• subscribe


Randy Franklin Smith

Randy Franklin Smith is a contributing editor for Windows IT Pro and the creator of LOGbinder SP for SharePoint. He publishes UltimateWindowsSecurity.com, which focuses on securing Active Directory, SharePoint, and SQL Server. He’s CEO of Monterey Technology Group, a SSCP, a CISA, and a Security MVP.

Email: rsmith@ultimatewindowssecurity.com

My Latest Content
My Latest Comments



Author Articles

Three SharePoint 2010 Security Pitfalls

By Randy Franklin Smith, 08/23/2010

The short-term benefits of flexibility and quick deployment can be quickly overshadowed by security and compliance risks as organically created SharePoint sites are embedded in ...

Replacing a Buggy Microsoft Security Update

By Randy Franklin Smith, 09/26/2008

Here's what you need to know about installing a rereleased security update.

Letting a User Log on from Only a Specific Computer

By Randy Franklin Smith, 08/27/2008

Here's how to make it so that a user can log on only from a specific computer.

Learning about Virtual Machine Security

By Randy Franklin Smith, 06/26/2008

Find out how to secure VMs of different organizations or untrusted users that are being hosted on the same host system.

Securing AD Service Accounts

By Randy Franklin Smith, 05/27/2008

Learn how to prevent users from using a service account to log on to the network.

The Risks Associated with Placing DCs at Remote Sites

By Randy Franklin Smith, 03/27/2008

Find out why it’s so dangerous to place a domain controller at a remote site instead of in a data center.

The Advantage of Using an RODC Rather Than a DC

By Randy Franklin Smith, 03/27/2008

Take a look at how Windows Server 2008’s RODC features can address the risks associated with placing a DC at a remote site.

Using BitLocker, TPM, and RODCs to Prevent the Exploitation of a DC

By Randy Franklin Smith, 03/27/2008

You can use Windows Server 2008’s BitLocker Drive Encryption, Trusted Platform Module, and Read-Only Domain Controller functionality to prevent the exploitation of physically ...

Access Denied

By Randy Franklin Smith, 03/27/2008

Answers to your Windows security questions.

Strengthening Permissions on Hard Links

By Randy Franklin Smith, 03/10/2008

Access Denied

By Randy Franklin Smith, 02/28/2008

Answers to your Windows security questions.

Determining Whether Administrators Are Forcing Users to Change Their Passwords

By Randy Franklin Smith, 02/28/2008

Discover which event ID will log whether an administrator selected the "User must change password at next logon" check box.

Removing a User or Group’s Permissions

By Randy Franklin Smith, 02/28/2008

Use Icacls to remove a user or group’s allow or deny permissions from a file server.

Preventing Users from Changing IE's Security Settings

By Randy Franklin Smith, 02/28/2008

Learn how to set the security level of IE’s Internet zone and prevent users from changing it.

Determining How Windows Handles Attachments and Downloaded Files

By Randy Franklin Smith, 01/24/2008

Is Windows blocking you from opening certain files downloaded from the Internet? Find out where you can configure the policies that let you open attachments and Internet files.

Using AccessChk to View Which Files and Folders a User Has Access To

By Randy Franklin Smith, 01/24/2008

Do you need to know which folders and files a user can access? Find out how to use AccessChk to generate a report that shows what data a given user can view.

Figuring Out Why Outside Parties Aren't Receiving a Remote User's Email Messages

By Randy Franklin Smith, 01/24/2008

Find out why SPF might be preventing people outside of your organization from receiving your telecommuter's email messages.

Access Denied

By Randy Franklin Smith, 01/24/2008

Answers to your Windows security questions.

How UAC Secures Workstations

By Randy Franklin Smith, 12/27/2007

Although UAC does secure workstation OSs, it doesn't necessarily make the information stored on workstations more secure. Find out just how UAC protects workstations.

Preventing IE from Prompting for a Client Certificate

By Randy Franklin Smith, 12/27/2007

Is IE prompting your users to choose a client certificate, even if they have only one certificate to choose from? Here's how to stop IE from doing so.