<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>SharePoint Magazine &#187; access</title>
	<atom:link href="http://sharepointmagazine.net/tag/access/feed" rel="self" type="application/rss+xml" />
	<link>http://sharepointmagazine.net</link>
	<description>SharePoint Magazine is an online Magazine dedicated to the world of SharePoint</description>
	<lastBuildDate>Mon, 05 Jul 2010 09:14:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Microsoft Office SharePoint Server 2007 Security Model</title>
		<link>http://sharepointmagazine.net/technical/administration/microsoft-office-sharepoint-server-2007-security-model</link>
		<comments>http://sharepointmagazine.net/technical/administration/microsoft-office-sharepoint-server-2007-security-model#comments</comments>
		<pubDate>Wed, 23 Jul 2008 05:51:37 +0000</pubDate>
		<dc:creator>mcardarelli</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Technical]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[audiences]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[model]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[search]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sharepoint]]></category>

		<guid isPermaLink="false">http://sharepointmagazine.net/?p=127</guid>
		<description><![CDATA[The purpose of this document is to explore the security model of MOSS and to explain how it is equipped to meet corporate security requirements. This document is not intended to recommend how to configure MOSS, nor does it try to answer why an organization should use MOSS.]]></description>
			<content:encoded><![CDATA[<p><strong><span style="Arial Narrow;">About Microsoft Office SharePoint Server 2007</span></strong></p>
<p><span>Microsoft Office SharePoint Server 2007 (referred to throughout this document as “MOSS”) is a software platform that is used to create web-based portal solutions such as Corporate Portals, Corporate Web Sites, Extranets, Intranets, and Internet Sites.<span style="yes;"> </span>A web application built using MOSS is essentially a fully packaged ASP.NET application including management and configuration tools, integrated Web Part architecture, and an end-to-end security model. <span style="yes;"> </span>It also includes features that provide site provisioning, business intelligence, business process management, collaboration, content management, and enterprise search.</span></p>
<p><span> </span></p>
<p><strong><span style="x-large;"><span style="Arial Narrow;">Introduction</span></span></strong></p>
<p><span>In order for a web application to exist in today’s business environment, it must stand up to modern day information security standards.<span style="yes;"> </span>Additionally, organizations maintain their own sets of information security policies, corporate compliance requirements and technical specifications.<span style="yes;"> </span>The purpose of this document is to explore the security model of MOSS and to explain how it is equipped to meet corporate security requirements.<span style="yes;"> </span>This document is not intended to recommend how to configure MOSS, nor does it try to answer why an organization should use MOSS.</span></p>
<h1><span style="10pt;"><span style="Arial Narrow;"> </span></span></h1>
<p class="MsoNormal" style="0in 0in 0pt;"><strong><span style="18.0pt;">Web Application Composition</span></strong></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;">The term web application refers to a single named instance of a MOSS solution such as a corporate portal or a project collaboration web site.<span style="yes;"> </span>A MOSS web application is composed of a collection of web sites (site collections) as multiple web pages are necessary in a solution such as a portal.</span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;">It is important to note that these web sites are structured in a hierarchical fashion much like Windows folders.<span style="yes;"> </span>There is one root web site and often this root site is labeled as “Home” and it is the first site the end user sees when he/she enters the portal.<span style="yes;"> </span>Beneath the root site are top level sites.<span style="yes;"> </span>Top level sites may contain multiple sub-sites; sub-sites may also contain more sub-sites, and this pattern can continue downward in the hierarchy.</span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;">Each site in the hierarchy contains at least one content page.<span style="yes;"> </span>Content pages include the navigational elements, headings, images, and content that the user sees when they navigate to the site.<span style="yes;"> </span>Content pages also contain web parts.</span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;">In order to have a complete understanding of the SharePoint security model, it is important to understand what web parts are and how they are used in content pages.<span style="yes;"> </span>Web parts are the individual building blocks that provide functionality and content on a content page.<span style="yes;"> </span>Web parts have properties.<span style="yes;"> </span>Properties define the appearance, behavior, and other characteristics of the web part.<span style="yes;"> </span>There are different types of web parts and each type of web part serves a distinct purpose for the content page that contains it.<span style="yes;"> </span>For example, a Content Editor Web Part may be used on a site to present a welcome message on that site, while an Image Web Part may be used to position an image on a content page.