Labs report: SP3 strengthens XP security

Service Pack 3 adds support for the Network Access Protection (NAP) mechanism in Windows Server 2008

Written by Dave Bailey

Microsoft's SP3 update is likely to be the final service pack for Windows XP, and consists largely of previously released updates and hotfixes. However, it does include some enhancements, the most significant of which is client support for the Network Access Protection (NAP) mechanism implemented in Windows Server 2008 (WS 2008) ­ our focus for this first look review. NAP is a policy enforcement mechanism to ensure systems connecting to a network comply with security requirements.

We tested SP3 by downloading it from Microsoft’s TechNet as a .ISO image, which we then burned to CD-ROM for deployment. The executable itself is 324MB in size, while deploying to systems took about 15 minutes and added about 400MB to XP’s image size. Tools and guidance for deployment have not fundamentally changed from Windows XP SP2, according to Microsoft, so system administrators are advised to follow these.

After deployment, we tested upgraded systems to see how NAP works. We set up our WS 2008 system for DHCP NAP enforcement by configuring it as a NAP health policy server and also a NAP enforcement server. Enforcement can also be applied to IPSec, 802.1X, and other VPN clients.

We then configured the Windows System Health Validator and defined a policy that determined whether or not to allow clients network access. The settings included options to disallow access if there were no firewall, anti-virus or anti-spyware tools deployed. We defined a policy blocking access to systems that did not have all updates installed. When clients failed to pass the system health check, a pop-up message informed the user their system needed remediation. This can be done manually, or automatically, if a remediation server has been set up.

Overall, we found it relatively easy to set up NAP protection with WS 2008 and XP SP3 clients, but firms with few IT staff may have difficulty deploying and maintaining the system.

Microsoft released to manufacturing (RTM) its Service Pack 3 (SP3) update for Windows XP on 22 April, and intended it to be generally available by 29 April. However, the update was delayed until last week owing to a compatibility issue reported by some early adopters between Microsoft Dynamics Retail Management System (RMS), and both Windows XP SP3 and Windows Vista SP1.

The Network Installation Package for Windows XP Service Pack 3 can be found here.

Tags:

reader comments

related articles

Windows XP update may hit Vista sales

Some users may see XP SP3 as the perfect stop-gap until Windows 7 28 Apr 2008

 

XP SP3 goes RTM

Microsoft has made its latest update for Windows XP available to manufacturers, a general download is set to follow 22 Apr 2008

Crunch time for Windows Vista

Will enterprises begin migration to Microsoft’s new platform this year or hold out for a successor? 14 Jan 2008

Microsoft publishes latest Release Candidate of Vista SP2

Reports also emerge of an Internet Explorer removal option in Windows 7 05 Mar 2009

Microsoft releases final beta of Vista SP2

Test versions of Vista and Windows Server 2008 SP2 go out to MSDN and TechNet subscribers 26 Feb 2009

Intel lifts the lid on Centrino 2 laptops - update

Delayed mobile platform finally ready to ship 15 Jul 2008

related whitepapers

today's top stories

CIO priorities for the next six months: the Gartner view

Gartner research director Dave Aron outlines the three key priorities for IT leaders during the second half of 2009 13 Jul 2009

The wishful CIO – the further adventures of Bob

Like a phoenix, Bob has risen from the ashes of his once fast-tracked career . He is pursuing a green agenda as... 10 Jul 2009

Infallabile opposition to outsourcing

The Holy Father, Pope Benedict, has warned of the dangers of outsourcing. Yes, you’d better believe it. The Vatican is now stepping... 10 Jul 2009

Google Chrome OS - We didn't see that coming did we?

Reading through the various news and blog sites on the internet it seems the wheels of the rumour mill are turning apace... 10 Jul 2009

Strength through unity

The friction that has traditionally characterised relations between finance and IT has no place in today’s business landscape 08 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will Google Chrome OS be a genuine alternative to Windows?

Will Google Chrome OS be a genuine alternative to Windows?

Tell us your views on the new operating system rivalry

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation