<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Comment Feed for Channel 9 - Network Access Protection with MSIT</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT/RSS"></atom:link>
	<image>
		<url>http://ecn.channel9.msdn.com/o9/previewImages/100/249516_100x75.jpg</url>
		<title>Channel 9 - Network Access Protection with MSIT</title>
		<link></link>
	</image>
	<description>After months of cajoling, Adam was finally able to convince Jeff Sigman from the NAP team and Brent Atkison from MSIT to sit still for 30 minutes to talk about why we created NAP, and how we went about deploying it worldwide at Microsoft.&amp;nbsp; Ah, who am I
 kidding.&amp;nbsp; Jeff&#39;s been asking me for months to put his blue anime hair up on Channel9.&amp;nbsp; Here you go Jeff.&amp;nbsp; Persistance pays off.
Network Access Protection is a new feature in Windows Server 2008 that allows you to enforce computer health requirements before allowing machines to communicate on the network.&amp;nbsp; It&#39;s the answer to the question &amp;quot;do I trust that this machine is patched and won&#39;t
 infect other machines on my network?&amp;quot;
These guys have done some pretty impressive stuff.&amp;nbsp; The NAP team worked with a list of partners as long as your arm to make sure NAP will play nicely with whatever switch hardware you&#39;ve invested in.&amp;nbsp; Brent shares some impressive sizing guidelines for implementing
 NAP:&amp;nbsp; Microsoft turned reporting and deferred enforcement on 120,000 machines worldwide, using a very small number of servers.&amp;nbsp; Very small.&amp;nbsp; Less than 3.&amp;nbsp; Total help desk calls as a result?&amp;nbsp; Also a very small number.&amp;nbsp; Oh, and he did that deployment using beta
 builds of Longhorn Server 2008.</description>
	<link></link>
	<language>en</language>
	<pubDate>Mon, 20 May 2013 12:39:26 GMT</pubDate>
	<lastBuildDate>Mon, 20 May 2013 12:39:26 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[If NAP prevents a non-healthy computer from acquiring an ip address i.e. lacking Windows patches or an antivirus, then how is it able to acquire them conveniently?<br>
<br>
Or is it connected to another server exclusively dedicated to this function?<p>posted by gr@nt</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633276676760000000</link>
		<pubDate>Thu, 11 Oct 2007 02:47:56 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633276676760000000</guid>
		<dc:creator>gr@nt</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[you can specify what to do with unhealthy machines.&nbsp; Typically, you'd configure your network to put the machines on a remediation v-lan where they can only access a remediation server that pushes down any required patches, antivirus signatures, etc.<br>
You might also have a v-lan that has internet access only, so guests on your network that don't meet your criteria for health can still get to the net.<br>
<br>
<p>posted by adambomb</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633276739500000000</link>
		<pubDate>Thu, 11 Oct 2007 04:32:30 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633276739500000000</guid>
		<dc:creator>adambomb</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[It does not prevent you from acquiring an IP address - it provides an IP with a set of settings that prevents you from communicating with any machines on the network other than those specified via the access policy.&nbsp; These are termed as 'fixup servers'.<br>
<br>
Please see documents/whitepapers/other info at <a href="http://www.microsoft.com/nap">
http://www.microsoft.com/nap</a> for more information.<br>
<br>
-Chris<p>posted by cedson -MSFT-</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633277189740000000</link>
		<pubDate>Thu, 11 Oct 2007 17:02:54 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633277189740000000</guid>
		<dc:creator>cedson -MSFT-</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[No comment (oh wait) on Adam's hair (or lack thereof), since he had to mention mine!<br>
<br>
<br>
Jeff Sigman<br>
<br>
<br>
PS - Thanks to Adam for making this video happen! Let us know if you like it and we can continue a series all about NAP. Make sure to check out the
<a href="http://blogs.technet.com/nap">NAP blog</a>.<p>posted by NAPDude</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633277294590000000</link>
		<pubDate>Thu, 11 Oct 2007 19:57:39 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633277294590000000</guid>
		<dc:creator>NAPDude</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[Any key differences between this and any standard NAC appliance?<br>