</span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;">For purposes of explaining the security concepts of web parts throughout this document, there are web parts that contain items and there are web parts that do not contain items.<span style="yes;"> </span>Web parts that contain items have additional security capabilities.</span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;">One web part that contains items, like records in a database table, is a Custom List.<span style="yes;"> </span>Custom Lists have several properties; list columns are an important example of this.<span style="yes;"> </span>Columns define what type of information is stored in the list pertaining to each list item.<span style="yes;"> </span>Columns can be of a wide range of data types such as single line of text, multiple lines of text, number, currency, date and time, or even the value resulting from a regular expression.<span style="yes;"> </span>An example of a custom list may be a list of departments in an organization.<span style="yes;"> </span>The list can contain columns to track department name, department manager, number of employees, and so forth, as shown in <strong><em>Figure 1</em></strong> below.</span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="center;" align="center"><img style="middle;" src="http://sharepointmagazine.net/wp-content/uploads/2008/07/cardarelli_security_figure1.bmp" alt="" width="707" height="148" /></p>
<p class="MsoCaption" style="center;" align="center"><a name="_Ref164489794"><strong><span style="Arial;">Figure </span></strong></a><strong><span style="x-small;"><span style="Arial;"><span style="_Ref164489794;"><span style="yes;">1</span></span></span></span></strong></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;">A document library also contains items.<span style="yes;"> </span>Document libraries are intended to store documents and metadata describing the documents.<span style="yes;"> </span>Each document with its corresponding metadata fields make up an item in the document library.<span style="yes;"> </span>For example, a document library may store technical documents and there may be columns for tracking information about the document such as the author, content type, and the date the document was created.<span style="yes;"> </span>An item would refer to the document, and the fields describing the document author, content type, and date created.</span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="387.0pt;"><span><span style="x-small;">Web parts which contain items generally allow file attachments.<span style="yes;"> </span>It is important to note that MOSS has the ability to block certain types of files from being uploaded into a MOSS web application.<span style="yes;"> </span>For example, .EXE files are considered risky because they can contain malicious code and virus.<span style="yes;"> </span>Many organizations choose to block .EXE files from being sent and received within their email systems to eliminate the risk that these types of files could cause ill effect.<span style="yes;"> </span>There is a management screen available in MOSS where a list of blocked file extensions is maintained.<span style="yes;"> </span>File extensions are added to the list to block the file type, and removed from the list to allow the file type.<span style="yes;"> </span>In MOSS, several file types are blocked by default.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><strong><span style="18.0pt;">Accessibility</span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">MOSS web applications utilize IIS web sites and application pools.<span style="yes;"> </span>As is the case with any web site, a unique combination of IP address, port number, and host header on each web site is required in order for the web site to run properly.<span style="yes;"> </span>Additionally, the web site must maintain a unique identity with respect to other nodes on the network in order for users on the network to be able to access the web application.<span style="yes;"> </span>Network configurations and services that exist between the users and the MOSS server including DNS, WINS, firewalls, routers, switch ports, virtual LANs, must also be configured in such a manner as to permit the user to access the IIS web site.<span style="yes;"> </span>In an Extranet configuration, an externally facing host name or IP address must be published so that users can access the web application.<span style="yes;"> </span>The hardware configuration of the MOSS server, the network configuration of the MOSS network, and the IIS configuration of the web sites for the MOSS web applications provide user accessibility to the web application.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><strong><span style="18.0pt;">Authentication</span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">In order for people to use a MOSS web application, the web application must validate the person’s identity.<span style="yes;"> </span>This process is known as authentication.<span style="yes;"> </span>MOSS is not a directory service and the actual authentication process is handled by IIS, not MOSS.<span style="yes;"> </span>However, MOSS is responsible for authorization to MOSS sites and content after a user successfully authenticates.<span style="yes;"> </span>Authentication happens like this:<span style="yes;"> </span>A user points their browser at a MOSS site and IIS performs the user validation using the authentication method that is configured for the environment.<span style="yes;"> </span>If the user authentication is successful, then MOSS renders the web pages based on the access level of the user.<span style="yes;"> </span>If authentication fails, the user is denied access to the MOSS site.