Category Archives: Uncategorized

Attack Surface Analyzer

A really interesting tool, just released at Blackhat DC. Read the following summary: The Attack Surface Analyzer beta is a Microsoft verification tool now available for ISVs and IT professionals to highlight the changes in system state, runtime parameters and … Continue reading

Posted in Uncategorized | Leave a comment

SharePoint 2010 and IRM Permissions

Have you ever worked with SharePoint 2010 and the IRM integration? Have you asked yourself how are the IRM permission calculated, because you cannot configure that in the library settings? If yes, take a loot at this table:   Found … Continue reading

Posted in Uncategorized | Leave a comment

AD FS 2.0: Upgrade from RC to RTW

After the PG announced the RTW release of AD FS (Active Directory Federation Services) 2.0 yesterday, it is time to upgrade my RC lab to RTW: But what’s the upgrade path? First of all, a silent upgrade is not possible. … Continue reading

Posted in Uncategorized | Leave a comment

TMG’s Network Inspection System (NIS) helps to protect against SQL Injection and Cross-site Scripting

Great news! The TMG PG has added signatures to help to protect against SQL injection and Cross-site scripting: Expl:Win/HTTP.URL.SQLInj!0000-0000 contains information about the SQL injection signature Expl:Win/HTTP.URL.XSS!0000-0000 contains information about the Cross-site scripting signature URL: http://blogs.technet.com/isablog/archive/2010/05/02/network-inspection-system-nis-adds-signatures-to-help-in-sql-injection-and-cross-site-scripting-prevention.aspx

Posted in Uncategorized | Leave a comment

How to Change the Icon of a RemoteApp published with UAG 2010

If you publish a RemoteApp application, UAG uses a default RDP icon for all RemoteApps ( ). But maybe you want to use the origin application icon?! The default way when publishing RemoteApps without UAG is, that the appropriate wizard … Continue reading

Posted in Uncategorized | Leave a comment

UAG and Smartcard-based AuthN

Although a Smartcard-based AuthN is not selectable in the repository wizard (OOB), it is very easy to implement that for a specific trunk. All required steps are described on the appropriate TechNet section, therefore please see http://technet.microsoft.com/en-us/library/ee861163.aspx for more information. … Continue reading

Posted in Uncategorized | Leave a comment

Forefront Roadmap

Looking for the Forefront Endpoint Protection (aka Client Security v2) release date? Or when we’ll release the next generation of Protection for Exchange Server? Maybe this slide helps. Url: http://www.microsoft.com/forefront/en/us/roadmap.aspx

Posted in Uncategorized | Leave a comment

Welcome to my re-engineered Blog

Since September 2008, I work as a TSP Security at Microsoft Switzerland. That’s the reason why I’ve just decided to re-engineer my blog. The goals of my blog are: share my experiences from PoC’s blog about product news, e.g. releases, … Continue reading

Posted in Uncategorized | Leave a comment