ã¹ã©ã¤ãæ¦è¦ Active Directory åå¼·ä¼ #1 (2024-04-12) ã®ç»å£è³æã§ãã Active Directory Domain Services (AD DS, ãã¡ã¤ã³ã³ã³ããã¼ã©ã¼) ã®æ§ç¯æã«ç¹ã«æ°ãä»ããã¹ã3ç¹ã«ã¤ãã¦èª¬æãã¦ãã¾ãã
ã¹ã©ã¤ãæ¦è¦ Active Directory åå¼·ä¼ #1 (2024-04-12) ã®ç»å£è³æã§ãã Active Directory Domain Services (AD DS, ãã¡ã¤ã³ã³ã³ããã¼ã©ã¼) ã®æ§ç¯æã«ç¹ã«æ°ãä»ããã¹ã3ç¹ã«ã¤ãã¦èª¬æãã¦ãã¾ãã
ã¨ã³ã¿ã¼ãã©ã¤ãºèªè¨¼ã·ã¹ãã ã¨ãã¦ããªãã¿ã® Active Directory Domain Serviceï¼AD DSï¼ã§ãããåç»å ´ãã20年以ä¸ãçµã¦ãã¾ããä»ã§ã¯Microsoft Entra IDï¼Azure ADï¼ã®å©ç¨ãæ¨å¥¨ããã¦ãã¾ããããªã³ãã¬ãã¹ç°å¢ã§ã¯ãå¼ãç¶ãæ°è¦ç°å¢ã®æ§ç¯ãOSãµãã¼ãæéã«ããæ´æ°ãªã©ããã¾ãã°ããã¯æ´»èºãã¤ã¥ãããã¨ã§ãããã AD DSã«ã¤ãã¦ã®ããã¥ã¡ã³ãã¯Microsoftã§å種åãæãã¦ãã¾ãããçºå£²å½åå ¬éããã¦ãã詳細ãªä»æ§ãå¶éäºé ã«ã¤ãã¦ã®æ å ±ã¯ãå¤ãæ å ±ã¨ãã¦å¤ããåé¤ããã確èªãé£ããã§ãããããªç¶æ³ãéã¿ãã®ããMicrosoftã®æ¥æ¬ãµãã¼ããã¼ã ããç´ æ´ãããããã¥ã¡ã³ãå ¬éãã¦ãã¾ãã ãã¡ã¤ã³ ã³ã³ããã¼ã©ã¼ã®æ§ç¯æã«è¨ãããªãã¨æ°ä»ããªãã㨠| Microsoft Japan Windows Technolog
Applies to: Windows Server 2022, Windows Server 2019, Windows Server 2016, Windows Server 2012 R2, Windows Server 2012 Attacks against computing infrastructure have increased over the last decade in all parts of the world. We live in an age of cyber-warfare, cybercrime, and hacktivism. As a result, organizations of all sizes all over the world have had to deal with information leaks, theft of inte
ADã«ã¯ã¦ã¼ã¶ã¼ãã°ã«ã¼ããOUãªã©ãæ§ã ãªãªãã¸ã§ã¯ããããã¾ãã ADãå°å ¥ããéããããã®ãªãã¸ã§ã¯ããå¤æ°ä½æããå¿ è¦ãããã¾ããã1ã¤ãã¤GUIã§ä½æããã®ã¯é¢åã§ãã ãããªæ㯠PowerShell ã使ããã¨ã§å¹çããä½æãããã¨ãåºæ¥ã¾ãã PowerShell ã使ããã¨ãAD éç¨ã®å¹çåã«ãå½¹ç«ã¤ã®ã§è¦ãã¦ããã¦æã¯ãªãã§ãã å¤æ´ãåé¤ã¯ä½ææé ãç解ããã°æ¯è¼çç°¡åã«ä½æãããã¨ãåºæ¥ã¾ãã ä»åã¯ä¸è¨ã®ãªãã¸ã§ã¯ãä½æã¨ç¢ºèªã®æ¹æ³ãç´¹ä»ãã¾ãã OU ã¦ã¼ã¶ã¼ ã°ã«ã¼ã ã°ã«ã¼ãã¡ã³ãã¼ ãµãããã 1.OUä½æ OU ã¨ã¯ãOrganization Unit (çµç¹åä½)ãã¨å¼ã°ãããã®ã§ãOUãé層åãããã¨ã§ã¦ã¼ã¶ã¼ãã³ã³ãã¥ã¼ã¿ã¼ãªã©ã® ADãªãã¸ã§ã¯ããå¹çãã管çåºæ¥ã¾ãã ã³ã³ããã¨ã®éãã«ã¤ãã¦ã¯ãã¡ãã ADã®OUã¨ã³ã³ããã®éãã«ã¤ã㦠ã¾
