Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Take full advantage of new web based administration tools without the risks current page
Link copied

Take full advantage of new web based administration tools without the risks

Nov 2, 2017
Author:
Bomgar portraits Jan 17 1708
Karl Lankford
Director, Solutions Engineering
Blog banner default
Take full advantage of new web based administration tools without the risks
Bomgar portraits Jan 17 1708
Karl Lankford
Director, Solutions Engineering

Microsoft’s recent Project Honolulu announcement introduces a new method of managing Windows Server systems from a centralized HTML5 web application, moving away from the legacy MMC snap-ins. This now makes it much easier than using a command line tool for ad-hoc configuration and troubleshooting tasks that depend more on exploration and investigation rather than scripting and automation.

Giving access to web-based administration is a great way of supporting the need for mobility in the workforce, however each one of these systems can increase an organisation’s attack surface. Data breaches frequently result from poor authentication practices, weak passwords, and even unsecure remote access, which remains as the #1 method of compromise according to Trustwave’s 2017 Global Security Report. By implementing this new web-based management method, organisations could inadvertently create a significant security risk. In a worst-case scenario, a threat actor could destroy or reconfigure the whole infrastructure with a few simple clicks if this system was compromised.

But there is good news. Implementing the following simple controls allows organisations to provide remote access to these new Windows sever management tools and remain secure.

  • Multifactor authentication is an important security control for critical systems and should be implemented wherever possible. If a management console is not compatible with multifactor authentication, consider putting it behind a secure access tool that requests a second factor before providing access to the solution.
  • Network segmentation delivers a great security control, but when providing remote access it can become very complex. The goal is to make the management console "go dark", which may sound complicated but the key is to implement a system that lets users do their jobs faster and easier than they do today. Look for a solution that can provide access from anywhere, in a hardened sandboxed browser without ever exposing or publishing the management console directly out to the internet.
  • Organizations often struggle with privileged user management. Frequently, access rights aren’t removed or updated if a job function changes or a user leaves the organization. And by creating shared accounts for the onboarding of contractors and 3rd party vendors, the risk of sharing credentials and access to these types of systems is clear, with 81% of hacking related breaches using stolen and/or weak passwords according the Verizon 2017 Data Breaches Incident Report (DBIR). It’s important to deploy a solution that allows for granular control and management of privileged users – giving them the right access, to the right systems, at the right time.
  • Password management is just as important as privileged user management. Look for an enterprise password vault where credentials can be stored, rotated, and randomized so users never see them. Eliminating the visibility of credentials reduces the threat of being phished or used through another pathway.

With the drive by Microsoft and other vendors launching new tools to enable IT teams to do their jobs with more efficiency and speed, comes additional risks. By ensuring the right controls and security are implemented around all remote access pathways into your infrastructure, organisations can take full advantage of the benefits that these new tools can provide.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Channelling Our Talent: BeyondTrust Champions Scoop Two Awards
    Nov 25, 2020 Channelling Our Talent: BeyondTrust Champions Scoop Two Awards
    Blog
    1m
  • Tackling Your Most Challenging Privileged Access Use Cases
    Sep 7, 2016 Tackling Your Most Challenging Privileged Access Use Cases
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.