<p>posted by mcampbell</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633277576970000000</link>
		<pubDate>Fri, 12 Oct 2007 03:48:17 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633277576970000000</guid>
		<dc:creator>mcampbell</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[Enterprise CA required or Standalone okay to test?<p>posted by CannedSoda</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633277603370000000</link>
		<pubDate>Fri, 12 Oct 2007 04:32:17 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633277603370000000</guid>
		<dc:creator>CannedSoda</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[
<p class="MsoNormal"><span>Hey Matt, good question.<br>
<br>
1.) <a href="http://blogs.technet.com/nap/archive/2007/06/21/nap-demystified-hopefully.aspx">
Integrated client </a>available in XP SP3 and Vista.<br>
2.) Able to enforce <a href="http://technet.microsoft.com/en-us/network/bb545879.aspx">
NAP</a> orthogonally to the logged-on user (since it is an NT service).<br>
3.) <a href="http://www.microsoft.com/windowsserver2008/nap-partners.mspx">3rd parties
</a>can build on top of client and server and extend the scope of what &quot;health&quot; means.<br>
4.) The <a href="http://blogs.technet.com/nap/archive/2007/05/21/network-access-protection-nap-announcement-with-the-trusted-computing-group-tcg.aspx">
TCG adopted our Statement of Health (SoH)</a> protocol as a standard - anyone can read the standard and interoperate.<br>
5.) Check out <a href="http://blogs.technet.com/nap/archive/2007/05/21/nap-longhorn-beta-3-webcast.aspx">
this demo </a>video I made to get a better idea of the experience.</span></p>
<p class="MsoNormal"><span>I hope you try it out for <a href="http://blogs.technet.com/nap/archive/2007/04/26/updated-nap-step-by-step-guides-for-longhorn-beta-3.aspx">
yourself</a>!</span></p>
<p class="MsoNormal"><span><br>
Jeff Sigman<br>
Senior Program Manager - NAP<br>
</span></p>
<p>posted by NAPDude</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278010740000000</link>
		<pubDate>Fri, 12 Oct 2007 15:51:14 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278010740000000</guid>
		<dc:creator>NAPDude</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[So, a networking guy hit by blaster because he didn't have his firewall on. Hmmm, fake story!<p>posted by ZippyV</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278342300000000</link>
		<pubDate>Sat, 13 Oct 2007 01:03:50 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278342300000000</guid>
		<dc:creator>ZippyV</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[
<blockquote>
<div class="quoteAuthor">NAPDude wrote:</div>
<div class="quoteBody">&#65279;
<p class="MsoNormal"><span>Hey Matt, good question.<br>
<br>
1.) <a href="http://blogs.technet.com/nap/archive/2007/06/21/nap-demystified-hopefully.aspx">
Integrated client </a>available in XP SP3 and Vista.<br>
2.) Able to enforce <a href="http://technet.microsoft.com/en-us/network/bb545879.aspx">
NAP</a> orthogonally to the logged-on user (since it is an NT service).<br>
3.) <a href="http://www.microsoft.com/windowsserver2008/nap-partners.mspx">3rd parties
</a>can build on top of client and server and extend the scope of what &quot;health&quot; means.<br>
4.) The <a href="http://blogs.technet.com/nap/archive/2007/05/21/network-access-protection-nap-announcement-with-the-trusted-computing-group-tcg.aspx">
TCG adopted our Statement of Health (SoH)</a> protocol as a standard - anyone can read the standard and interoperate.<br>
5.) Check out <a href="http://blogs.technet.com/nap/archive/2007/05/21/nap-longhorn-beta-3-webcast.aspx">
this demo </a>video I made to get a better idea of the experience.</span></p>
<p class="MsoNormal"><span>I hope you try it out for <a href="http://blogs.technet.com/nap/archive/2007/04/26/updated-nap-step-by-step-guides-for-longhorn-beta-3.aspx">
yourself</a>!</span></p>
<p class="MsoNormal"><span><br>
Jeff Sigman<br>
Senior Program Manager - NAP<br>
</span></p>
</div>
</blockquote>
<br>
<br>
The live meeting site says that the webcast has expired.<br>
<p>posted by mcampbell</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278938540000000</link>
		<pubDate>Sat, 13 Oct 2007 17:37:34 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278938540000000</guid>
		<dc:creator>mcampbell</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[Zippy, every word I uttered was true. Can't you see it on my face? My machine rebooting while I was coding was very troubling! :-&gt;<br>
<br>