Active Directory Assessment ã§ã¯ããªã³ãã¬ãã¹ãAzure VMãã¾ã㯠Amazon Web Services (AWS) VM ã§å®è¡ããã¦ãããã¡ã¤ã³ ã³ã³ããã¼ã©ã¼ã使ç¨ã㦠Active Directory ç°å¢ã®è©ä¾¡ãåå¾ã§ãã¾ãã Active Directory ã¤ã³ãã©ã¹ãã©ã¯ãã£ã¨ãã¢ããªã±ã¼ã·ã§ã³ãã½ããã¦ã§ã¢æ´æ°ããã°ã©ã ããªãã¬ã¼ãã£ã³ã° ã·ã¹ãã ãå±éãããªã©ã®æ©è½ã®ããã©ã¼ãã³ã¹ãåä¸ãããããã«ãåæã«ãã£ã¦ã修復ã«é¢ããã¬ã¤ãã³ã¹ã¨ãã¹ã ãã©ã¹ãã£ã¹ã§å¯¾å¦ããåé¡ã®ä¸è¦§ãçæããã¾ãã è©ä¾¡ã¯ãµã¼ãã¹ ãããéãã¦å©ç¨ã§ãã¾ããããã«ãããMicrosoft ãã¯ããã¸ã¼ã®å¯ç¨æ§ãã»ãã¥ãªãã£ãããã©ã¼ãã³ã¹ãæé©åã§ãã¾ãã ãããã®è©ä¾¡ã¯ãMicrosoft Azure Log Analytics ã使ç¨ãã¾ããAzure
Windows Server 2016ã«ãããªã³ãã¬ãã¹ã¨ã¯ã©ã¦ããµã¼ãã¹éã§ã®SSOç°å¢ã®æ§æï¼AD FSã使ã£ãSaaSã¨ã®SSOç°å¢æ§ç¯ï¼2ï¼ï¼1/3 ãã¼ã¸ï¼ æ¥åã§æ´»ç¨ãå¢ãã¦ãããSaaSãããã®ã¾ã¾ä½¿ãã®ã§ã¯ãªããID管çã·ã¹ãã ã¨é£æºãããã¨ã§ãã¦ã¼ã¶ã¼ã®å©ä¾¿æ§ã¯ä¸ãããã·ã¹ãã 管çè ã¯éç¨ç®¡çã容æã«ãªããæ¬é£è¼ã§ã¯ãAD FSã使ã£ãSaaSã¨ã®ã·ã³ã°ã«ãµã¤ã³ãªã³ç°å¢ã®æ§ç¯æ¹æ³ã説æããã Windows Server 2016ã®AD FSã使ã£ãSaaSã¨ã®SSOç°å¢æ§ç¯ ã¡ã¼ã«ãã¹ã±ã¸ã¥ã¼ã«ãããã¥ã¡ã³ã管çãªã©ããã¾ãã¾ãªã·ã¹ãã ãSaaSï¼Software as a Serviceï¼ã«ãªããå¤ãã®ä¼æ¥ãæ¥å¸¸çã«å©ç¨ãã¦ãã¾ãããã®ãããªSaaSãå©ç¨ããå ´åããã°ã¤ã³ã®ã¢ã«ã¦ã³ãã¨ãã¹ã¯ã¼ããæ¢åã·ã¹ãã ã¨ã¯ç°ãªã£ã¦ããã¨ãã¦ã¼ã¶ã¼ã®å©ä¾¿æ§ãä¸ãããæ å ±ã·ã¹ãã
å®è·µãAD FS 2016ãã使ã£ã¦ãOffice 365ãã¨ã®SSOè©ä¾¡ç°å¢æ§ç¯ï¼Azureç°å¢ã¨AD DSã®æ§ç¯ç·¨ï¼AD FSã使ã£ãSaaSã¨ã®SSOç°å¢æ§ç¯ï¼3ï¼ï¼1/6 ãã¼ã¸ï¼ Windows Server 2016ã®AD FSã使ã£ã¦ãSaaSã¨ã®SSOç°å¢æ§ç¯æ¹æ³ãç´¹ä»ããæ¬é£è¼ãä»åã¯ãAD FS 2016ã«ããOffice 365ã¨ã®SSOè©ä¾¡ç°å¢ã®æ§ç¯æ¹æ³ã¨ãã¦ãAzureç°å¢ãAzure Active Directoryãã¡ã¤ã³ãµã¼ãã¹ï¼AD DSï¼ã®æ§ç¯æ¹æ³ãç´¹ä»ãã¾ãã Windows Server 2016ã®AD FSã使ã£ãSaaSã¨ã®SSOç°å¢æ§ç¯ ã¡ã¼ã«ãã¹ã±ã¸ã¥ã¼ã«ãããã¥ã¡ã³ã管çãªã©ããã¾ãã¾ãªã·ã¹ãã ãSaaSï¼Software as a Serviceï¼ã«ãªããå¤ãã®ä¼æ¥ãæ¥å¸¸çã«å©ç¨ãã¦ãã¾ãããã®ãããªSaaSãå©ç¨ããå ´åããã°ã¤ã³ã®ã¢ã«