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Authentication methods determine which type of identity directory can be used and how users are authenticated by IIS.<span style="yes;"> </span>MOSS supports three methods of authentication: Windows, ASP.NET Forms, and Web Single Sign-On.<span style="yes;"> </span></span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Windows Authentication is the most common authentication type used in MOSS intranet deployments because it uses Active Directory to validate users.<span style="yes;"> </span>When Windows Authentication is configured, IIS uses the Windows authentication protocol that is configured in IIS.<span style="yes;"> </span>NTLM, Kerberos, certificates, basic, and digest protocols are supported.<span style="yes;"> </span>When Windows authentication is configured, the security policies which are applied to the user accounts are configured within Active Directory.<span style="yes;"> </span>For example, account expiration policies, password complexity policies, and password history policies are all defined in Active Directory and not in MOSS.<span style="yes;"> </span>When a user attempts to authenticate to a MOSS web application using Windows authentication, IIS validates the user against NTFS and Active Directory, and once the validation occurs the user is authenticated and the access levels of that user are then applied by MOSS.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span style="x-small;"><strong><em><span>Figure 2</span></em></strong><span> below, taken from Microsoft TechNet, illustrates the MOSS authentication process.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><img style="middle;" src="http://sharepointmagazine.net/wp-content/uploads/2008/07/cardarelli_security_figure2.bmp" alt="" width="547" height="734" /></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span style="Verdana;"> </span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Anonymous access is considered to be a Windows authentication method because it associates unknown users with an anonymous user account (IUSR_MACHINENAME).<span style="yes;"> </span>Anonymous access is commonly used in internet Web sites and in situations where web site users will not have their own user accounts.<span style="yes;"> </span>Since exposing content to unknown users is risky, this configuration is disabled by default.<span style="yes;"> </span>In order to configure anonymous access to a MOSS web application, anonymous access must be enabled in IIS, enabled in the MOSS web application, and the anonymous user account must be provisioned throughout the MOSS Web application.<span style="yes;"> </span>Even when anonymous access is configured, there are still several limitations compared to a Windows user.<span style="yes;"> </span>By default, anonymous users are only allowed to read, and they are unable to edit, update, or delete content.<span style="yes;"> </span>Additionally, anonymous users are not able to utilize personalization features such as Microsoft Office integration, check-in/check-out and email alerts.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">The ASP.NET Forms authentication method is commonly used in situations where a custom authentication provider is required.<span style="yes;"> </span>In other words, where a custom LDAP, SQL Server, or other type of identity repository will be storing user account information.<span style="yes;"> </span>This is common in extranet environments, such as partner collaboration sites, where it is not practical to create Active Directory user accounts for users or a different type of directory is required. </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">The Web Single Sign-On authentication method is used in environments that have federated identity systems or single sign-on systems configured.<span style="yes;"> </span>In this type of environment, an independent identity management system integrates user identities across heterogeneous directories and provides the user validation for IIS.<span style="yes;"> </span>Some examples of identity management systems with single sign-on capability include Microsoft Identity Information Server with Active Directory Federation Services, Oracle Identity Management with Single Sign-On and Web Access Control, Sun Microsystems Java System Identity Manager, and Netegrity SiteMinder.<span style="yes;"> </span>Large enterprises often implement federated identity models to ease the administration of user provisioning and de-provisioning for systems that span across companies.<span style="yes;"> </span>Single Sign-On systems are used to consolidate user accounts across heterogeneous systems, allowing the end user to authenticate to systems with one set of credentials, rather than to use a different set of credentials for each unique system.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">In MOSS, it is possible to configure web applications to use a combination of authentication methods.<span style="yes;"> </span>This provides a great deal of flexibility because it makes it possible to serve a web application to different user bases which have different identity requirements.<span style="yes;"> </span>For example, an organization may have a Project Collaboration Web site that is used by employees and partners.<span style="yes;"> </span>For security and compliance reasons, it is necessary to store employee user accounts in Active Directory and partner user accounts in a SQL Server database.<span style="yes;"> </span>In this case, MOSS can be configured to use Windows authentication and ASP.NET Forms authentication.