36C24219Q0513-009.pdf

PDF 3 MB Posted

Attached to
Sources Sought-Viral Load Tester Federal contract opportunity
Solicitation number
36C24219Q0513
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 2

About this file

36C24219Q0513 Endpoint Baselines.pdf

View the file

Other files for this federal contract opportunity

Other files attached to Sources Sought-Viral Load Tester, newest first.
File Type Posted
36C24219Q0513-007.pdf PDF
36C24219Q0513-006.docx DOCX document
36C24219Q0513-008.pdf PDF
36C24219Q0513-000.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Solution Delivery Endpoint Engineering Desktop and Device Engineering

Endpoint Baselines Version 2.0

March 12, 2019 | IT Operations and Services

OFFICE OF INFORMATION AND TECHNOLOGY

IT Operations and Services

Revision History

Date Reason for Changes Version Author

09/25/2017 Initial Document 1.0 Kevin Overholt

02/21/2018 SEDR18-1810, Endpoint Baselines (Bed Management Solution (BMS) Whiteboard Kiosk, VM Non-Persistent Desktop, VM Persistent Desktop, Windows 10, and TeleHealth) are now considered ratified.

Updated document with Ratified Date: for above baselines.

1.1 Kevin Overholt

02/26/2018 Reformatted document and repaired indexing

(TOC).

1.1 Bob Leahy (Technical Writer)

03/30/2018 Added CSP Bingo for SEDR review 1.2 Kevin Overholt

03/30/2018 Replaced document cover and regenerated TOC. 1.2 Bob Leahy (Technical Writer)

04/06/2018 Update TeleHealth adding Dell information 1.2 Kevin Overholt

04/06/2018 Reformatted document and changed main document baseline sections to appendices.

Edited for 508 Compliance.

1.2 Bob Leahy (Technical Writer)

04/11/2018 Updated CSP Bingo Board Kiosk SEDR Ratification 1.2 Kevin Overholt

04/11/2018 Repaired/edited and added screenshots back into document to meet 508 Compliance.

1.3 Bob Leahy (Technical Writer)

04/11/2018 Added comments to be addressed 1.4 Bob Leahy (Technical Writer)

04/24/2018 Repaired items in CSP Bingo Board Kiosk section (508 Compliance)

1.5 Bob Leahy (Technical Writer)

04/24/2018 Replied to comments and updated information 1.5 Kevin Overholt

04/27/2018 Cleared previous comments and applied changes. Applied baseline document template to update format and styles.

1.6 Bob Leahy (Technical Writer)

04/30/2018 Repaired links and inserted new image. 1.7 Bob Leahy (Technical Writer)

06/05/2018 Updated links to VA Naming Conventions website 1.8 Bob Leahy (Technical Writer)

06/18/2018 Added the following baselines: Burial Schedule Display Kiosk, Digital Signage Kiosk, USAccess Mobile Credentialing Unit, Windows 10 Generic Kiosk, Windows 7 Generic Kiosk

1.9 Bob Leahy (Technical Writer)

06/28/2018 Updated path from root\Specialized Systems\ CSPBB\yourcomputer to root\Specialized Systems\Kiosks\CSPBB\yourcomputer in CPS Bingo Board Kiosk appendix

1.10 Bob Leahy (Technical Writer)

07/09/2018 Added baseline ratification dates for Digital Signage Kiosk, Windows 7 Generic Kiosk, USAccess Mobile Credentialing Unit (MCU), Burial Schedule Display Kiosk and Windows 10 Generic Kiosk.

1.11 Bob Leahy (Technical Writer)

08/10/2018 Updated Appendix R: USAccess Mobile Credentialing Unit.

1.12 Kevin Overholt

08/10/2018 Applied new baseline document template, reviewed updates, regenerated TOC and reposted.

1.12 Bob Leahy (Technical Writer)

08/20/2018 Updated naming convention section for USAccess Mobile Credentialing Unit

1.13 Bob Leahy (Technical Writer)

09/10/2018 Removed BHL SOLUTIONS and CITRIX ENDPOINT LOCKDOWN information (both items decommissioned)

1.14 Bob Leahy (Technical Writer)

03/06/2019 Updated Digital Signage Kiosk required OU to root\Specialized Systems\Kiosks\DIGS\ yourcomputer per Dan Z.

1.15 Bob Leahy (Technical Writer)

03/12/2019 Modified document to include all Windows 7 sub-baselines in one appendix and all Windows 10 sub-baseline in another appendix. Added Windows 10 sub-baseline for VM Persistent Desktop (per Kevin Overhold)

2.0 Bob Leahy (Technical Writer)

Table of Contents

1 PURPOSE

2 HARDWARE

3 APPLICATIONS

4 BUILD METHOD

5 COMPUTER NAMING

6 ACTIVE DIRECTORY

7 GROUP POLICY OBJECTS

8 ENCRYPTION

9 SYSTEMS ENGINEERING AND DESIGN REVIEW

10 REPORTING

11 CONTACTS

12 ADDITIONAL REFERENCES AND LINKS

APPENDIX A: WINDOWS 7 BASELINE

A.1 Hardware

A.2 Applications

A.3 Build Method

A.4 Computer Naming

A.5 Active Directory

A.6 Group Policy Objects

A.7 Encryption

A.8 Systems Engineering and Design Review

A.9 Reporting

APPENDIX B: WINDOWS 7 SUB-BASELINES

B.1 Audiology Workstation

B.2 Bed Management Solution (BMS) Whiteboard Kiosk

B.3 BHL Solutions

B.4 Citrix Endpoint Lockdown

B.5 CMOP Production Floor Systems

B.6 Environment of Care (EOC)

B.7 Environmental Management Service (EMS) Bed Management Solution (BMS)

March 2019 Endpoint Baselines | i

March 2019 Endpoint Baselines | ii

B.8 HealtheVet Kiosk

B.9 Howdy Kiosk

B.10 Medical Device Protection Program (MDPP)

B.11 PICIS

B.12 PIV Issuing Stations

B.13 Real Time Location System (RTLS)

B.14 TeleHealth

B.15 Voice Assisted Manikin (VAM)

B.16 VSS Kiosk

B.17 VM Non-Persistent Desktop

B.18 VM Persistent Desktop

B.19 Windows 7 Generic Kiosk

APPENDIX C: WINDOWS 10 BASELINE

C.1 Hardware

C.2 Applications

C.3 Build Method

C.4 Computer Naming

C.5 Active Directory

C.6 Group Policy Objects

C.7 Encryption

C.8 Systems Engineering and Design Review

C.9 Reporting

C.10 Baseline Specific Instructions

APPENDIX D: WINDOWS 10 SUB-BASELINES

D.1 Burial Schedule Display Kiosk

D.2 CMOP Production Floor Systems

D.3 CSP Bingo Board Kiosk

D.4 Digital Signage Kiosk

D.5 VM Persistent Desktop

D.6 USAccess Mobile Credentialing Unit

D.7 Windows 10 Generic Kiosk

March 2019 Endpoint Baselines | iii

Figures Figure 1. Standards for Baseline portal page

Figure 2. Dialog box Security tab

Figure 3. Facility Configuration window

Figure 4 - Whiteboard Kiosk User Role Assignment Fields

Figure 5. BMS WhiteBoard Configuration dialog box

Figure 6. Computer Management - System Tools - Task Scheduler

Figure 7. Create Task dialog box – General tab

Figure 8. Create Task dialog box – Trigger tab

Figure 9. New Trigger dialog box

Figure 10. Create Task dialog box – Trigger tab

Figure 11. New Action dialog box

Figure 12. Computer Management Screen showing IE Refresh scheduled

Figure 13. Autologon - Sysinternals dialog box

Figure 14. Dialog box Security tab

Figure 15. Autologon - Sysinternals dialog box

Figure 16. Enter BMS siteID dialog box

Figure 17. Confirmation dialog box

Figure 18. Example Bed Management Solution Website

Figure 19. Dialog box Security tab

Figure 20. Autologon - Sysinternals dialog box

Figure 21. Dialog box Security tab

Figure 22. Autologon - Sysinternals dialog box

Figure 23. Display Setup window – Colors tab

Figure 24. Colors changed in background

Figure 25. Connection Setup dialog box

Figure 26. Reflection Secure Shell Settings – BlankPassword dialog box

March 2019 Endpoint Baselines | iv

Figure 27. Connection Setup dialog box

Figure 28. Secure Shell Connection example

Figure 29. Save Settings dialog box

Figure 30. Shortcut dialog box

Figure 31. Example of desktop displaying HOWDY desktop icon

Figure 32. Stop Recording dialog box

Figure 33. C:\Users\Public\Desktop folder

Figure 34. Autologon - Sysinternals dialog box

Figure 35. Site Confirmation dialog box

Figure 36. Package dialog box

Figure 37. Type of Install dialog box

Figure 38. Location of Install dialog box

Figure 39. PICIS POC Startup dialog box

Figure 40. Registry Editor screen

Figure 41. Dialog box Security tab

Figure 42. Star SP700 Cutter (SP742) Properties dialog box

Figure 43. Star SP700 Cutter (SP742) Printing Defaults dialog box

Figure 44. Star SP700 Cutter (SP742) Advance Options dialog box

Figure 45. IE Page Setup dialog box

Figure 46. Select/Change Kiosk window

Figure 47. VSS site window example

Figure 48. VSS Homepage Configuration dialog box

Figure 49. Autologon - Sysinternals dialog box

Figure 50. Java Control Panel dialog box

Figure 51. Exception Site List dialog box

Figure 52. Exception Site List dialog box - Add address

Figure 53. Install Baseline Marker dialog box

March 2019 Endpoint Baselines | v

Figure 54. Baseline Application List

Figure 55. Install Baseline Marker dialog box

Figure 56. Baseline Application List

Figure 57. Dialog box Security tab

Figure 58. Default Website URL Dialog Box

Figure 59. Default Website URL Dialog Box with URL

Figure 60. Autologon - Sysinternals dialog box

Figure 61. Dialog box Security tab

Figure 62. Autologon - Sysinternals dialog box

Figure 63. Autologon - Sysinternals dialog box

Figure 64. Dialog box Security tab

Figure 65. Autologon - Sysinternals dialog box

Figure 66. dBAT reporting fields

Figure 67. Install Baseline Marker dialog box

Figure 68. Baseline Application List

Figure 69. Dialog box Security tab

Figure 70. Launch USAccess MCUInstaller

Figure 71. User Account Control dialog box

Figure 72. USAccess AISiteManagerControl

Figure 73. Dialog box Security tab

Figure 74. Autologon - Sysinternals dialog box

Tables Table 1. Contact List

Table 2. Ward Whiteboard URL Configuration Parameters

March 2019 Endpoint Baselines | 1

1 PURPOSE

This document was prepared by Service Delivery, Endpoint Engineering, Desktop and Device Engineering team and describes the content that makes up the identified baseline(s) and should be used in the configuration of computers for the baseline(s). The initial baseline listed is the primary also called the core endpoint baseline which includes applications and their version, security/other settings, documents, and reports that make up a complete baseline. Sub-baselines listed include many of the same items as the Primary/core baseline, but will identify their own application list including versions allowed and some that are not allowed.

Complete lists of baselines in production, as well as in development, are on the Baseline List portal.

SMA baseline is located under Windows Desktops on the Baseline and Configuration Management portal.

2 HARDWARE

The Endpoint Baselines use any of the hardware that is listed as Operating System Deployment (OSD) supported unless otherwise noted within that baseline as some may have specific hardware it was designed for. The OSD supported hardware is referenced on the Hardware List portal.

3 APPLICATIONS

The applications for each baseline will be listed on the Standards for Baselines portal and SharePoint Views will be used to filter the application list for each baseline.

Every national baseline includes a national marker in order to maintain this baseline. Refer to the VA Marker Solution MSI Build Document for the 1VA collection to exclude from standard application deployments for applications that are unapproved for each baseline.

4 BUILD METHOD

To build Endpoint Baselines, use the Baseline collection variable with the OSD task sequence to install the required applications listed for the Endpoint Baselines(s). This process is detailed in the Configuration Manager OSD Guide.

In order to maintain this baseline please refer to the VA Marker Solution MSI Build Document for the 1VA collection to exclude from standard application deployments.

5 COMPUTER NAMING

The various baselines follow the VA naming convention found at https://vaww.vashare.oit.va.gov/sites/isac/NamingConventions/Pages/Home.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Baseline%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Baseline%20List/AllItems.aspx https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/bcm/sitepages/home.aspx https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/bcm/sitepages/home.aspx https://vaww.eie.va.gov/SysDesign/CS/hardware/Lists/Hardware%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/hardware/Lists/Hardware%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Applications%20(All).aspx https://vaww.eie.va.gov/SysDesign/CS/Shared%20Documents/DBPDF/Application%20Tier%203%20and%204/VA%20Marker%20Solution%20Build%20Document.pdf https://vaww.eie.va.gov/SysDesign/CS/Operating%20System%20Deployment%20OSD/Forms/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Shared%20Documents/DBPDF/Application%20Tier%203%20and%204/VA%20Marker%20Solution%20Build%20Document.pdf https://vaww.vashare.oit.va.gov/sites/isac/NamingConventions/Pages/Home.aspx

March 2019 Endpoint Baselines | 2

Each baseline will give an example for that particular baseline.

6 ACTIVE DIRECTORY

This is to help with guidance on computer account Organizational Unit (OU) location. The approved standard operating procedure (SOP) for Active Directory Users and Computers (ADUC) should be followed. Baselines that require special OU placement will be provided in that baseline section. Some might need special consideration like a kiosk or in the domain Specialized Systems OU. If not, then the systems are to be placed in workstations or laptops OU per the SOP. Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure (Active Directory) Division but it will be up to the person setting up the computer to verify everything is in place and correct.

7 GROUP POLICY OBJECTS

Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure (Active Directory) Division but it will be up to the person setting up the computer to verify everything is in place and correct. Group Policy Objects (GPO) consists of security settings taken from the United States Government Configuration Baseline (USGCB), Defense Information Systems Agency (DISA), Security Technical Implementation Guide (STIG) and Microsoft. GPOs also consist of settings that are needed to standardize for application, baseline specific (e.g. kiosk), and other known settings required within the VA. The GPOs for each baseline will be listed in the same list as the applications portal and SharePoint Views will be used to filter the list for each baseline. It is the combination or all these settings that make up the baseline (not just security).

8 ENCRYPTION

Windows 7 baseline(s) use Symantec Endpoint Encryption (SEE) and Windows 10 uses BitLocker/Microsoft BitLocker Administration and Monitoring (MBAM). Each encryption technology use one of two options. One has a pre-boot authentication and the other uses a pass-through. This is not always determined via the baseline but the hardware. In some cases, it will be identified how to set it for it to work (e.g. kiosk is pass-through). Refer to the encryption SOP for more guidance as needed.

9 SYSTEMS ENGINEERING AND DESIGN REVIEW

The Systems Engineering and Design Review (SEDR) number will be documented in each baseline. It will include the ratification date when known and the Change Order number when applicable.

https://vaww.eie.va.gov/techstrategy/TAR

March 2019 Endpoint Baselines | 3

10 REPORTING

Each baseline will have a Configuration Manager (CM) report for application compliance. A complete list can be found at the Baselines portal, and under the purpose of this document, as it lists all of the baselines and that link includes reporting. It is our goal for each baseline to have a report for GPO settings. Presently the VA cannot provide this report with its current toolset and configuration. We have been working diligently to get this setup and configured within the VA for many years now and will continue to work with those teams responsible for hosting and managing the reports to have it setup at some point soon. We can provide a report of the USGCB and DISA STIG settings as a whole or unmodified for VA deviations on the IBM BigFix Compliance portal for former regions 3 and 4 and for former regions 1, 2 and all others,, but not specifically the ones used in the Endpoint Baseline(s) for these approved VA baseline(s). We are continuing to work towards the goal of reporting on all and only the settings in the VA baseline(s).

Desktop Baseline Assessment Toolkit (dBAT) is another tool created by SD Desktop and Device Engineering (DDE) to help with reporting compliance for baselines. It will show the active directory location of the computer, applications and their compliance and GPOs applied. It should be used on all systems after the imaging and patching process to verify it has all the correct applications and version before placing in production environment for the end user.

Refer to the dBAT portal to get help, how-to, feedback or ask questions.

11 CONTACTS

If you have any questions or comments, you can reach out to the proper group. The following is a list of what is available:

• OSD – Contact your District (former regional) Client Tech team and they will help or reach out to SD national team for assistance as needed via feedback portal. You can also search open and closed items on the same portal.

• Application – Use the Build Documents for each application. If not successful, then contact your District (former regional) Client Tech team and they will help or reach out to SD national team for assistance as needed via feedback portal. You can also search open and closed items on the same portal.

• ESL Client Technologies (District or Region) o OIT ITOPS SO IO PS ESL Client Technologies Division Chiefs

VHA FR01 ESL Client Technologies Division 1, Bradley, William D., III

VHA-FR02 ESL Client Technologies Division 2, Williamson, Sharon

VHA-FR03 ESL Client Technologies Division 3, Sutherland, Hobert L.

VHA-FR04 ESL Client Technologies Division 4, Logan, James

VBA-FR05 ESL Client Technologies Division 5, Hantz, Charles, L.

https://vaww.vashare.oit.va.gov/sites/SMS/EnterpriseReporting/Baselines/SitePages/Home.aspx https://ssologon.iam.va.gov/CentralLogin/Default.aspx?appname=core&URL=https://ssologon.iam.va.gov/CentralLogin/core/redirect.aspx&TYPE=33619969&REALMOID=06-8e087667-35bf-4917-ad25-6e8ab25a5793&GUID=&SMAUTHREASON=0&METHOD=GET&SMAGENTNAME=-SM-eV9x1Z1uAN5eAYZqaAogjWvh68eq%2fnX181iI57ZjseGdBJMmHdp7wh65%2bw9uOsDN&TARGET=-SM-HTTPS%3a%2f%2flogon%2eiam%2eva%2egov%2ffedredirectjsp%2ffedredirect%2ejsp%3fSPID%3dhttps%3a%2f%2fv2dtema1%2etic%2eva%2egov%3a443%2fibm%2fsaml20%2fdefaultSP%26RelayState%3dhttps-%3A-%2F-%2Fv2dtema1%2etic%2eva%2egov-%2F%26SPID%3dhttps-%3A-%2F-%2Fv2dtema1%2etic%2eva%2egov-%3A443-%2Fibm-%2Fsaml20-%2FdefaultSP%26SMPORTALURL%3dhttps-%3A-%2F-%2Flogon%2eiam%2eva%2egov-%2Faffwebservices-%2Fpublic-%2Fsaml2sso https://ssologon.iam.va.gov/CentralLogin/Default.aspx?appname=core&URL=https://ssologon.iam.va.gov/CentralLogin/core/redirect.aspx&TYPE=33619969&REALMOID=06-f375e503-c3ea-46d7-84fd-0838a8a00804&GUID=&SMAUTHREASON=0&METHOD=GET&SMAGENTNAME=-SM-eV9x1Z1uAN5eAYZqaAogjWvh68eq%2fnX181iI57ZjseGdBJMmHdp7wh65%2bw9uOsDN&TARGET=-SM-HTTPS%3a%2f%2flogon%2eiam%2eva%2egov%2ffedredirectjsp%2ffedredirect%2ejsp%3fSPID%3dhttps%3a%2f%2fv2dtema2%2etic%2eva%2egov%3a443%2fibm%2fsaml20%2fdefaultSP%26RelayState%3dhttps-%3A-%2F-%2Fv2dtema2%2etic%2eva%2egov-%2F%26SPID%3dhttps-%3A-%2F-%2Fv2dtema2%2etic%2eva%2egov-%3A443-%2Fibm-%2Fsaml20-%2FdefaultSP%26SMPORTALURL%3dhttps-%3A-%2F-%2Flogon%2eiam%2eva%2egov-%2Faffwebservices-%2Fpublic-%2Fsaml2sso http://vaww.eie.va.gov/SysDesign/CS/dTools/ https://vaww.eie.va.gov/SysDesign/CS/dTools/default.aspx mailto:OITITOPSSOIOPSESLClientTechnologiesDivisionChiefs@va.gov mailto:OITITOPSSOIOPSESLClientTechnologiesDivision1@va.gov mailto:William.D.Bradley@va.gov mailto:VAITRegion2CORClientTechDivision@va.gov mailto:Sharon.Williamson@va.gov mailto:OITITOPSSOIOPSESLClientTechnologiesLeadership3@va.gov mailto:Hobert.Sutherland@va.gov mailto:OITITOPSSOIOPSESLClientTechnologiesDivision4@va.gov mailto:James.Logan@va.gov mailto:OITITOPSSOIOPSESLCLIENTTECHNOLOGIESTEAM5@va.gov mailto:chuck.hantz@va.gov

March 2019 Endpoint Baselines | 4

FPO-FR06 ESL Client Technologies Division 6, Barry, Daniel o VACO – Macdonald, Michelle o AITC – Gonzalez, Alex o OIFO – OIFO SCCM

• GPO & Active Directory – Contact your District (former regional) Domain Infrastructure Division and they will help you or reach out to SD national team for assistance as needed via feedback portal. You can also search open and closed items on the same portal.

• ESL Domain Infrastructure (Active Directory) Division (see Table 1)

Table 1. Contact List

Org/Region Name E-Mail Address Phone Number

Field Operations Charles Puchon charles.puchon@va.gov 520-295-3455

FO\Region 1 Richard Sebring richard.sebring@va.gov 559-241-6474

Ron Lui ron.lui@va.gov 415-720-9715

FO\Region 2 Stefan DeMeyer stefan.demeyer@va.gov 816-701-3045

FO\Region 3 Russ Eidemiller russ.eidemiller@va.gov 727-398-6661 x14888

Alan Kaplan alan.kaplan@va.gov 704-597-3517

FO\Region 4 Jim Bator james.bator@va.gov 585-393-8288

Kareme, Ki-Ve kareme.ki-ve@va.gov 347-668-4903

FO\Region 5 Scott Anderson scott.anderson1@va.gov 630-414-3258

Michael Hrouda michael.hrouda@va.gov 708-483-5393

FO\Region 6 (FPO) Stiehl, Chris chris.stiehl@va.gov 412-329-8881

Vincent, Jeanette jeanette.vincent@va.gov 708-786-7868

EO\AITC Richard Siegelman richard.siegelman@va.gov 512-326-6516

Denver Griffith denver.griffith@va.gov 512-326-6637

EO\FSC Chris Wildermuth christopher.wildermuth@va.gov 512-386-2200

EO\QITC Michael Thompson michael.thompson@va.gov 703-441-3037

Scott Walker scott.walker@va.gov 703-441-3089

Field Offices Carolyn Brown-Hardie carolyn.brown-hardie@va.gov 817-385-3856

ESE\Client Services Kevin Overholt kevin.overholt@va.gov 518-449-0668

Jamie Hosley jamie.hosley@va.gov 518-449-0251

ESE\Platforms Jay Hawkins jay.hawkins@va.gov 937-241-0296 mailto:OITITOPSSOIOPSClientTechnologiesTeam1@va.gov mailto:Daniel.Barry2@va.gov mailto:michelle.macdonald@va.gov mailto:Alex.Gonzalez@va.gov mailto:OIFOSCCM@va.gov mailto:charles.puchon@va.gov mailto:Richard.Sebring@va.gov mailto:ron.lui@va.gov mailto:Stefan.DeMeyer@va.gov mailto:Russ.Eidemiller@va.gov mailto:alan.kaplan@va.gov mailto:James.Bator@va.gov mailto:kareme.ki-ve@va.gov mailto:scott.anderson1@va.gov mailto:Michael.Hrouda@va.gov mailto:Chris.Stiehl@va.gov mailto:jeanette.vincent@va.gov mailto:Richard.Siegelman@va.gov mailto:Denver.Griffith@va.gov mailto:christopher.wildermuth@va.gov mailto:michael.thompson@va.gov mailto:scott.walker@va.gov mailto:carolyn.brown-hardie@va.gov mailto:kevin.overholt@va.gov mailto:jamie.hosley@va.gov mailto:jay.hawkins@va.gov

March 2019 Endpoint Baselines | 5

ESE\Core Infrastructure Services

Joyce Nkansah joyce.nkansah@va.gov 708 786-5915

Salinda Walker salinda.walker@va.gov 817-385-3879

Robert Sanson robert.sanson@va.gov 518-542-4582

NSOC Chris Adams chris.adams2@va.gov 304-262-5270

Miguel Valls miguel.Valls@va.gov 304-262-5217

OIG Rhena Williams rhena.williams@va.gov 708-202-5191

Jess del Mundo jess.delmundo@va.gov 202-461-4621

Schannel Davis schannel.davis@va.gov 202-461-4436

VACO ITSS David Bender david.bender@va.gov 202-632-4709

• Reporting o Access to CM Reports: Field staff, such as remote computer health check technicians or Information Security Officers, requiring access should follow local organization access requests processes in order to be added as a member of the VA IT FO xxx Compliance Scorecards security groups. All Area Managers and NCIOs should also have access to maintain compliance going forward.

o Issues in the logic of CM reports email OIT ITOPS SD EE EEMR Reporting team and copy Kevin.Overholt@va.gov

12 ADDITIONAL REFERENCES AND LINKS

• Active Directory Administrative Roles SOP

• Active Directory Standardization portal

• Organizational Units – Standardized Structure

• Organizational Unit Standardization - Specialized Systems

• Service Delivery, Endpoint Engineering, Desktop and Device Engineering o Application List o GPO List o Baseline List

• Systems Engineering and Design Review (SEDR)

• IBM BigFix Compliance reports. These are for reference only as they are not specific to the baselines and include settings from the USGCB and DISA STIG that the VA does not include in its baselines.

