Recipe 17.1. Analyzing Your Security Configuration


You want to analyze the security configuration of one or more systems to find any vulnerabilities or missing security updates.


The Microsoft Baseline Security Analyzer (MBSA) is a freely available tool from Microsoft that lets you scan computers for the latest security problems with Windows, along with numerous Microsoft products. Some of these include Office, Exchange Server 2003, Microsoft Virtual Machine, and BizTalk. It can also check the configuration of Internet Configuration Firewall, Automatic Updates, and password settings.

MBSA has both a graphical and command-line interface. The MBSA graphical interface allows you to scan a single or multiple computers at one time (up to 10,000). Figure 17-1 shows the MBSA screen for selecting multiple computers. You can choose computers based on domain name and IP address range.

Figure 17-1. MBSA multiple computer selection screen

The MBSA command-line interface, mbsacli.exe, has the same functionality as the graphical interface. With it, you can easily automate periodic scans of your systems.

For more information on MBSA, including download instructions, see the following site:


MBSA keeps itself up-to-date with the latest vulnerabilities and security updates by automatically polling Microsoft when you start the program. As of version 1.2, you can alternately point MBSA at a SUS server to download the update catalog. This lets you determine what systems in your network are up-to-date according to your internal SUS server.