<span style="yes;"> </span>This is achieved by defining various zones and associated authentication methods to the zones.<span style="yes;"> </span>In the example above, an intranet zone would be configured with Windows authentication and an extranet zone would be configured with ASP.NET Forms authentication.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><strong><span style="18.0pt;">Access</span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">As explained in previous sections, the composition of a MOSS web application includes sites, content pages, and web parts.<span style="yes;"> </span>MOSS has several management controls in place for provisioning access to and within a web application.<span style="yes;"> </span></span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Users, groups, permissions, and permission levels are used to configure access within a MOSS Web application.<span style="yes;"> </span>MOSS provides management and configuration functionality for these objects.<span style="yes;"> </span>In MOSS, users are added from the directory service such as Active Directory.<span style="yes;"> </span>Once users are added to a site collection, they are added to groups and assigned permissions on sites, lists, and items.<span style="yes;"> </span>MOSS supports the creation of SharePoint groups, for which the memberships are maintained within MOSS.<span style="yes;"> </span>Additionally, Active Directory security groups may also be used directly in MOSS.<span style="yes;"> </span>Active Directory group memberships are managed in Active Directory.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Users and groups gain access or are restricted access to sites and Web Parts based upon permission levels set for the users and groups.<span style="yes;"> </span>Permissions are individual rights that may be performed by a user in a site, list, or item and so these types of permissions are referred to as Site Permissions, List Permissions, and Item Permissions, respectively.<span style="yes;"> </span>There are over thirty permissions in MOSS.<span style="yes;"> </span></span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Permissions are applied to users and groups using permission levels.<span style="yes;"> </span>Permission levels allow roles to be defined, consisting of unique combinations of individual permissions.<span style="yes;"> </span>MOSS provides some default permission levels such as “Contribute and “Full Control,” but in addition to using the default permission levels, custom permissions can be created in cases where a more appropriate name is required or a unique combination of permissions is more appropriate than what is available by default.<span style="yes;"> </span>Existing permission levels may be copied and used as starting point when creating custom permission levels.<span style="yes;"> </span>Permissions are assigned to users and groups in a similar fashion as in the Windows operating system.<span style="yes;"> </span>Much like the access control lists that allow assigning permissions to users and groups on Windows folders, MOSS provides similar access control lists on sites, lists, and items.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">The relationship between sites, lists, and items is hierarchical in nature and the default behavior within MOSS web applications is that the permissions are inherited by child objects from the parent objects.<span style="yes;"> </span>In cases where business requirements are such that a child object is required to have different permissions than the parent object, then the permission inheritance chain may be broken manually using the access control list of the child object and the child object may be configured with permissions different from its parent.<span style="yes;"> </span>When this type of modification is made then all child objects of the modified object inherit the new settings.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">To provide an example of this, imagine a MOSS site that contains a document library, which contains a set of documents.<span style="yes;"> </span>By default, the document library will inherit permissions from its parent site and each document contained within the document library will inherit permissions from the document library.<span style="yes;"> </span>Say, for instance, that there is a requirement that the document library has different permissions than the site; perhaps a group of users should be able to read contents of a site, but not be able to view contents of a document library.<span style="yes;"> </span>The permissions for the document library may be configured accordingly.<span style="yes;"> </span>Doing so will achieve the desired result and not affect the permissions of the parent site.<span style="yes;"> </span>Additionally, individual document (item) permissions may be configured so that they have different permissions than the modified document library.<span style="yes;"> </span>Keep in mind that since the relationship between the objects is hierarchical, users must at least have read access to the parent in order to gain access to the child object.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> <img style="middle;" src="http://sharepointmagazine.net/wp-content/uploads/2008/07/cardarelli_security_figure3.bmp" alt="" width="664" height="195" /></span></span></p>
