Microsoft Previews Web Server Security Baseline Tool

Microsoft this week offered yet another preview of a new Operations Management Suite (OMS) feature, this time focused on checking the security compliance of Windows Web servers.

The new Web Security Baseline Assessment preview is part of the OMS Security and Audit Solution. It compares Microsoft's recommendations for Web server configurations with the configurations detected on the customer's premises. It also can be used to scan the Web server security baselines used on Microsoft Azure or "other cloud platforms" that OMS can monitor. OMS is Microsoft's solution for managing public cloud workloads.

The Web Security Baseline Assessment preview will check registry rules, audit policies and security policies for Windows Web servers, including .NET, ASP.NET and Internet Information Services configurations, according to Microsoft's documentation. It scans Web servers every 24 hours as part of this process. Users see results in the OMS Security and Audit dashboard.

The dashboard shows the machines that passed. based on Microsoft's baseline security settings recommendations, along with the compliance percentage numbers. There's also a list of failures, along with severity rankings. Machines that weren't assessed get listed, too. Users can create their own custom dashboards from the queries used by the tool via the OMS View Designer.

OMS supports running these baseline profiles on Web Servers using Windows Server 2008 R2 through Windows Server 2012 R2. Microsoft is still working on adding support for Windows Server 2016, according to this Microsoft document.

About the Author

Kurt Mackie is senior news producer for the 1105 Enterprise Computing Group.


  • Tamper Protection Now Available to Microsoft Defender ATP Subscribers

    The Microsoft Defender Advanced Threat Protection (ATP) E5 subscription plan now has an optional "tamper protection" security feature, Microsoft announced on Monday.

  • Exploring OCR, a New Way To Get Data into Excel

    Microsoft recently added a new optical character recognition feature to Excel that lets users import data from a photograph taken from a smartphone. Here's how to use it.

  • Microsoft Authenticator App To Get Real-Time Phishing Protections

    Microsoft is working on adding capabilities to its Microsoft Authenticator app to help defeat security breaches enabled by advanced attack techniques, including phishing and man-in-the-middle methods.

  • A Quicker Way To Create Hyper-V Inventory Reports

    If you need to generate Hyper-V inventory reports but don't want the hassle of writing your own custom PowerShell script, here is a shortcut.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.