Labs report: SP3 strengthens XP security

Service Pack 3 adds support for the Network Access Protection (NAP) mechanism in Windows Server 2008

Written by Dave Bailey

Microsoft's SP3 update is likely to be the final service pack for Windows XP, and consists largely of previously released updates and hotfixes. However, it does include some enhancements, the most significant of which is client support for the Network Access Protection (NAP) mechanism implemented in Windows Server 2008 (WS 2008) ­ our focus for this first look review. NAP is a policy enforcement mechanism to ensure systems connecting to a network comply with security requirements.

We tested SP3 by downloading it from Microsoft’s TechNet as a .ISO image, which we then burned to CD-ROM for deployment. The executable itself is 324MB in size, while deploying to systems took about 15 minutes and added about 400MB to XP’s image size. Tools and guidance for deployment have not fundamentally changed from Windows XP SP2, according to Microsoft, so system administrators are advised to follow these.

After deployment, we tested upgraded systems to see how NAP works. We set up our WS 2008 system for DHCP NAP enforcement by configuring it as a NAP health policy server and also a NAP enforcement server. Enforcement can also be applied to IPSec, 802.1X, and other VPN clients.

We then configured the Windows System Health Validator and defined a policy that determined whether or not to allow clients network access. The settings included options to disallow access if there were no firewall, anti-virus or anti-spyware tools deployed. We defined a policy blocking access to systems that did not have all updates installed. When clients failed to pass the system health check, a pop-up message informed the user their system needed remediation. This can be done manually, or automatically, if a remediation server has been set up.

Overall, we found it relatively easy to set up NAP protection with WS 2008 and XP SP3 clients, but firms with few IT staff may have difficulty deploying and maintaining the system.

Microsoft released to manufacturing (RTM) its Service Pack 3 (SP3) update for Windows XP on 22 April, and intended it to be generally available by 29 April. However, the update was delayed until last week owing to a compatibility issue reported by some early adopters between Microsoft Dynamics Retail Management System (RMS), and both Windows XP SP3 and Windows Vista SP1.

The Network Installation Package for Windows XP Service Pack 3 can be found here.

See also:

reader comments

related articles

Windows XP update may hit Vista sales

Some users may see XP SP3 as the perfect stop-gap until Windows 7 28 Apr 2008

XP SP3 goes RTM

Microsoft has made its latest update for Windows XP available to manufacturers, a general download is set to follow 22 Apr 2008

Crunch time for Windows Vista

Will enterprises begin migration to Microsoft’s new platform this year or hold out for a successor? 14 Jan 2008

Hyper-V launches without management tool

Microsoft has unleashed its server virtualisation technology 26 Jun 2008

XP SP3 goes RTM

Microsoft has made its latest update for Windows XP available to manufacturers, a general download is set to follow 22 Apr 2008

Windows XP update may hit Vista sales

Some users may see XP SP3 as the perfect stop-gap until Windows 7 28 Apr 2008

latest news

Comms-care mourns loss of managing director

Staff vow to continue business as usual in memory of Scott Yates who passed away at the weekend 13 Oct 2008

UK business failures hold firm

Despite the credit crunch, the number of UK firms hitting the wall increased just 3.2 per cent between Q1 and Q3 13 Oct 2008

Infosys abandons Axon bid

Bad tidyings for outsourcing sector as Infosys pulls out of bid for UK firm and slashes growth forecasts 13 Oct 2008

poll

Education gap?

Education gap?

Is there still business up for grabs in the education space?

Previous poll results

Vendor Q&A Session: Rick Wallis, NEC Computers

Vendor Q&A Session: Rick Wallis, NEC Computers

During this Q&A session Rick Wallis, UK Sales Director at NEC Computers, talks about the firm’s reasons for committing to a 100 per cent channel strategy

In The Studio with CRN: Dave Poskett, HP

CRN TV catches up with Dave Poskett, director of Solutions Partner Organisation for the UK & Ireland at HP

events

Channel Awards logo

CRN Channel Awards 2008

The Channel Awards recognise excellence and exceptional performance from businesses and individuals in the UK technology channel

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation