36C24219Q0513-014.pdf
PDF 3 MB Posted
- Attached to
- Viral Load Testing Bronx VA Federal contract opportunity
- Solicitation number
- 36C24219Q0513
About this file
36C24219Q0513 Endpoint Baselines.pdf
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C24219D0114-001.docx | DOCX document | |
| 36C24219Q0513-012.pdf | ||
| 36C24219Q0513-010.docx | DOCX document | |
| 36C24219Q0513-013.pdf | ||
| 36C24219Q0513-011.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Solution Delivery Endpoint Engineering Desktop and Device Engineering
Endpoint Baselines Version 2.0
March 12, 2019 | IT Operations and Services
OFFICE OF INFORMATION AND TECHNOLOGY
IT Operations and Services
Revision History
Date Reason for Changes Version Author
09/25/2017 Initial Document 1.0 Kevin Overholt
02/21/2018 SEDR18-1810, Endpoint Baselines (Bed Management Solution (BMS) Whiteboard Kiosk, VM Non-Persistent Desktop, VM Persistent Desktop, Windows 10, and TeleHealth) are now considered ratified.
Updated document with Ratified Date: for above baselines.
1.1 Kevin Overholt
02/26/2018 Reformatted document and repaired indexing
(TOC).
1.1 Bob Leahy (Technical Writer)
03/30/2018 Added CSP Bingo for SEDR review 1.2 Kevin Overholt
03/30/2018 Replaced document cover and regenerated TOC. 1.2 Bob Leahy (Technical Writer)
04/06/2018 Update TeleHealth adding Dell information 1.2 Kevin Overholt
04/06/2018 Reformatted document and changed main document baseline sections to appendices.
Edited for 508 Compliance.
1.2 Bob Leahy (Technical Writer)
04/11/2018 Updated CSP Bingo Board Kiosk SEDR Ratification 1.2 Kevin Overholt
04/11/2018 Repaired/edited and added screenshots back into document to meet 508 Compliance.
1.3 Bob Leahy (Technical Writer)
04/11/2018 Added comments to be addressed 1.4 Bob Leahy (Technical Writer)
04/24/2018 Repaired items in CSP Bingo Board Kiosk section (508 Compliance)
1.5 Bob Leahy (Technical Writer)
04/24/2018 Replied to comments and updated information 1.5 Kevin Overholt
04/27/2018 Cleared previous comments and applied changes. Applied baseline document template to update format and styles.
1.6 Bob Leahy (Technical Writer)
04/30/2018 Repaired links and inserted new image. 1.7 Bob Leahy (Technical Writer)
06/05/2018 Updated links to VA Naming Conventions website 1.8 Bob Leahy (Technical Writer)
06/18/2018 Added the following baselines: Burial Schedule Display Kiosk, Digital Signage Kiosk, USAccess Mobile Credentialing Unit, Windows 10 Generic Kiosk, Windows 7 Generic Kiosk
1.9 Bob Leahy (Technical Writer)
06/28/2018 Updated path from root\Specialized Systems\ CSPBB\yourcomputer to root\Specialized Systems\Kiosks\CSPBB\yourcomputer in CPS Bingo Board Kiosk appendix
1.10 Bob Leahy (Technical Writer)
07/09/2018 Added baseline ratification dates for Digital Signage Kiosk, Windows 7 Generic Kiosk, USAccess Mobile Credentialing Unit (MCU), Burial Schedule Display Kiosk and Windows 10 Generic Kiosk.
1.11 Bob Leahy (Technical Writer)
08/10/2018 Updated Appendix R: USAccess Mobile Credentialing Unit.
1.12 Kevin Overholt
08/10/2018 Applied new baseline document template, reviewed updates, regenerated TOC and reposted.
1.12 Bob Leahy (Technical Writer)
08/20/2018 Updated naming convention section for USAccess Mobile Credentialing Unit
1.13 Bob Leahy (Technical Writer)
09/10/2018 Removed BHL SOLUTIONS and CITRIX ENDPOINT LOCKDOWN information (both items decommissioned)
1.14 Bob Leahy (Technical Writer)
03/06/2019 Updated Digital Signage Kiosk required OU to root\Specialized Systems\Kiosks\DIGS\ yourcomputer per Dan Z.
1.15 Bob Leahy (Technical Writer)
03/12/2019 Modified document to include all Windows 7 sub-baselines in one appendix and all Windows 10 sub-baseline in another appendix. Added Windows 10 sub-baseline for VM Persistent Desktop (per Kevin Overhold)
2.0 Bob Leahy (Technical Writer)
Table of Contents
1 PURPOSE
2 HARDWARE
3 APPLICATIONS
4 BUILD METHOD
5 COMPUTER NAMING
6 ACTIVE DIRECTORY
7 GROUP POLICY OBJECTS
8 ENCRYPTION
9 SYSTEMS ENGINEERING AND DESIGN REVIEW
10 REPORTING
11 CONTACTS
12 ADDITIONAL REFERENCES AND LINKS
APPENDIX A: WINDOWS 7 BASELINE
A.1 Hardware
A.2 Applications
A.3 Build Method
A.4 Computer Naming
A.5 Active Directory
A.6 Group Policy Objects
A.7 Encryption
A.8 Systems Engineering and Design Review
A.9 Reporting
APPENDIX B: WINDOWS 7 SUB-BASELINES
B.1 Audiology Workstation
B.2 Bed Management Solution (BMS) Whiteboard Kiosk
B.3 BHL Solutions
B.4 Citrix Endpoint Lockdown
B.5 CMOP Production Floor Systems
B.6 Environment of Care (EOC)
B.7 Environmental Management Service (EMS) Bed Management Solution (BMS)
March 2019 Endpoint Baselines | i
March 2019 Endpoint Baselines | ii
B.8 HealtheVet Kiosk
B.9 Howdy Kiosk
B.10 Medical Device Protection Program (MDPP)
B.11 PICIS
B.12 PIV Issuing Stations
B.13 Real Time Location System (RTLS)
B.14 TeleHealth
B.15 Voice Assisted Manikin (VAM)
B.16 VSS Kiosk
B.17 VM Non-Persistent Desktop
B.18 VM Persistent Desktop
B.19 Windows 7 Generic Kiosk
APPENDIX C: WINDOWS 10 BASELINE
C.1 Hardware
C.2 Applications
C.3 Build Method
C.4 Computer Naming
C.5 Active Directory
C.6 Group Policy Objects
C.7 Encryption
C.8 Systems Engineering and Design Review
C.9 Reporting
C.10 Baseline Specific Instructions
APPENDIX D: WINDOWS 10 SUB-BASELINES
D.1 Burial Schedule Display Kiosk
D.2 CMOP Production Floor Systems
D.3 CSP Bingo Board Kiosk
D.4 Digital Signage Kiosk
D.5 VM Persistent Desktop
D.6 USAccess Mobile Credentialing Unit
D.7 Windows 10 Generic Kiosk
March 2019 Endpoint Baselines | iii
Figures Figure 1. Standards for Baseline portal page
Figure 2. Dialog box Security tab
Figure 3. Facility Configuration window
Figure 4 - Whiteboard Kiosk User Role Assignment Fields
Figure 5. BMS WhiteBoard Configuration dialog box
Figure 6. Computer Management - System Tools - Task Scheduler
Figure 7. Create Task dialog box – General tab
Figure 8. Create Task dialog box – Trigger tab
Figure 9. New Trigger dialog box
Figure 10. Create Task dialog box – Trigger tab
Figure 11. New Action dialog box
Figure 12. Computer Management Screen showing IE Refresh scheduled