o Checklists https://v2dtema1.tic.va.gov/scm/checklists mailto:Joyce.Nkansah@va.gov mailto:Salinda.Walker@va.gov mailto:Robert.Sanson@va.gov mailto:chris.adams2@va.gov mailto:miguel.Valls@va.gov mailto:rhena.williams@va.gov mailto:jess.delmundo@va.gov mailto:schannel.davis@va.gov mailto:David.Bender@va.gov https://vaww.vashare.oit.va.gov/sites/euo/EUOWiki/PublicWikiDocs/ACTION%20%20%20Request%20for%20Security%20Groups.msg https://vaww.vashare.oit.va.gov/sites/euo/EUOWiki/PublicWikiDocs/ACTION%20%20%20Request%20for%20Security%20Groups.msg https://vaww.vashare.oit.va.gov/sites/euo/EUOWiki/PublicWikiDocs/Nested%20Security%20main%20groups.pdf mailto:VAITEngineeringCSCAMTReporting@va.gov mailto:Kevin.Overholt@va.gov https://vaww.sde.portal.va.gov/sites/fo/committees/coresystems/AD%20Standardization/Standards%20Development%20Project_Documentation/AD%20Standardization%20Administrative%20Roles%20SOP%20version%202.0.docx https://vaww.sde.portal.va.gov/sites/fo/committees/coresystems/AD%20Standardization/Forms/AllItems.aspx https://vaww.sde.portal.va.gov/sites/fo/committees/coresystems/Wiki/Organizational%20Units%20-%20Standard%20Structure.aspx https://vaww.sde.portal.va.gov/sites/fo/committees/coresystems/Wiki/Organizational%20Units%20-%20Specialized%20Systems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Applications%20(All).aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/GPO%20All.aspx http://vaww.eie.va.gov/SysDesign/CS/Lists/Baseline%20List/AllItems.aspx https://vaww.eie.va.gov/techstrategy/TAR https://v2dtema1.tic.va.gov/scm/checklists

March 2019 Endpoint Baselines | 6 https://v2dtema2.tic.va.gov/scm/checklists o Windows 7 USGCB https://v2dtema1.tic.va.gov/scm/checklists/70 https://v2dtema2.tic.va.gov/scm/checklists/30 o Windows 10 DISA STIG https://v2dtema1.tic.va.gov/scm/checklists/201 https://v2dtema2.tic.va.gov/scm/checklists/343 o Internet Explorer 11 DISA STIG https://v2dtema1.tic.va.gov/scm/checklists/192 https://v2dtema2.tic.va.gov/scm/checklists/333

• BitLocker guides

• Reporting TBD in this document – The following reports are not available in the VA as we do not currently have a method for reporting on these setting based on these approved baseline settings. We are working to get something in place, until then we are adding a placeholder in the baseline document for each item.

o DISA STIG report (TBD) o Complete baseline settings report (TBD)

• Navigation of SharePoint Views in this document

The DDE SharePoint lists consist of views. You will need to select the baseline name from the View menu by clicking the ellipse (…) on the Standards for Baselines portal (see Figure 1. Standards for Baseline portal page).

Figure 1. Standards for Baseline portal page https://v2dtema2.tic.va.gov/scm/checklists https://v2dtema1.tic.va.gov/scm/checklists/70 https://v2dtema2.tic.va.gov/scm/checklists/30 https://v2dtema1.tic.va.gov/scm/checklists/201 https://v2dtema2.tic.va.gov/scm/checklists/343 https://v2dtema1.tic.va.gov/scm/checklists/192 https://v2dtema2.tic.va.gov/scm/checklists/333 https://vaww.eie.va.gov/SysDesign/CS/Shared%20Documents/Forms/AllItems.aspx?RootFolder=/SysDesign/CS/Shared%20Documents/Encryption/BitLocker https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Applications%20(All).aspx

March 2019 Endpoint Baselines | 7

APPENDIX A: WINDOWS 7 BASELINE

This baseline is the primary/core Windows 7 baseline used in the VA for computers unless there is a sub-baseline as documented. This baseline will have a list of mandatory applications including the version; it will also have a list of mandatory GPO settings. With the primary/core baseline sites will then have to decide what additional applications and GPO settings to install and implement as long as they do not override the items listed in the primary/core baseline. If a conflicting item is required a Strategic Technology Alignment Team (STAT) waiver or Plan of Action and Milestones (POA&M) will need to be obtained and documented for their site.

A.1 Hardware This baseline uses any of the hardware that is listed as Operating System Deployment (OSD) supported. The OSD supported hardware is referenced on the Hardware portal.

A.2 Applications The applications for this baseline are listed on the Standards for Baselines portal and SharePoint View for the specific baseline to filter the application list for this baseline. Check the portal for the up to date list and versions.

A.3 Build Method To build the Endpoint Baselines computer, use the Baseline collection variable with the OSD task sequence to install the required applications listed for the Endpoint Baselines(s). This process is detailed in the Configuration Manager OSD Guide.

In order to maintain this baseline please refer to the VA Marker Solution MSI Build Document for the 1VA collection to exclude from standard application deployments.

A.4 Computer Naming Follow the VA naming convention https://vaww.vashare.oit.va.gov/sites/isac/NamingConventions/Pages/Home.aspx

Device Type= WS or LT and the first three characters of Device ID= Project name Example: ISA-WSXXXXXXXX Location Code = ISA- Device Type = WS or LT Device ID = XXXXXXXX (The 8 XXXXXXXX is up to each site)

A.5 Active Directory This is only to help with guidance on computer account Organizational Unit (OU) location. The SOP for ADUC should be followed. For special OU placement it will be provided in that sub-https://vaww.eie.va.gov/SysDesign/CS/_layouts/listform.aspx?PageType=4&ListId=%7b253CBBEF-9423-44D4-9501-0824E70CF23F%7d&ID=16&ContentTypeID=0x010073EB5475940BDD498C460AF574F69CC7 https://vaww.eie.va.gov/SysDesign/CS/hardware/Lists/Hardware%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Windows%207.aspx https://vaww.eie.va.gov/SysDesign/CS/Operating%20System%20Deployment%20OSD/Forms/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Shared%20Documents/DBPDF/Application%20Tier%203%20and%204/VA%20Marker%20Solution%20Build%20Document.pdf

March 2019 Endpoint Baselines | 8 baseline section. Some might need special consideration like a kiosk or in the domain Specialized Systems OU. If not, then the systems are to be placed in workstations and laptops per SOP.

A.6 Group Policy Objects The GPOs for this baseline are listed on the Standards for Baselines portal with the applications and the SharePoint View is used to filter the list for this baseline. Check the portal for the up to date list and versions. Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure Division but it will be up to the person setting up the computer to verify everything is in place and correct before proceeding and if not take action to get it completed.