<p class="MsoCaption" style="center;" align="center"><strong><span style="Arial;"><span style="x-small;">Figure <span style="yes;">3</span></span></span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span style="Verdana;"> </span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">The access control lists for sites, lists, and items are very similar.<span style="yes;"> </span>However, lists provide one additional configuration menu called advanced settings, which allows an added layer of security to be set on the child items.<span style="yes;"> </span>Within advanced settings specifications may be made such that users can view all items or view only their own items.<span style="yes;"> </span>There is also a setting for specifying that users can edit all items, their own items, or no items in the list.<span style="yes;"> </span></span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><img style="middle;" src="http://sharepointmagazine.net/wp-content/uploads/2008/07/cardarelli_security_figure4.bmp" alt="" width="270" height="149" /></p>
<p class="MsoCaption" style="center;" align="center"><strong><span style="x-small;"><span style="Arial;">Figure <span style="yes;">4</span></span></span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span style="Verdana;">Additionally, document libraries can contain folders and it is possible to set permissions on these folders.</span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span style="Arial;"><img style="middle;" src="http://sharepointmagazine.net/wp-content/uploads/2008/07/cardarelli_security_figure5.bmp" alt="" width="550" height="319" /></span></p>
<p class="MsoCaption" style="center;" align="center"><strong><span style="Arial;"><span style="x-small;">Figure <span style="yes;">5</span></span></span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><strong><span style="18.0pt;">Audiences</span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Not all MOSS Web Parts have access control lists: only those Web Parts which contained items such as lists and document libraries.<span style="yes;"> </span>However, all Web Parts do support audiences.<span style="yes;"> </span>Audiences are used to target content to users.<span style="yes;"> </span>SharePoint Groups, AD Groups, AD Users, and global audiences may be used to define the audience of a particular Web Part.<span style="yes;"> </span>Audiences allow the restriction and filtering of certain content that exists on a content page to users who otherwise have some level of access to the page.<span style="yes;"> </span>For example, an organization may have a MOSS portal that serves employees, contractors, and partners.<span style="yes;"> </span>Perhaps there is an employee announcement Web Part on the home page.<span style="yes;"> </span>It may not be appropriate for contractors and partners to view the employee announcements.<span style="yes;"> </span>It is possible to target the employee announcements Web Part to a specific audience, in this case a security group called employees.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><img style="middle;" src="http://sharepointmagazine.net/wp-content/uploads/2008/07/cardarelli_security_figure6.bmp" alt="" width="239" height="371" /></p>
<p class="MsoCaption" style="center;" align="center"><strong><span style="x-small;"><span style="Arial;">Figure <span style="yes;">6</span></span></span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><strong><span style="18.0pt;">Search</span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">In MOSS, users are able to search for content across many different content sources such as MOSS portals, Web sites, network file shares, structured data stored in line of business systems, and people profiles stored within Active Directory and other custom data sources.<span style="yes;"> </span>The MOSS security model is fully integrated with the search feature and therefore all of the content access concepts that apply to sites, web parts, and items also apply to search results.<span style="yes;"> </span>For example, if a user does not have read access to a particular document library and the user performs a search, that user’s search results will not include any links to the document library or any documents contained within that document library.<span style="yes;"> </span>Likewise, if a user only has read access to a particular document and the user opens a link to that document from a search results page, that user will be unable to edit that document.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">There are several management controls available with MOSS that allow for custom tailoring of how content is crawled, what content can be searched, and how the search results appear to the end users who are performing the search.<span style="yes;"> </span>Using these controls, MOSS search can be configured to meet unique security and compliance requirements for searching content.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><strong><span style="18.0pt;">Administration</span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">In MOSS, there are two types of administrators that are configured, which allows the responsibilities associated with server component configuration to be separated from those responsibilities associated with content management and content access management.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Central Administrators are used to configure SharePoint components on a server.<span style="yes;"> </span>By default these administrators don’t have access to modify content contained within site collections.<span style="yes;"> </span>Central Administrators are able to grant themselves access to content contained within site collections and events related to this are tracked in the event log for auditing purposes.