signing up to SCM betas:

My list of links for SharePoint 2010 security:

1. Newly published content (updated weekly)
2. Governance:
3. Security & Protection:
4. Security and protection for SharePoint Foundation 2010:
5. Security & Authentication:
6. PowerShell:
7. IT Pro Training:
8. Main site on TechNet:
9. Blog:
10. Forums:

11. Security training:
12. Labs:


Kurt Dillard, CISSP

We have quite complex policy that is not possible to summarize on a mailing
Some important point for me specific for this project (it is a public web
- The front end on internet need to a have a secure in depth configuration
(if one level fail, I don't want to have all site compromised).
I am looking both on configuration to be applied to the front end and to the
- I want to have a strong auditing level on who does what in changing the
content of the site to be able to analise possible compromise/mistake with
the change functionality.

Thank you.

>> Hello.
>> My company is working on the new internet web site.
>> It is going to be based on Sharepoint 2010 on Windows 2008 R2.
>> They are very new platform (very very new for me :-( ). Do you know
>> of any hardening guide for Sharepoint 2010? Can you give me pointers
>> on Windows 2008 Hardening or security checklist?
>> Thank you in advance.
>> Mamo