A.7 Encryption Windows 7 baseline(s) use Symantec Endpoint Encryption (SEE) using one of two options. One has a pre-boot authentication and the other uses a pass-through. This is not always determined via the baseline but the hardware. In some cases, it will be identified how to set it for it to work (e.g. kiosk is pass-through). Refer to the encryption SOP for more guidance as needed.

A.8 Systems Engineering and Design Review Systems Engineering and Design Review (SEDR) #: N/A

Ratified Date: N/A

Change Order#: N/A

A.9 Reporting Application report

DISA STIG reports at https://v2dtema1.tic.va.gov/scm/checklists and

Complete baseline settings report (TBD) https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Windows%207.aspx https://vaphcsmssqlrrn1.vha.med.va.gov/Reports/Pages/Report.aspx?ItemPath=%2fExecutive+Dashboards%2fDesktop+Engineering+Score+Cards%2fBaselines%2fWindows+7%2fWindows+7 https://v2dtema1.tic.va.gov/scm/checklists

March 2019 Endpoint Baselines | 9

APPENDIX B: WINDOWS 7 SUB-BASELINES

B.1 Audiology Workstation This baseline is the Windows 7 Audiology Workstation sub-baseline used in the VA. This baseline will have a list of mandatory applications including the version. This baseline is unique in that it has some applications in the baseline that not all sites will install and are listed separately as such as well as reports. It will also have a list of mandatory GPO settings. With this baseline sites cannot add additional applications and GPO settings. They cannot obtain a Strategic Technology Alignment Team (STAT) waiver or Plan of Action and Milestones (POA&M) or make any changes to the baseline.

• VA OIT Issues contact Project Manager Susan Knause.

• Audiology application issues contact the national Audiology POC Chad Gladden.

B.1.1 Hardware There is no specific hardware for the baseline. There may have been purchases specified for using with this baseline (e.g. HP Pro Desk 600 G1 SFF purchase), but that is not a requirement for using this baseline from a baseline documentation perspective. The Operating System Deployment (OSD) supported hardware is referenced on the Hardware portal.

B.1.2 Applications The applications for this baseline are listed on the Standards for Baselines portal. A SharePoint View for the specific baseline is available to filter the application list for this baseline. Check the portal for the up to date list and versions. Take note that some applications are not installed at some sites as they do not support the associated accessories or hardware. These are noted in the application portal and the reports.

B.1.3 Build Method In order to build the Audiology baseline computer, use the Baseline collection variable with the OSD task sequence to install the required applications listed for Audiology. This process is detailed in the Configuration Manager OSD Guide.

B.1.4 Computer Naming Follow the VA naming convention https://vaww.vashare.oit.va.gov/sites/isac/NamingConventions/Pages/Home.aspx

Device Type=SP and the first three characters of Device ID= Project name https://vaww.eie.va.gov/SysDesign/CS/_layouts/15/listform.aspx?PageType=4&ListId=%7B253CBBEF%2D9423%2D44D4%2D9501%2D0824E70CF23F%7D&ID=2&ContentTypeID=0x010073EB5475940BDD498C460AF574F69CC7 mailto:Susan.Knause@va.gov mailto:Chad.Gladden2@va.gov https://vaww.sde.portal.va.gov/docctr/Bulletins/Audiology_Workstation_Solutions_Procurement_Update_No.5.pdf https://vaww.eie.va.gov/SysDesign/CS/hardware/Lists/Hardware%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Windows%207.aspx https://vaww.eie.va.gov/SysDesign/CS/Operating%20System%20Deployment%20OSD/Forms/AllItems.aspx

March 2019 Endpoint Baselines | 10

Example: ISA-SPAUDXXXXX Location Code = ISA- Device Type = SP Device ID = AUDXXXXX (The 5 XXXXX is up to each site)

B.1.5 Active Directory Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure Division but it will be up to the person setting up the computer to verify everything is in place and correct before proceeding, and if not, take action to get it completed by contacting the appropriate Domain Infrastructure Division. The required Organizational Unit (OU) for the baseline is they can exist in the normal location where workstations currently exist in Active Directory.

B.1.6 Group Policy Objects The GPOs for this baseline are listed on the Standards for Baselines portal with the applications and the SharePoint View is used to filter the list for this baseline. Check the portal for the up to date list and versions. Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure Division but it will be up to the person setting up the computer to verify everything is in place and correct before proceeding and if not take action to get it completed.

B.1.7 Encryption No specialized configuration of encryption is required. Systems will use Symantec Endpoint Encryption (SEE) pre-boot authentication. Encryption should be handled by the local and/or regional encryption administrators.

B.1.8 Systems Engineering and Design Review Systems Engineering and Design Review (SEDR) #: SEDR16-1685

Ratified Date: 11/08/2016

Change Order #: CO354322FY16

B.1.9 Reporting Application report

DISA STIG report (TBD)

Complete baseline settings report (TBD) https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Audiology%20Workstation.aspx https://vaphcsmssqlrrn1.vha.med.va.gov/Reports/Pages/Report.aspx?ItemPath=/Executive+Dashboards/Desktop+Engineering+Score+Cards/Baselines/Audiology+Workstation/Audiology+Workstation&ViewMode=Detail

March 2019 Endpoint Baselines | 11

B.1.10 Baseline Specific Instructions This baseline has semi-annual updates for hearing aid software that is released in May and November. The CM task sequence name is 1VA - Audiology Updates [Month] [Year]. Follow normal procedure for release.

March 2019 Endpoint Baselines | 12

B.2 Bed Management Solution (BMS) Whiteboard Kiosk This baseline is the Windows 7 Bed Management Solution (BMS) Whiteboard Kiosk sub-baseline used in the VA for configuration of computers for the Bed Management Solution (BMS) Whiteboard Kiosk project. This baseline will have a list of mandatory applications including the version; it will also have a list of mandatory GPO settings. With this baseline sites, cannot add additional application and GPO settings. They cannot obtain a Strategic Technology Alignment Team (STAT) waiver or Plan of Action and Milestones (POA&M) or make any changes to the baseline.

BMS Whiteboard Kiosk Build Process (not OSD) – National Service Desk to create a ticket. Have the NSD used and assign to: The Request Area will be NTL.APP.HealtheVet VistA.Bed Management Solutions. The group responsible will be NTL SUP BMS.

B.2.1 Hardware This baseline uses any of the hardware that is listed as Operating System Deployment (OSD) supported. The OSD supported hardware is referenced on the Hardware portal.

B.2.2 Applications The applications for this baseline is listed on the Standards for Baselines portal and SharePoint View for the specific baseline to filter the application list for this baseline. Check the portal for the up to date list and versions.

B.2.3 Build Method In order to build this baseline computer, use the Baseline collection variable with the OSD task sequence to install the required applications listed for this baseline. This process is detailed in the Configuration Manager OSD Guide.

B.2.4 Computer Naming Follow the VA naming convention https://vaww.vashare.oit.va.gov/sites/isac/NamingConventions/Pages/Home.aspx

Device Type=KI and the first three characters of Device ID= Project name Example: ISA-KIBMSWXXXXX Location Code = ISA- Device Type = KI Device ID = BMSWXXXXX (The 5 XXXXX is up to each site)

B.2.5 Active Directory Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure Division but it will be up to the person setting up the computer to verify https://vaww.eie.va.gov/SysDesign/CS/_layouts/listform.aspx?PageType=4&ListId=%7b253CBBEF-9423-44D4-9501-0824E70CF23F%7d&ID=24&ContentTypeID=0x010073EB5475940BDD498C460AF574F69CC7 https://vaww.eie.va.gov/SysDesign/CS/hardware/Lists/Hardware%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Bed%20Management%20Solution%20BMS%20Whiteboard%20Kiosk.aspx

March 2019 Endpoint Baselines | 13 everything is in place and correct before proceeding, and if not, take action to get it completed by contacting the appropriate Domain Infrastructure Division. The required Organizational Unit (OU) for the BMS Whiteboard kiosk is root\Specialized Systems\Kiosks\BMSW\yourkiosk.

B.2.6 Group Policy Objects The GPOs for this baseline are listed on the Standards for Baselines portal with the applications and the SharePoint View is used to filter the list for this baseline. Check the portal for the up to date list and versions. Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure Division but it will be up to the person setting up the computer to verify everything is in place and correct before proceeding and if not take action to get it completed.

Link the VA ESE DT BMS Whiteboard KIOSK Standards GPO to root\Specialized Systems\Kiosks\BMSW\

1. In the Group Policy Management Console (GPMC), select the Delegation tab for the VA ESE DT BMS Whiteboard KIOSK Standards GPO.

2. Click the Advanced button in the lower right-hand corner.

3. Click Add and search for your domains standard delegation group (usually VHAxxxAllAccountAdmins).

4. Click the OK button.

5. Click the Security tab in the dialog box.

Figure 2. Dialog box Security tab

6. In the Group or user names section, highlight the group you added.

7. In the Permissions section, check Deny for the Apply group policy option.

https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Bed%20Management%20Solution%20BMS%20Whiteboard%20Kiosk.aspx

March 2019 Endpoint Baselines | 14

8. Click the Apply button.

9. Click the OK button.

NOTE: To assure the proper settings are in place for the kiosks, make sure the kiosk OU is set so that the appropriate kiosk policy has the highest precedence.

NOTE: As indicated in the standards list, any VA Banner GPO should not be applied to any kiosks systems in a domain. This allows for the proper functioning of the auto-login feature.

All standards GPOs for this baseline should be inherited or linked to the baseline OU.

B.2.7 Encryption No specialized configuration of encryption is required. Systems will use Symantec Endpoint Encryption (SEE) Auto-logon. Encryption should be handled by the local and/or regional encryption administrators.

B.2.8 Systems Engineering and Design Review Systems Engineering and Design Review (SEDR) #: SEDR18-1810

Ratified Date: 02/21/2018

Change Order #: CO402355FY17

B.2.9 Reporting Application report

DISA STIG report (TBD)

Complete baseline settings report (TBD)

B.2.10 Baseline Specific Instructions

B.2.10.1 Service Account

• There are two separate service accounts for this baseline. They are not the same account.

• The first service account will be used for Windows auto logon at domain level.

• The second service account is used for the Whiteboard website access. Instructions below call this Whiteboard Kiosk Default User Name.

https://vaphcsmssqlrrn1.vha.med.va.gov/Reports/Pages/Report.aspx?ItemPath=%2fExecutive+Dashboards%2fDesktop+Engineering+Score+Cards%2fBaselines%2fBed+Management+Solution+(BMS)+Whiteboard+Kiosk%2fBed+Management+Solution+(BMS)+Whiteboard+Kiosk+Baseline&ViewM

March 2019 Endpoint Baselines | 15

• You will need to contact the ESL Domain Infrastructure (Active Directory) Division for each of the service account names and passwords. A list is found in section 11 Contacts on page 3.

B.2.10.2 Configure the Whiteboard Kiosk Default Login User (Service Account) in

BMS

For the current facility that will display the associated Whiteboard page, a default user needs to be configured in BMS application for the Ward Whiteboard Kiosk. Coordinate with the local site BMS POC to use the second service account listed above, Not the Windows auto logon service account.

To configure the Whiteboard Kiosk Default User:

1. Go to the BMS Site Home Page

2. Click on the Site Options link

3. Click on the Facility Setting link

4. On the Facility Configuration window, fill in the following fields:

• Whiteboard Kiosk Default User Name – User name

• Whiteboard Kiosk Password – Password

• Whiteboard Kiosk Password Confirm – BMS Service Account ID

Figure 3. Facility Configuration window

5. Click Submit.

March 2019 Endpoint Baselines | 16

B.2.10.3 Assign a Role to the Whiteboard Kiosk Default User in BMS Each facility must assign the BMS EMS USER Role to the Service Account ID created to run the Whiteboard Kiosk URL. This assignment can be done from the BMS Admin Section > Add/Edit BMS User hyperlink or Facility Site Options > BMS User Add/Edit hyperlink.

1. Click the Select Existing NT User Name button

2. Select the correct VISN Domain from the left dropdown box.

3. In the NT User Name box, enter the BMS Service Account ID created for the BMS Whiteboard Kiosk. Click the Find button

4. Click the Selected radio button for the user. Click the Select button.

5. In the Admin User dropdown, select No.

6. In the Audit Log User dropdown, select No.

7. In the Site User dropdown, select Yes.

8. In the EMS User dropdown, select No.

9. In the EMS Supervisor User dropdown, select No.

10. In the READ Access dropdown, select Yes.

11. In the WRITE Access dropdown, select Yes.

Figure 4 - Whiteboard Kiosk User Role Assignment Fields

12. Click Submit.

March 2019 Endpoint Baselines | 17

B.2.10.4 Create the Ward Whiteboard Kiosk URL The Ward Whiteboard display uses parameters to determine the behavior of the display.

For example, the whiteboard can display a specific ward or ALL wards for a site by setting the parameter wardName. Table 2 contains descriptions for each whiteboard display parameter along with available options for each.

