Microsoft Identity Integration Server 2003 graphic

Best practices for security

Control access with Microsoft Identity Integration Server 2003 security groups.

Restrict physical access to computers to trusted personnel.

Implement user rights and permissions to restrict software access to trusted accounts.

Enforce strong password policies for all user accounts.

Implement SQL Server 2000 security best practices.

Ensure that the network context in which the server running Microsoft Identity Integration Server 2003 runs is behind a firewall.

Lock down the Microsoft Identity Integration Server 2003 service account.

Periodically change the Microsoft Identity Integration Server 2003 service account password.

Create a domain service account if your SQL Server 2000 is installed on a computer other than the one that is running Microsoft Identity Integration Server 2003.

Secure your crash dump files.

Control debug rights to the MIIServer process.

Restrict access to the Microsoft Identity Integration Server 2003 Extensions and ExtensionsCache folders.

Use SSL if you are setting initial passwords.