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Site Collection Administrators are assigned at the site collection level and have full control over content contained in that site collection.<span style="yes;"> </span>Site Collection Administrators are able to perform all the necessary tasks involved with administering content including the ability to restore content that has been deleted from the Recycle Bin and override check-out of documents.<span style="yes;"> </span>Site Collection Administrators are configured in a separate menu than where other types of users are provisioned and it is impossible for other types of users to revoke permissions from Site Collection Administrators. </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><strong><span style="18.0pt;">Hardware, Software, and Network</span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Beyond the context of the MOSS application itself, there are several security related topics that have to do with the way MOSS is installed and configured in a network environment.<span style="yes;"> </span>It is important to understand the server and network topology of a MOSS deployment because many of the security considerations exist at this level.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">The major software components included in a MOSS installation are the Windows Operating System, IIS, .NET Framework, SQL Server, and MOSS.<span style="yes;"> </span>As an ASP.NET application, the principles of .NET code access security apply to MOSS installations.<span style="yes;"> </span>Configuration files on MOSS servers such as machine.config and web.config are used to prevent or allow code from being run on MOSS systems.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">MOSS is designed to be scalable so that it can be configured to serve small workgroups, large enterprises, or serve public Internet sites.<span style="yes;"> </span>The MOSS application is divided into several different services that can run on one server in a single server deployment or divided across multiple servers in a server farm deployment.<span style="yes;"> </span>Servers in a server farm can have various roles, meaning that they have certain services running on them.<span style="yes;"> </span>For example a two-server farm may include a database server that runs only the database components and a web server than runs the web applications and application services.<span style="yes;"> </span>MOSS servers are required to communicate with each other and with end users and this communication occur on channels.<span style="yes;"> </span>It is certainly possible to secure these channels, and MOSS does support doing so.<span style="yes;"> </span>For example, it is possible to use SSL to secure a channel between a Web server and a client machine or IPSec to secure a channel between two servers.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">On the network, there are several other areas that relate to the security of MOSS.<span style="yes;"> </span>Servers exist as nodes on a TCP/IP network and networks can be running a wide variety of hardware including switches, routers, firewalls, and load balancers.<span style="yes;"> </span>The network security of a MOSS server farm depends upon the configuration on these network devices.<span style="yes;"> </span>For example, a network may be configured with multiple network segments, DMZs, or VLANs.<span style="yes;"> </span>MOSS servers can be configured to operate in unique TCP/IP network environments.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><strong><span style="18.0pt;">Conclusion</span></strong></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Microsoft Office SharePoint Server 2007 is equipped to meet complex business requirements pertaining to security and compliance for Web applications in every security context.<span style="yes;"> </span>MOSS has a robust security model that provides management capabilities for controlling how MOSS is configured in a network, controlling how users access web applications, and controlling user access to content within web applications.<span style="yes;"> </span>The security model integrates seamlessly with Windows Server, Active Directory, Exchange Server, SQL Server, IIS and the .NET Framework.<span style="yes;"> </span>MOSS can be configured in many different ways to meet varying needs.<span style="yes;"> </span>The platform is also highly customizable, so there are virtually no hard limitations when building a web application solution using MOSS.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;">
<div class="Section1">
<h1><span style="x-large;"><span style="Arial Narrow;">About the Authors</span></span></h1>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Mauro Cardarelli is a Director at Vitale Caturano, a Boston-based information technology consulting company. His responsibilities include technology evangelism, architecture design, and software development. He can be reached at <a href="mailto:mauro.cardarelli@vitale.com">mauro.cardarelli@vitale.com</a>.</span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;"> </span></span></p>
<p class="MsoNormal" style="0in 0in 0pt;"><span><span style="x-small;">Nicholas Bisciotti is a Senior Consultant at Vitale. His responsibilities include Microsoft technology-based implementation and development. He can be reached at <a href="mailto:nicholas.bisciotti@vitale.com">nicholas.bisciotti@vitale.com</a>.</span></span></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://sharepointmagazine.net/technical/administration/microsoft-office-sharepoint-server-2007-security-model/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
	</channel>
</rss>