Table 2. Ward Whiteboard URL Configuration Parameters

Parameter Short Description Options facilityCode Code of facility (e.g., BROCKTON = BRK). Enter the 3-character facility ID.

wardName Name of BMS Ward Name. To see all the wards the value that needs to be configured is ALL.

These are the BMS WARDS as defined in the Facility, Site Options, VistA Ward Add/Edit.

The Ward name value should match the "BMS WARD GROUP TEXT". A single ward can be entered or the value "ALL" to display all the wards at the facility.

splitScreen To split the page in two tables enters the value Yes. Yes No displayPTCode How the patient should be displayed under the column "Patient" (full name or 1st+Last 4) or LastName.

LastName is required for Kiosk mode due to Privacy regulations.

FirstAndLast4 LastName genderColorCode To change the background color for the row according with patient’s gender.

Blue/Pink None displayFooterCensus To view the footer census. Yes No displayStaffAttending What column is displayed in the table? (Staff column, Attending column or both).

Staff and Attending Staff Attending scrollRate The timer interval will affect the scrolling speed. This parameter can be absent. (If specified then it represents seconds).

Null or an integer value.

• Determine the parameters for the Kiosk, and create the URL

• Below is a sample URL to display All Wards for site BRK:

https://vaww.bms.va.gov/WardWhiteboardUrl?facilityCode=BRK&wardName=ALL&splitSc reen=No&displayPTCode=LastName&genderColorCode=Blue/Pink&displayFooterCensus=Y es&displayStaffAttending=Staff%20and%20Attending&scrollRate=20

• Test the URL. Once you have the URL, type it into a browser to test. The BMS Ward Whiteboard should come up.

https://vaww.bms.va.gov/WardWhiteboardUrl?facilityCode=BRK&wardName=ALL&splitScreen=No&displayPTCode=LastName&genderColorCode=Blue/Pink&displayFooterCensus=Yes&displayStaffAttending=Staff%20and%20Attending&scrollRate=20 https://vaww.bms.va.gov/WardWhiteboardUrl?facilityCode=BRK&wardName=ALL&splitScreen=No&displayPTCode=LastName&genderColorCode=Blue/Pink&displayFooterCensus=Yes&displayStaffAttending=Staff%20and%20Attending&scrollRate=20 https://vaww.bms.va.gov/WardWhiteboardUrl?facilityCode=BRK&wardName=ALL&splitScreen=No&displayPTCode=LastName&genderColorCode=Blue/Pink&displayFooterCensus=Yes&displayStaffAttending=Staff%20and%20Attending&scrollRate=20

March 2019 Endpoint Baselines | 18

NOTE: A site can have a different URL for each kiosk

• Copy the URL to a text file and save it on the desktop or a network share where you can access it for setting up the default BMS WhiteBoard website in the next section.

B.2.10.5 Setting up Default BMS WhiteBoard Website with Your Site URL

1. Make sure your Domain Infrastructure team has performed their step found in B.2.6 Group

Policy Objects.

2. Logon to the kiosk system with your eToken account.

3. Navigate to C:\KIOSK\BMSW.

4. Right-click the CreateBMSsite.cmd file and select Run as administrator.

5. Copy and paste the BMS WhiteBoard URL created earlier into the dialog box and click OK.

Figure 5. BMS WhiteBoard Configuration dialog box

6. Click OK again to confirm the setting. Internet Explorer will open with the URL as home page. Your BMS WhiteBoard Kiosk Internet Explorer home page is now set to your specific site. This setting will apply to all users on this kiosk workstation.

NOTE: Close and re-open Internet Explorer to confirm your home page. Repeat above steps to change the URL setting if needed.

NOTE: if you want to close the dialog box without saving the setting, open task manager and end the cscript.exe process.

B.2.10.6 Setup for Hourly Internet Explorer Refresh

1. Logon to the kiosk system with your eToken account.

2. Open Computer Management. Under System Tools, select Task Scheduler.

March 2019 Endpoint Baselines | 19

Figure 6. Computer Management - System Tools - Task Scheduler

3. Right-click Task Scheduler and select Create Task.

4. On the Create Task dialog box, select the General tab.

Figure 7. Create Task dialog box – General tab

a. In the Name field, enter the title of the scheduled task (e.g., IE Refresh).

March 2019 Endpoint Baselines | 20

b. In the Description field, enter a description as needed.

c. Click the Change User or Group… button.

1) In the Select User or Group dialog box, enter the BMS WhiteBoard Kiosk service account information specific to your location.

2) Click the OK button.

d. Continuing under the General tab, select the Run only when user is logged on radio button.

e. Check the Hidden checkbox.

f. In the Configure for dropdown, select Windows 7, Windows Server 2008 R2.

5. On the Create Task dialog box, select the Trigger tab.

Figure 8. Create Task dialog box – Trigger tab

a. Click the New… button.

b. In the New Trigger dialog box, under the Begin the task dropdown select On a schedule (see Figure 9).

March 2019 Endpoint Baselines | 21

Figure 9. New Trigger dialog box

c. Under the Settings section, select the Daily radio button.

d. Under the Settings section in the Recur every field, enter 1 days.

e. Under the Advanced settings section:

1) Check the Repeat task every checkbox

2) In the Repeat task every dropdown, select 1 hour.

3) In the for the duration of dropdown, select 1 day.

NOTE: The task is scheduled to repeat hourly in this example. You may change it as needed.

f. Under the Advanced settings section, check the Enabled checkbox

g. Click the OK button.

6. On the Create Task dialog box, select the Actions tab (see Figure 10).

March 2019 Endpoint Baselines | 22

Figure 10. Create Task dialog box – Trigger tab

a. Click the New… button.

b. On the New Action dialog box, click the Browse… button.

Figure 11. New Action dialog box

c. Navigate to C:\Kiosk\BMSW. Select the RefreshIE.cmd file and click the Open button.

d. On the New Action dialog box, the Program/script field now has C:\Kiosk\BMSW\RefreshIE.cmd entered.

e. Click the OK button.

March 2019 Endpoint Baselines | 23

7. On the Create Task dialog box, click the OK button.

8. The IE Refresh task is now scheduled.

Figure 12. Computer Management Screen showing IE Refresh scheduled

B.2.10.7 Setup Auto Logon

NOTE: Be sure that the correct password is being used. If auto logon does not work, you may rerun these steps.

1. Logon to the kiosk system with your administrative eToken account.

2. Navigate to the C:\Kiosk\AutoLogon folder.

3. Right-click the Autologon.exe file and select Run as administrator.

4. Enter information on…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.