Jeff Sigman<p>posted by NAPDude</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278983530000000</link>
		<pubDate>Sat, 13 Oct 2007 18:52:33 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278983530000000</guid>
		<dc:creator>NAPDude</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[Hey Matt - I am looking for another copy of the demo now. If I can't find it, I will make another one!<br>
<br>
Jeff Sigman<p>posted by NAPDude</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278985280000000</link>
		<pubDate>Sat, 13 Oct 2007 18:55:28 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278985280000000</guid>
		<dc:creator>NAPDude</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[
<p>CannedSoda, Enterprise CA or Standalone will work fine!<br>
<br>
Check out the <a href="http://blogs.technet.com/nap/archive/2007/04/26/updated-nap-step-by-step-guides-for-longhorn-beta-3.aspx">
step-by-step</a> for more information.<br>
<br>
Jeff Sigman<br>
</p>
<p>posted by NAPDude</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278986540000000</link>
		<pubDate>Sat, 13 Oct 2007 18:57:34 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633278986540000000</guid>
		<dc:creator>NAPDude</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[
<p class="MsoNormal"><span>Turns out my full 802.1x NAP Live Meeting demo (Server Beta 3)&nbsp;is gone and I can't locate another copy of it. I will create a brand spanking new one and post it on the
<a href="http://blogs.technet.com/nap">NAP blog</a>. I have some ideas how to make it better anyway, like showing you how I set up the HP Procurve 802.1x Switch to work with NAP (it is a snap).<br>
<br>
Please let me know if there is anything you specifically want to see, and I will consider demoing it. Otherwise just come see me at TechEd / IT Forum Europe and introduce yourself!<br>
<br>
Jeff Sigman</span></p>
<p>posted by NAPDude</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633281389150000000</link>
		<pubDate>Tue, 16 Oct 2007 13:41:55 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633281389150000000</guid>
		<dc:creator>NAPDude</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[Another thing: I heard you saying that NAP is new to Windows Server 2008 but I was under the impression that this feature already existed in Server 2003 SP1. The feature had Quarantine in the name I think.<p>posted by ZippyV</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633282529950000000</link>
		<pubDate>Wed, 17 Oct 2007 21:23:15 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633282529950000000</guid>
		<dc:creator>ZippyV</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[ZippyV,<br>
You're right, Server 2003 included a feature called Quarantine Services, you can read more about it
<a href="http://www.microsoft.com/technet/security/prodtech/windowsserver2003/quarantineservices/default.mspx">
here</a>.&nbsp; Brent talks about it a bit in the video when he talks about Microsoft's Remote Access implementation.&nbsp; Quarantine services work only on VPN connections, and rely on custom scripts to do all the inspection on the client.&nbsp; NAP can be used on VPN, IPSEC,
 802.1x, or DHCP, and uses client issued health statements for the inspection.&nbsp; It covers more scenarios and is a faster inspection process.<br>
<p>posted by adambomb</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633282582390000000</link>
		<pubDate>Wed, 17 Oct 2007 22:50:39 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633282582390000000</guid>
		<dc:creator>adambomb</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[Hi,<br>
<br>
Just wondering is NAP compatible with all managable switches, i use a wide range and ages of intelligent switches, vlans are not currently setup however with the introduction of NAP it is an ideal oppertunity to do so.<br>
<br>
Regards James!<p>posted by jamesscammell</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633404077930000000</link>
		<pubDate>Thu, 06 Mar 2008 13:43:13 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c633404077930000000</guid>
		<dc:creator>jamesscammell</dc:creator>
	</item>
	<item>
		<title>Re: Network Access Protection with MSIT</title>
		<description>
			<![CDATA[iam coplane,no have chanel please sign in<p>posted by raf hernandez</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c634272171610000000</link>
		<pubDate>Mon, 06 Dec 2010 07:26:01 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/adambomb/Network-Access-Protection-with-MSIT#c634272171610000000</guid>
		<dc:creator>raf hernandez</dc:creator>
	</item>
</channel>
</rss>