Figure 13. Autologon - Sysinternals dialog box
Figure 14. Dialog box Security tab
Figure 15. Autologon - Sysinternals dialog box
Figure 16. Enter BMS siteID dialog box
Figure 17. Confirmation dialog box
Figure 18. Example Bed Management Solution Website
Figure 19. Dialog box Security tab
Figure 20. Autologon - Sysinternals dialog box
Figure 21. Dialog box Security tab
Figure 22. Autologon - Sysinternals dialog box
Figure 23. Display Setup window – Colors tab
Figure 24. Colors changed in background
Figure 25. Connection Setup dialog box
Figure 26. Reflection Secure Shell Settings – BlankPassword dialog box
March 2019 Endpoint Baselines | iv
Figure 27. Connection Setup dialog box
Figure 28. Secure Shell Connection example
Figure 29. Save Settings dialog box
Figure 30. Shortcut dialog box
Figure 31. Example of desktop displaying HOWDY desktop icon
Figure 32. Stop Recording dialog box
Figure 33. C:\Users\Public\Desktop folder
Figure 34. Autologon - Sysinternals dialog box
Figure 35. Site Confirmation dialog box
Figure 36. Package dialog box
Figure 37. Type of Install dialog box
Figure 38. Location of Install dialog box
Figure 39. PICIS POC Startup dialog box
Figure 40. Registry Editor screen
Figure 41. Dialog box Security tab
Figure 42. Star SP700 Cutter (SP742) Properties dialog box
Figure 43. Star SP700 Cutter (SP742) Printing Defaults dialog box
Figure 44. Star SP700 Cutter (SP742) Advance Options dialog box
Figure 45. IE Page Setup dialog box
Figure 46. Select/Change Kiosk window
Figure 47. VSS site window example
Figure 48. VSS Homepage Configuration dialog box
Figure 49. Autologon - Sysinternals dialog box
Figure 50. Java Control Panel dialog box
Figure 51. Exception Site List dialog box
Figure 52. Exception Site List dialog box - Add address
Figure 53. Install Baseline Marker dialog box
March 2019 Endpoint Baselines | v
Figure 54. Baseline Application List
Figure 55. Install Baseline Marker dialog box
Figure 56. Baseline Application List
Figure 57. Dialog box Security tab
Figure 58. Default Website URL Dialog Box
Figure 59. Default Website URL Dialog Box with URL
Figure 60. Autologon - Sysinternals dialog box
Figure 61. Dialog box Security tab
Figure 62. Autologon - Sysinternals dialog box
Figure 63. Autologon - Sysinternals dialog box
Figure 64. Dialog box Security tab
Figure 65. Autologon - Sysinternals dialog box
Figure 66. dBAT reporting fields
Figure 67. Install Baseline Marker dialog box
Figure 68. Baseline Application List
Figure 69. Dialog box Security tab
Figure 70. Launch USAccess MCUInstaller
Figure 71. User Account Control dialog box
Figure 72. USAccess AISiteManagerControl
Figure 73. Dialog box Security tab
Figure 74. Autologon - Sysinternals dialog box
Tables Table 1. Contact List
Table 2. Ward Whiteboard URL Configuration Parameters
March 2019 Endpoint Baselines | 1
1 PURPOSE
This document was prepared by Service Delivery, Endpoint Engineering, Desktop and Device Engineering team and describes the content that makes up the identified baseline(s) and should be used in the configuration of computers for the baseline(s). The initial baseline listed is the primary also called the core endpoint baseline which includes applications and their version, security/other settings, documents, and reports that make up a complete baseline. Sub-baselines listed include many of the same items as the Primary/core baseline, but will identify their own application list including versions allowed and some that are not allowed.
Complete lists of baselines in production, as well as in development, are on the Baseline List portal.
SMA baseline is located under Windows Desktops on the Baseline and Configuration Management portal.
2 HARDWARE
The Endpoint Baselines use any of the hardware that is listed as Operating System Deployment (OSD) supported unless otherwise noted within that baseline as some may have specific hardware it was designed for. The OSD supported hardware is referenced on the Hardware List portal.
3 APPLICATIONS
The applications for each baseline will be listed on the Standards for Baselines portal and SharePoint Views will be used to filter the application list for each baseline.
Every national baseline includes a national marker in order to maintain this baseline. Refer to the VA Marker Solution MSI Build Document for the 1VA collection to exclude from standard application deployments for applications that are unapproved for each baseline.
4 BUILD METHOD
To build Endpoint Baselines, use the Baseline collection variable with the OSD task sequence to install the required applications listed for the Endpoint Baselines(s). This process is detailed in the Configuration Manager OSD Guide.
In order to maintain this baseline please refer to the VA Marker Solution MSI Build Document for the 1VA collection to exclude from standard application deployments.
5 COMPUTER NAMING
The various baselines follow the VA naming convention found at https://vaww.vashare.oit.va.gov/sites/isac/NamingConventions/Pages/Home.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Baseline%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Baseline%20List/AllItems.aspx https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/bcm/sitepages/home.aspx https://vaww.vashare.oit.va.gov/sites/itops/svcs/sma/bcm/sitepages/home.aspx https://vaww.eie.va.gov/SysDesign/CS/hardware/Lists/Hardware%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/hardware/Lists/Hardware%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Applications%20(All).aspx https://vaww.eie.va.gov/SysDesign/CS/Shared%20Documents/DBPDF/Application%20Tier%203%20and%204/VA%20Marker%20Solution%20Build%20Document.pdf https://vaww.eie.va.gov/SysDesign/CS/Operating%20System%20Deployment%20OSD/Forms/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Shared%20Documents/DBPDF/Application%20Tier%203%20and%204/VA%20Marker%20Solution%20Build%20Document.pdf https://vaww.vashare.oit.va.gov/sites/isac/NamingConventions/Pages/Home.aspx
March 2019 Endpoint Baselines | 2
Each baseline will give an example for that particular baseline.
6 ACTIVE DIRECTORY
This is to help with guidance on computer account Organizational Unit (OU) location. The approved standard operating procedure (SOP) for Active Directory Users and Computers (ADUC) should be followed. Baselines that require special OU placement will be provided in that baseline section. Some might need special consideration like a kiosk or in the domain Specialized Systems OU. If not, then the systems are to be placed in workstations or laptops OU per the SOP. Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure (Active Directory) Division but it will be up to the person setting up the computer to verify everything is in place and correct.
7 GROUP POLICY OBJECTS
Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure (Active Directory) Division but it will be up to the person setting up the computer to verify everything is in place and correct. Group Policy Objects (GPO) consists of security settings taken from the United States Government Configuration Baseline (USGCB), Defense Information Systems Agency (DISA), Security Technical Implementation Guide (STIG) and Microsoft. GPOs also consist of settings that are needed to standardize for application, baseline specific (e.g. kiosk), and other known settings required within the VA. The GPOs for each baseline will be listed in the same list as the applications portal and SharePoint Views will be used to filter the list for each baseline. It is the combination or all these settings that make up the baseline (not just security).
8 ENCRYPTION
Windows 7 baseline(s) use Symantec Endpoint Encryption (SEE) and Windows 10 uses BitLocker/Microsoft BitLocker Administration and Monitoring (MBAM). Each encryption technology use one of two options. One has a pre-boot authentication and the other uses a pass-through. This is not always determined via the baseline but the hardware. In some cases, it will be identified how to set it for it to work (e.g. kiosk is pass-through). Refer to the encryption SOP for more guidance as needed.
9 SYSTEMS ENGINEERING AND DESIGN REVIEW
The Systems Engineering and Design Review (SEDR) number will be documented in each baseline. It will include the ratification date when known and the Change Order number when applicable.
https://vaww.eie.va.gov/techstrategy/TAR
March 2019 Endpoint Baselines | 3
10 REPORTING
Each baseline will have a Configuration Manager (CM) report for application compliance. A complete list can be found at the Baselines portal, and under the purpose of this document, as it lists all of the baselines and that link includes reporting. It is our goal for each baseline to have a report for GPO settings. Presently the VA cannot provide this report with its current toolset and configuration. We have been working diligently to get this setup and configured within the VA for many years now and will continue to work with those teams responsible for hosting and managing the reports to have it setup at some point soon. We can provide a report of the USGCB and DISA STIG settings as a whole or unmodified for VA deviations on the IBM BigFix Compliance portal for former regions 3 and 4 and for former regions 1, 2 and all others,, but not specifically the ones used in the Endpoint Baseline(s) for these approved VA baseline(s). We are continuing to work towards the goal of reporting on all and only the settings in the VA baseline(s).
Desktop Baseline Assessment Toolkit (dBAT) is another tool created by SD Desktop and Device Engineering (DDE) to help with reporting compliance for baselines. It will show the active directory location of the computer, applications and their compliance and GPOs applied. It should be used on all systems after the imaging and patching process to verify it has all the correct applications and version before placing in production environment for the end user.
Refer to the dBAT portal to get help, how-to, feedback or ask questions.
11 CONTACTS
If you have any questions or comments, you can reach out to the proper group. The following is a list of what is available:
• OSD – Contact your District (former regional) Client Tech team and they will help or reach out to SD national team for assistance as needed via feedback portal. You can also search open and closed items on the same portal.
• Application – Use the Build Documents for each application. If not successful, then contact your District (former regional) Client Tech team and they will help or reach out to SD national team for assistance as needed via feedback portal. You can also search open and closed items on the same portal.
• ESL Client Technologies (District or Region) o OIT ITOPS SO IO PS ESL Client Technologies Division Chiefs
VHA FR01 ESL Client Technologies Division 1, Bradley, William D., III
VHA-FR02 ESL Client Technologies Division 2, Williamson, Sharon
VHA-FR03 ESL Client Technologies Division 3, Sutherland, Hobert L.
VHA-FR04 ESL Client Technologies Division 4, Logan, James
VBA-FR05 ESL Client Technologies Division 5, Hantz, Charles, L.
https://vaww.vashare.oit.va.gov/sites/SMS/EnterpriseReporting/Baselines/SitePages/Home.aspx https://ssologon.iam.va.gov/CentralLogin/Default.aspx?appname=core&URL=https://ssologon.iam.va.gov/CentralLogin/core/redirect.aspx&TYPE=33619969&REALMOID=06-8e087667-35bf-4917-ad25-6e8ab25a5793&GUID=&SMAUTHREASON=0&METHOD=GET&SMAGENTNAME=-SM-eV9x1Z1uAN5eAYZqaAogjWvh68eq%2fnX181iI57ZjseGdBJMmHdp7wh65%2bw9uOsDN&TARGET=-SM-HTTPS%3a%2f%2flogon%2eiam%2eva%2egov%2ffedredirectjsp%2ffedredirect%2ejsp%3fSPID%3dhttps%3a%2f%2fv2dtema1%2etic%2eva%2egov%3a443%2fibm%2fsaml20%2fdefaultSP%26RelayState%3dhttps-%3A-%2F-%2Fv2dtema1%2etic%2eva%2egov-%2F%26SPID%3dhttps-%3A-%2F-%2Fv2dtema1%2etic%2eva%2egov-%3A443-%2Fibm-%2Fsaml20-%2FdefaultSP%26SMPORTALURL%3dhttps-%3A-%2F-%2Flogon%2eiam%2eva%2egov-%2Faffwebservices-%2Fpublic-%2Fsaml2sso https://ssologon.iam.va.gov/CentralLogin/Default.aspx?appname=core&URL=https://ssologon.iam.va.gov/CentralLogin/core/redirect.aspx&TYPE=33619969&REALMOID=06-f375e503-c3ea-46d7-84fd-0838a8a00804&GUID=&SMAUTHREASON=0&METHOD=GET&SMAGENTNAME=-SM-eV9x1Z1uAN5eAYZqaAogjWvh68eq%2fnX181iI57ZjseGdBJMmHdp7wh65%2bw9uOsDN&TARGET=-SM-HTTPS%3a%2f%2flogon%2eiam%2eva%2egov%2ffedredirectjsp%2ffedredirect%2ejsp%3fSPID%3dhttps%3a%2f%2fv2dtema2%2etic%2eva%2egov%3a443%2fibm%2fsaml20%2fdefaultSP%26RelayState%3dhttps-%3A-%2F-%2Fv2dtema2%2etic%2eva%2egov-%2F%26SPID%3dhttps-%3A-%2F-%2Fv2dtema2%2etic%2eva%2egov-%3A443-%2Fibm-%2Fsaml20-%2FdefaultSP%26SMPORTALURL%3dhttps-%3A-%2F-%2Flogon%2eiam%2eva%2egov-%2Faffwebservices-%2Fpublic-%2Fsaml2sso http://vaww.eie.va.gov/SysDesign/CS/dTools/ https://vaww.eie.va.gov/SysDesign/CS/dTools/default.aspx mailto:OITITOPSSOIOPSESLClientTechnologiesDivisionChiefs@va.gov mailto:OITITOPSSOIOPSESLClientTechnologiesDivision1@va.gov mailto:William.D.Bradley@va.gov mailto:VAITRegion2CORClientTechDivision@va.gov mailto:Sharon.Williamson@va.gov mailto:OITITOPSSOIOPSESLClientTechnologiesLeadership3@va.gov mailto:Hobert.Sutherland@va.gov mailto:OITITOPSSOIOPSESLClientTechnologiesDivision4@va.gov mailto:James.Logan@va.gov mailto:OITITOPSSOIOPSESLCLIENTTECHNOLOGIESTEAM5@va.gov mailto:chuck.hantz@va.gov
March 2019 Endpoint Baselines | 4
FPO-FR06 ESL Client Technologies Division 6, Barry, Daniel o VACO – Macdonald, Michelle o AITC – Gonzalez, Alex o OIFO – OIFO SCCM
• GPO & Active Directory – Contact your District (former regional) Domain Infrastructure Division and they will help you or reach out to SD national team for assistance as needed via feedback portal. You can also search open and closed items on the same portal.
• ESL Domain Infrastructure (Active Directory) Division (see Table 1)
Table 1. Contact List
Org/Region Name E-Mail Address Phone Number
Field Operations Charles Puchon charles.puchon@va.gov 520-295-3455
FO\Region 1 Richard Sebring richard.sebring@va.gov 559-241-6474
Ron Lui ron.lui@va.gov 415-720-9715
FO\Region 2 Stefan DeMeyer stefan.demeyer@va.gov 816-701-3045
FO\Region 3 Russ Eidemiller russ.eidemiller@va.gov 727-398-6661 x14888
Alan Kaplan alan.kaplan@va.gov 704-597-3517
FO\Region 4 Jim Bator james.bator@va.gov 585-393-8288
Kareme, Ki-Ve kareme.ki-ve@va.gov 347-668-4903
FO\Region 5 Scott Anderson scott.anderson1@va.gov 630-414-3258
Michael Hrouda michael.hrouda@va.gov 708-483-5393
FO\Region 6 (FPO) Stiehl, Chris chris.stiehl@va.gov 412-329-8881
Vincent, Jeanette jeanette.vincent@va.gov 708-786-7868
EO\AITC Richard Siegelman richard.siegelman@va.gov 512-326-6516
Denver Griffith denver.griffith@va.gov 512-326-6637
EO\FSC Chris Wildermuth christopher.wildermuth@va.gov 512-386-2200
EO\QITC Michael Thompson michael.thompson@va.gov 703-441-3037
Scott Walker scott.walker@va.gov 703-441-3089
Field Offices Carolyn Brown-Hardie carolyn.brown-hardie@va.gov 817-385-3856
ESE\Client Services Kevin Overholt kevin.overholt@va.gov 518-449-0668
Jamie Hosley jamie.hosley@va.gov 518-449-0251
ESE\Platforms Jay Hawkins jay.hawkins@va.gov 937-241-0296 mailto:OITITOPSSOIOPSClientTechnologiesTeam1@va.gov mailto:Daniel.Barry2@va.gov mailto:michelle.macdonald@va.gov mailto:Alex.Gonzalez@va.gov mailto:OIFOSCCM@va.gov mailto:charles.puchon@va.gov mailto:Richard.Sebring@va.gov mailto:ron.lui@va.gov mailto:Stefan.DeMeyer@va.gov mailto:Russ.Eidemiller@va.gov mailto:alan.kaplan@va.gov mailto:James.Bator@va.gov mailto:kareme.ki-ve@va.gov mailto:scott.anderson1@va.gov mailto:Michael.Hrouda@va.gov mailto:Chris.Stiehl@va.gov mailto:jeanette.vincent@va.gov mailto:Richard.Siegelman@va.gov mailto:Denver.Griffith@va.gov mailto:christopher.wildermuth@va.gov mailto:michael.thompson@va.gov mailto:scott.walker@va.gov mailto:carolyn.brown-hardie@va.gov mailto:kevin.overholt@va.gov mailto:jamie.hosley@va.gov mailto:jay.hawkins@va.gov
March 2019 Endpoint Baselines | 5
ESE\Core Infrastructure Services
Joyce Nkansah joyce.nkansah@va.gov 708 786-5915
Salinda Walker salinda.walker@va.gov 817-385-3879
Robert Sanson robert.sanson@va.gov 518-542-4582
NSOC Chris Adams chris.adams2@va.gov 304-262-5270
Miguel Valls miguel.Valls@va.gov 304-262-5217
OIG Rhena Williams rhena.williams@va.gov 708-202-5191
Jess del Mundo jess.delmundo@va.gov 202-461-4621
Schannel Davis schannel.davis@va.gov 202-461-4436
VACO ITSS David Bender david.bender@va.gov 202-632-4709
• Reporting o Access to CM Reports: Field staff, such as remote computer health check technicians or Information Security Officers, requiring access should follow local organization access requests processes in order to be added as a member of the VA IT FO xxx Compliance Scorecards security groups. All Area Managers and NCIOs should also have access to maintain compliance going forward.
o Issues in the logic of CM reports email OIT ITOPS SD EE EEMR Reporting team and copy Kevin.Overholt@va.gov
12 ADDITIONAL REFERENCES AND LINKS
• Active Directory Administrative Roles SOP
• Active Directory Standardization portal
• Organizational Units – Standardized Structure
• Organizational Unit Standardization - Specialized Systems
• Service Delivery, Endpoint Engineering, Desktop and Device Engineering o Application List o GPO List o Baseline List
• Systems Engineering and Design Review (SEDR)
• IBM BigFix Compliance reports. These are for reference only as they are not specific to the baselines and include settings from the USGCB and DISA STIG that the VA does not include in its baselines.
o Checklists https://v2dtema1.tic.va.gov/scm/checklists mailto:Joyce.Nkansah@va.gov mailto:Salinda.Walker@va.gov mailto:Robert.Sanson@va.gov mailto:chris.adams2@va.gov mailto:miguel.Valls@va.gov mailto:rhena.williams@va.gov mailto:jess.delmundo@va.gov mailto:schannel.davis@va.gov mailto:David.Bender@va.gov https://vaww.vashare.oit.va.gov/sites/euo/EUOWiki/PublicWikiDocs/ACTION%20%20%20Request%20for%20Security%20Groups.msg https://vaww.vashare.oit.va.gov/sites/euo/EUOWiki/PublicWikiDocs/ACTION%20%20%20Request%20for%20Security%20Groups.msg https://vaww.vashare.oit.va.gov/sites/euo/EUOWiki/PublicWikiDocs/Nested%20Security%20main%20groups.pdf mailto:VAITEngineeringCSCAMTReporting@va.gov mailto:Kevin.Overholt@va.gov https://vaww.sde.portal.va.gov/sites/fo/committees/coresystems/AD%20Standardization/Standards%20Development%20Project_Documentation/AD%20Standardization%20Administrative%20Roles%20SOP%20version%202.0.docx https://vaww.sde.portal.va.gov/sites/fo/committees/coresystems/AD%20Standardization/Forms/AllItems.aspx https://vaww.sde.portal.va.gov/sites/fo/committees/coresystems/Wiki/Organizational%20Units%20-%20Standard%20Structure.aspx https://vaww.sde.portal.va.gov/sites/fo/committees/coresystems/Wiki/Organizational%20Units%20-%20Specialized%20Systems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Applications%20(All).aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/GPO%20All.aspx http://vaww.eie.va.gov/SysDesign/CS/Lists/Baseline%20List/AllItems.aspx https://vaww.eie.va.gov/techstrategy/TAR https://v2dtema1.tic.va.gov/scm/checklists
March 2019 Endpoint Baselines | 6 https://v2dtema2.tic.va.gov/scm/checklists o Windows 7 USGCB https://v2dtema1.tic.va.gov/scm/checklists/70 https://v2dtema2.tic.va.gov/scm/checklists/30 o Windows 10 DISA STIG https://v2dtema1.tic.va.gov/scm/checklists/201 https://v2dtema2.tic.va.gov/scm/checklists/343 o Internet Explorer 11 DISA STIG https://v2dtema1.tic.va.gov/scm/checklists/192 https://v2dtema2.tic.va.gov/scm/checklists/333
• BitLocker guides
• Reporting TBD in this document – The following reports are not available in the VA as we do not currently have a method for reporting on these setting based on these approved baseline settings. We are working to get something in place, until then we are adding a placeholder in the baseline document for each item.
o DISA STIG report (TBD) o Complete baseline settings report (TBD)
• Navigation of SharePoint Views in this document
The DDE SharePoint lists consist of views. You will need to select the baseline name from the View menu by clicking the ellipse (…) on the Standards for Baselines portal (see Figure 1. Standards for Baseline portal page).
Figure 1. Standards for Baseline portal page https://v2dtema2.tic.va.gov/scm/checklists https://v2dtema1.tic.va.gov/scm/checklists/70 https://v2dtema2.tic.va.gov/scm/checklists/30 https://v2dtema1.tic.va.gov/scm/checklists/201 https://v2dtema2.tic.va.gov/scm/checklists/343 https://v2dtema1.tic.va.gov/scm/checklists/192 https://v2dtema2.tic.va.gov/scm/checklists/333 https://vaww.eie.va.gov/SysDesign/CS/Shared%20Documents/Forms/AllItems.aspx?RootFolder=/SysDesign/CS/Shared%20Documents/Encryption/BitLocker https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Applications%20(All).aspx
March 2019 Endpoint Baselines | 7
APPENDIX A: WINDOWS 7 BASELINE
This baseline is the primary/core Windows 7 baseline used in the VA for computers unless there is a sub-baseline as documented. This baseline will have a list of mandatory applications including the version; it will also have a list of mandatory GPO settings. With the primary/core baseline sites will then have to decide what additional applications and GPO settings to install and implement as long as they do not override the items listed in the primary/core baseline. If a conflicting item is required a Strategic Technology Alignment Team (STAT) waiver or Plan of Action and Milestones (POA&M) will need to be obtained and documented for their site.
A.1 Hardware This baseline uses any of the hardware that is listed as Operating System Deployment (OSD) supported. The OSD supported hardware is referenced on the Hardware portal.
A.2 Applications The applications for this baseline are listed on the Standards for Baselines portal and SharePoint View for the specific baseline to filter the application list for this baseline. Check the portal for the up to date list and versions.
A.3 Build Method To build the Endpoint Baselines computer, use the Baseline collection variable with the OSD task sequence to install the required applications listed for the Endpoint Baselines(s). This process is detailed in the Configuration Manager OSD Guide.
In order to maintain this baseline please refer to the VA Marker Solution MSI Build Document for the 1VA collection to exclude from standard application deployments.
A.4 Computer Naming Follow the VA naming convention https://vaww.vashare.oit.va.gov/sites/isac/NamingConventions/Pages/Home.aspx
Device Type= WS or LT and the first three characters of Device ID= Project name Example: ISA-WSXXXXXXXX Location Code = ISA- Device Type = WS or LT Device ID = XXXXXXXX (The 8 XXXXXXXX is up to each site)
A.5 Active Directory This is only to help with guidance on computer account Organizational Unit (OU) location. The SOP for ADUC should be followed. For special OU placement it will be provided in that sub-https://vaww.eie.va.gov/SysDesign/CS/_layouts/listform.aspx?PageType=4&ListId=%7b253CBBEF-9423-44D4-9501-0824E70CF23F%7d&ID=16&ContentTypeID=0x010073EB5475940BDD498C460AF574F69CC7 https://vaww.eie.va.gov/SysDesign/CS/hardware/Lists/Hardware%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Windows%207.aspx https://vaww.eie.va.gov/SysDesign/CS/Operating%20System%20Deployment%20OSD/Forms/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Shared%20Documents/DBPDF/Application%20Tier%203%20and%204/VA%20Marker%20Solution%20Build%20Document.pdf
March 2019 Endpoint Baselines | 8 baseline section. Some might need special consideration like a kiosk or in the domain Specialized Systems OU. If not, then the systems are to be placed in workstations and laptops per SOP.
A.6 Group Policy Objects The GPOs for this baseline are listed on the Standards for Baselines portal with the applications and the SharePoint View is used to filter the list for this baseline. Check the portal for the up to date list and versions. Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure Division but it will be up to the person setting up the computer to verify everything is in place and correct before proceeding and if not take action to get it completed.
A.7 Encryption Windows 7 baseline(s) use Symantec Endpoint Encryption (SEE) using one of two options. One has a pre-boot authentication and the other uses a pass-through. This is not always determined via the baseline but the hardware. In some cases, it will be identified how to set it for it to work (e.g. kiosk is pass-through). Refer to the encryption SOP for more guidance as needed.
A.8 Systems Engineering and Design Review Systems Engineering and Design Review (SEDR) #: N/A
Ratified Date: N/A
Change Order#: N/A
A.9 Reporting Application report
DISA STIG reports at https://v2dtema1.tic.va.gov/scm/checklists and
Complete baseline settings report (TBD) https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Windows%207.aspx https://vaphcsmssqlrrn1.vha.med.va.gov/Reports/Pages/Report.aspx?ItemPath=%2fExecutive+Dashboards%2fDesktop+Engineering+Score+Cards%2fBaselines%2fWindows+7%2fWindows+7 https://v2dtema1.tic.va.gov/scm/checklists
March 2019 Endpoint Baselines | 9
APPENDIX B: WINDOWS 7 SUB-BASELINES
B.1 Audiology Workstation This baseline is the Windows 7 Audiology Workstation sub-baseline used in the VA. This baseline will have a list of mandatory applications including the version. This baseline is unique in that it has some applications in the baseline that not all sites will install and are listed separately as such as well as reports. It will also have a list of mandatory GPO settings. With this baseline sites cannot add additional applications and GPO settings. They cannot obtain a Strategic Technology Alignment Team (STAT) waiver or Plan of Action and Milestones (POA&M) or make any changes to the baseline.
• VA OIT Issues contact Project Manager Susan Knause.
• Audiology application issues contact the national Audiology POC Chad Gladden.
B.1.1 Hardware There is no specific hardware for the baseline. There may have been purchases specified for using with this baseline (e.g. HP Pro Desk 600 G1 SFF purchase), but that is not a requirement for using this baseline from a baseline documentation perspective. The Operating System Deployment (OSD) supported hardware is referenced on the Hardware portal.
B.1.2 Applications The applications for this baseline are listed on the Standards for Baselines portal. A SharePoint View for the specific baseline is available to filter the application list for this baseline. Check the portal for the up to date list and versions. Take note that some applications are not installed at some sites as they do not support the associated accessories or hardware. These are noted in the application portal and the reports.
B.1.3 Build Method In order to build the Audiology baseline computer, use the Baseline collection variable with the OSD task sequence to install the required applications listed for Audiology. This process is detailed in the Configuration Manager OSD Guide.
B.1.4 Computer Naming Follow the VA naming convention https://vaww.vashare.oit.va.gov/sites/isac/NamingConventions/Pages/Home.aspx
Device Type=SP and the first three characters of Device ID= Project name https://vaww.eie.va.gov/SysDesign/CS/_layouts/15/listform.aspx?PageType=4&ListId=%7B253CBBEF%2D9423%2D44D4%2D9501%2D0824E70CF23F%7D&ID=2&ContentTypeID=0x010073EB5475940BDD498C460AF574F69CC7 mailto:Susan.Knause@va.gov mailto:Chad.Gladden2@va.gov https://vaww.sde.portal.va.gov/docctr/Bulletins/Audiology_Workstation_Solutions_Procurement_Update_No.5.pdf https://vaww.eie.va.gov/SysDesign/CS/hardware/Lists/Hardware%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Windows%207.aspx https://vaww.eie.va.gov/SysDesign/CS/Operating%20System%20Deployment%20OSD/Forms/AllItems.aspx
March 2019 Endpoint Baselines | 10
Example: ISA-SPAUDXXXXX Location Code = ISA- Device Type = SP Device ID = AUDXXXXX (The 5 XXXXX is up to each site)
B.1.5 Active Directory Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure Division but it will be up to the person setting up the computer to verify everything is in place and correct before proceeding, and if not, take action to get it completed by contacting the appropriate Domain Infrastructure Division. The required Organizational Unit (OU) for the baseline is they can exist in the normal location where workstations currently exist in Active Directory.
B.1.6 Group Policy Objects The GPOs for this baseline are listed on the Standards for Baselines portal with the applications and the SharePoint View is used to filter the list for this baseline. Check the portal for the up to date list and versions. Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure Division but it will be up to the person setting up the computer to verify everything is in place and correct before proceeding and if not take action to get it completed.
B.1.7 Encryption No specialized configuration of encryption is required. Systems will use Symantec Endpoint Encryption (SEE) pre-boot authentication. Encryption should be handled by the local and/or regional encryption administrators.
B.1.8 Systems Engineering and Design Review Systems Engineering and Design Review (SEDR) #: SEDR16-1685
Ratified Date: 11/08/2016
Change Order #: CO354322FY16
B.1.9 Reporting Application report
DISA STIG report (TBD)
Complete baseline settings report (TBD) https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Audiology%20Workstation.aspx https://vaphcsmssqlrrn1.vha.med.va.gov/Reports/Pages/Report.aspx?ItemPath=/Executive+Dashboards/Desktop+Engineering+Score+Cards/Baselines/Audiology+Workstation/Audiology+Workstation&ViewMode=Detail
March 2019 Endpoint Baselines | 11
B.1.10 Baseline Specific Instructions This baseline has semi-annual updates for hearing aid software that is released in May and November. The CM task sequence name is 1VA - Audiology Updates [Month] [Year]. Follow normal procedure for release.
March 2019 Endpoint Baselines | 12
B.2 Bed Management Solution (BMS) Whiteboard Kiosk This baseline is the Windows 7 Bed Management Solution (BMS) Whiteboard Kiosk sub-baseline used in the VA for configuration of computers for the Bed Management Solution (BMS) Whiteboard Kiosk project. This baseline will have a list of mandatory applications including the version; it will also have a list of mandatory GPO settings. With this baseline sites, cannot add additional application and GPO settings. They cannot obtain a Strategic Technology Alignment Team (STAT) waiver or Plan of Action and Milestones (POA&M) or make any changes to the baseline.
BMS Whiteboard Kiosk Build Process (not OSD) – National Service Desk to create a ticket. Have the NSD used and assign to: The Request Area will be NTL.APP.HealtheVet VistA.Bed Management Solutions. The group responsible will be NTL SUP BMS.
B.2.1 Hardware This baseline uses any of the hardware that is listed as Operating System Deployment (OSD) supported. The OSD supported hardware is referenced on the Hardware portal.
B.2.2 Applications The applications for this baseline is listed on the Standards for Baselines portal and SharePoint View for the specific baseline to filter the application list for this baseline. Check the portal for the up to date list and versions.
B.2.3 Build Method In order to build this baseline computer, use the Baseline collection variable with the OSD task sequence to install the required applications listed for this baseline. This process is detailed in the Configuration Manager OSD Guide.
B.2.4 Computer Naming Follow the VA naming convention https://vaww.vashare.oit.va.gov/sites/isac/NamingConventions/Pages/Home.aspx
Device Type=KI and the first three characters of Device ID= Project name Example: ISA-KIBMSWXXXXX Location Code = ISA- Device Type = KI Device ID = BMSWXXXXX (The 5 XXXXX is up to each site)
B.2.5 Active Directory Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure Division but it will be up to the person setting up the computer to verify https://vaww.eie.va.gov/SysDesign/CS/_layouts/listform.aspx?PageType=4&ListId=%7b253CBBEF-9423-44D4-9501-0824E70CF23F%7d&ID=24&ContentTypeID=0x010073EB5475940BDD498C460AF574F69CC7 https://vaww.eie.va.gov/SysDesign/CS/hardware/Lists/Hardware%20List/AllItems.aspx https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Bed%20Management%20Solution%20BMS%20Whiteboard%20Kiosk.aspx
March 2019 Endpoint Baselines | 13 everything is in place and correct before proceeding, and if not, take action to get it completed by contacting the appropriate Domain Infrastructure Division. The required Organizational Unit (OU) for the BMS Whiteboard kiosk is root\Specialized Systems\Kiosks\BMSW\yourkiosk.
B.2.6 Group Policy Objects The GPOs for this baseline are listed on the Standards for Baselines portal with the applications and the SharePoint View is used to filter the list for this baseline. Check the portal for the up to date list and versions. Management of the location in Active Directory (AD) will be handled by the Domain Infrastructure Division but it will be up to the person setting up the computer to verify everything is in place and correct before proceeding and if not take action to get it completed.
Link the VA ESE DT BMS Whiteboard KIOSK Standards GPO to root\Specialized Systems\Kiosks\BMSW\
1. In the Group Policy Management Console (GPMC), select the Delegation tab for the VA ESE DT BMS Whiteboard KIOSK Standards GPO.
2. Click the Advanced button in the lower right-hand corner.
3. Click Add and search for your domains standard delegation group (usually VHAxxxAllAccountAdmins).
4. Click the OK button.
5. Click the Security tab in the dialog box.
Figure 2. Dialog box Security tab
6. In the Group or user names section, highlight the group you added.
7. In the Permissions section, check Deny for the Apply group policy option.
https://vaww.eie.va.gov/SysDesign/CS/Lists/Application%20Standards/Baseline%20Bed%20Management%20Solution%20BMS%20Whiteboard%20Kiosk.aspx
March 2019 Endpoint Baselines | 14
8. Click the Apply button.
9. Click the OK button.
NOTE: To assure the proper settings are in place for the kiosks, make sure the kiosk OU is set so that the appropriate kiosk policy has the highest precedence.
NOTE: As indicated in the standards list, any VA Banner GPO should not be applied to any kiosks systems in a domain. This allows for the proper functioning of the auto-login feature.
All standards GPOs for this baseline should be inherited or linked to the baseline OU.
B.2.7 Encryption No specialized configuration of encryption is required. Systems will use Symantec Endpoint Encryption (SEE) Auto-logon. Encryption should be handled by the local and/or regional encryption administrators.
B.2.8 Systems Engineering and Design Review Systems Engineering and Design Review (SEDR) #: SEDR18-1810
Ratified Date: 02/21/2018
Change Order #: CO402355FY17
B.2.9 Reporting Application report
DISA STIG report (TBD)
Complete baseline settings report (TBD)
B.2.10 Baseline Specific Instructions
B.2.10.1 Service Account
• There are two separate service accounts for this baseline. They are not the same account.
• The first service account will be used for Windows auto logon at domain level.
• The second service account is used for the Whiteboard website access. Instructions below call this Whiteboard Kiosk Default User Name.
https://vaphcsmssqlrrn1.vha.med.va.gov/Reports/Pages/Report.aspx?ItemPath=%2fExecutive+Dashboards%2fDesktop+Engineering+Score+Cards%2fBaselines%2fBed+Management+Solution+(BMS)+Whiteboard+Kiosk%2fBed+Management+Solution+(BMS)+Whiteboard+Kiosk+Baseline&ViewM
March 2019 Endpoint Baselines | 15
• You will need to contact the ESL Domain Infrastructure (Active Directory) Division for each of the service account names and passwords. A list is found in section 11 Contacts on page 3.
B.2.10.2 Configure the Whiteboard Kiosk Default Login User (Service Account) in
BMS
For the current facility that will display the associated Whiteboard page, a default user needs to be configured in BMS application for the Ward Whiteboard Kiosk. Coordinate with the local site BMS POC to use the second service account listed above, Not the Windows auto logon service account.
To configure the Whiteboard Kiosk Default User:
1. Go to the BMS Site Home Page
2. Click on the Site Options link
3. Click on the Facility Setting link
4. On the Facility Configuration window, fill in the following fields:
• Whiteboard Kiosk Default User Name – User name
• Whiteboard Kiosk Password – Password
• Whiteboard Kiosk Password Confirm – BMS Service Account ID
Figure 3. Facility Configuration window
5. Click Submit.
March 2019 Endpoint Baselines | 16
B.2.10.3 Assign a Role to the Whiteboard Kiosk Default User in BMS Each facility must assign the BMS EMS USER Role to the Service Account ID created to run the Whiteboard Kiosk URL. This assignment can be done from the BMS Admin Section > Add/Edit BMS User hyperlink or Facility Site Options > BMS User Add/Edit hyperlink.
1. Click the Select Existing NT User Name button
2. Select the correct VISN Domain from the left dropdown box.
3. In the NT User Name box, enter the BMS Service Account ID created for the BMS Whiteboard Kiosk. Click the Find button
4. Click the Selected radio button for the user. Click the Select button.
5. In the Admin User dropdown, select No.
6. In the Audit Log User dropdown, select No.
7. In the Site User dropdown, select Yes.
8. In the EMS User dropdown, select No.
9. In the EMS Supervisor User dropdown, select No.
10. In the READ Access dropdown, select Yes.
11. In the WRITE Access dropdown, select Yes.
Figure 4 - Whiteboard Kiosk User Role Assignment Fields
12. Click Submit.
March 2019 Endpoint Baselines | 17
B.2.10.4 Create the Ward Whiteboard Kiosk URL The Ward Whiteboard display uses parameters to determine the behavior of the display.
For example, the whiteboard can display a specific ward or ALL wards for a site by setting the parameter wardName. Table 2 contains descriptions for each whiteboard display parameter along with available options for each.
Table 2. Ward Whiteboard URL Configuration Parameters
Parameter Short Description Options facilityCode Code of facility (e.g., BROCKTON = BRK). Enter the 3-character facility ID.
wardName Name of BMS Ward Name. To see all the wards the value that needs to be configured is ALL.
These are the BMS WARDS as defined in the Facility, Site Options, VistA Ward Add/Edit.
The Ward name value should match the "BMS WARD GROUP TEXT". A single ward can be entered or the value "ALL" to display all the wards at the facility.
splitScreen To split the page in two tables enters the value Yes. Yes No displayPTCode How the patient should be displayed under the column "Patient" (full name or 1st+Last 4) or LastName.
LastName is required for Kiosk mode due to Privacy regulations.
FirstAndLast4 LastName genderColorCode To change the background color for the row according with patient’s gender.
Blue/Pink None displayFooterCensus To view the footer census. Yes No displayStaffAttending What column is displayed in the table? (Staff column, Attending column or both).
Staff and Attending Staff Attending scrollRate The timer interval will affect the scrolling speed. This parameter can be absent. (If specified then it represents seconds).
Null or an integer value.
• Determine the parameters for the Kiosk, and create the URL
• Below is a sample URL to display All Wards for site BRK:
https://vaww.bms.va.gov/WardWhiteboardUrl?facilityCode=BRK&wardName=ALL&splitSc reen=No&displayPTCode=LastName&genderColorCode=Blue/Pink&displayFooterCensus=Y es&displayStaffAttending=Staff%20and%20Attending&scrollRate=20
• Test the URL. Once you have the URL, type it into a browser to test. The BMS Ward Whiteboard should come up.
https://vaww.bms.va.gov/WardWhiteboardUrl?facilityCode=BRK&wardName=ALL&splitScreen=No&displayPTCode=LastName&genderColorCode=Blue/Pink&displayFooterCensus=Yes&displayStaffAttending=Staff%20and%20Attending&scrollRate=20 https://vaww.bms.va.gov/WardWhiteboardUrl?facilityCode=BRK&wardName=ALL&splitScreen=No&displayPTCode=LastName&genderColorCode=Blue/Pink&displayFooterCensus=Yes&displayStaffAttending=Staff%20and%20Attending&scrollRate=20 https://vaww.bms.va.gov/WardWhiteboardUrl?facilityCode=BRK&wardName=ALL&splitScreen=No&displayPTCode=LastName&genderColorCode=Blue/Pink&displayFooterCensus=Yes&displayStaffAttending=Staff%20and%20Attending&scrollRate=20
March 2019 Endpoint Baselines | 18
NOTE: A site can have a different URL for each kiosk
• Copy the URL to a text file and save it on the desktop or a network share where you can access it for setting up the default BMS WhiteBoard website in the next section.
B.2.10.5 Setting up Default BMS WhiteBoard Website with Your Site URL
1. Make sure your Domain Infrastructure team has performed their step found in B.2.6 Group
Policy Objects.
2. Logon to the kiosk system with your eToken account.
3. Navigate to C:\KIOSK\BMSW.
4. Right-click the CreateBMSsite.cmd file and select Run as administrator.
5. Copy and paste the BMS WhiteBoard URL created earlier into the dialog box and click OK.
Figure 5. BMS WhiteBoard Configuration dialog box
6. Click OK again to confirm the setting. Internet Explorer will open with the URL as home page. Your BMS WhiteBoard Kiosk Internet Explorer home page is now set to your specific site. This setting will apply to all users on this kiosk workstation.
NOTE: Close and re-open Internet Explorer to confirm your home page. Repeat above steps to change the URL setting if needed.
NOTE: if you want to close the dialog box without saving the setting, open task manager and end the cscript.exe process.
B.2.10.6 Setup for Hourly Internet Explorer Refresh
1. Logon to the kiosk system with your eToken account.
2. Open Computer Management. Under System Tools, select Task Scheduler.
March 2019 Endpoint Baselines | 19
Figure 6. Computer Management - System Tools - Task Scheduler
3. Right-click Task Scheduler and select Create Task.
4. On the Create Task dialog box, select the General tab.
Figure 7. Create Task dialog box – General tab
a. In the Name field, enter the title of the scheduled task (e.g., IE Refresh).
March 2019 Endpoint Baselines | 20
b. In the Description field, enter a description as needed.
c. Click the Change User or Group… button.
1) In the Select User or Group dialog box, enter the BMS WhiteBoard Kiosk service account information specific to your location.
2) Click the OK button.
d. Continuing under the General tab, select the Run only when user is logged on radio button.
e. Check the Hidden checkbox.
f. In the Configure for dropdown, select Windows 7, Windows Server 2008 R2.
5. On the Create Task dialog box, select the Trigger tab.
Figure 8. Create Task dialog box – Trigger tab
a. Click the New… button.
b. In the New Trigger dialog box, under the Begin the task dropdown select On a schedule (see Figure 9).
March 2019 Endpoint Baselines | 21
Figure 9. New Trigger dialog box
c. Under the Settings section, select the Daily radio button.
d. Under the Settings section in the Recur every field, enter 1 days.
e. Under the Advanced settings section:
1) Check the Repeat task every checkbox
2) In the Repeat task every dropdown, select 1 hour.
3) In the for the duration of dropdown, select 1 day.
NOTE: The task is scheduled to repeat hourly in this example. You may change it as needed.
f. Under the Advanced settings section, check the Enabled checkbox
g. Click the OK button.
6. On the Create Task dialog box, select the Actions tab (see Figure 10).
March 2019 Endpoint Baselines | 22
Figure 10. Create Task dialog box – Trigger tab
a. Click the New… button.
b. On the New Action dialog box, click the Browse… button.
Figure 11. New Action dialog box
c. Navigate to C:\Kiosk\BMSW. Select the RefreshIE.cmd file and click the Open button.
d. On the New Action dialog box, the Program/script field now has C:\Kiosk\BMSW\RefreshIE.cmd entered.
e. Click the OK button.
March 2019 Endpoint Baselines | 23
7. On the Create Task dialog box, click the OK button.
8. The IE Refresh task is now scheduled.
Figure 12. Computer Management Screen showing IE Refresh scheduled
B.2.10.7 Setup Auto Logon
NOTE: Be sure that the correct password is being used. If auto logon does not work, you may rerun these steps.
1. Logon to the kiosk system with your administrative eToken account.
2. Navigate to the C:\Kiosk\AutoLogon folder.
3. Right-click the Autologon.exe file and select Run as administrator.
4. Enter information on…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.