ãªã³ãã¬ãã¹ç°å¢ä¸ã® Active Directory ã¢ã«ã¦ã³ãã¨åãã¢ã«ã¦ã³ãã使ç¨ãã¦ããããªã㯠ã¯ã©ã¦ã (SaaS, PaaS) ã«ã¢ã¯ã»ã¹ (ã·ã³ã°ã«ãµã¤ã³ãªã³ : SSO å«ã) ããããã¨æããã¨ããããã¨æãã¾ãã ä»åã¯ãAzure AD Connect ã使ç¨ãããªã³ãã¬ãã¹ Active Directory 㨠Azure Active Directory éã§ã¢ã«ã¦ã³ãã®åæãããæ¹æ³ã«ã¤ãã¦ãèªåã®æ´çãå ¼ãã¦ãã¾ã¨ãã¦ã¿ããã¨æãã¾ãã Azure AD Connect v2.0 ã«ã¤ãã¦ã¯ã以ä¸ã® URL ãåç §ã Azure AD Connect è¨å®æé äºåæºå è¨å® Azure AD Connect åæç¶æ ç¢ºèª ã¾ã¨ã Azure AD Connect è¨å®æé äºåæºå â» ç¹ã«ããããã·çµç±ã§ã¤ã³ã¿ã¼ãããã«æ¥ç¶ããå ´åããC:\Window
Azure AD Connect (AADC)ã使ããActive Directory ãã¡ã¤ã³ ãµã¼ãã¹ (ADDS) 㨠Azure Active Directory éã§ã¦ã¼ã¶ã¼æ å ±ãåæããèªè¨¼åºç¤ãçµ±åãã¦ã¿ã¾ãããï¼ï¼ å ããAzure AD Connect ç¨ã®ãµã¼ãã¼(ãã¡ã¤ã³åå æ¸ã¿)ãç¨æããAzure AD Connect ããã¦ã³ãã¼ããã¾ããâ»ãªã³ã¯ãåãã¦ããå ´åã¯æ¤ç´¢ãã¦ã¿ã¦ä¸ããã ãã¦ã³ãã¼ããããAzureADConnect.msiããå®è¡ ãç°¡åè¨å®ã使ãããé¸æãâ»èªåã§ããã¹ã¯ã¼ãåæããæ§æããã¾ãã ãã«ã¹ã¿ãã¤ãºããé¸æããã¨ãä¸è¨ã®ãããªå¤æ´ãå¯è½ Azure AD ã«æ¥ç¶ããããã® [å ¨ä½ç®¡çè ]権éãæã¤ã¦ã¼ã¶ã¼æ å ±ãå ¥å Active Directoryãã¡ã¤ã³ãµã¼ãã¹ã«æ¥ç¶ããããã® [Enterprise Admins]権éãæã¤
Azure AD Connect Cloud Sync ã¨ã¯ï¼ 2021/10/10 2021/10/11 Microsoft Entra Active Directoryã«ç»é²ãã¦ããã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ããAzureADã«åæããããã¿ãæä¾ãã¾ããããã«ãããActive Directoryå´ã§ã¦ã¼ã¶ã¼ç®¡çãè¡ãäºã§ãAzureADã«ãèªåã§åæ (åæ)ããããããäºé管çã解æ¶ããã¾ãã Cloud Syncã¯ãAzureãã¼ã¿ã«ç»é¢ã§ç®¡çãè¡ãããããã¡ã¤ã³ãè¤æ°ããç°å¢ã®å ´åã 管çãããããã§ãã æ§ç¯ã¯ã¨ã¦ãç°¡åã§ãWindows Serverã«âCloud Sync Agentâãã¤ã³ã¹ãã¼ã«ããã ãã§ãã ãæ§æãã¿ã¼ã³ã ï¼ãã©ã¬ã¹ããï¼ãã¡ã¤ã³ãåæãããã¿ã¼ã³ ï¼ãã©ã¬ã¹ããï¼ãã¡ã¤ã³ãåæãããã¿ã¼ã³ â»AAD Connectã¨æ··å¨ããäºãå¯è½ ï¼ãã©ã¬ã¹ããï¼ã
ããããID管çã«ã¤ãã¦å¦ç¿ãããã®å 容ãã¾ã¨ãã¦ããã¾ããä»åã¯AADCã¨ã¯ä½ããã©ã®ãããªä»çµã¿ã§åãã¦ããã®ãã«ã¤ãã¦ç´¹ä»ãã¾ãã AADCã¨ã¯ AADCã¨ã¯ä½ããç解ããããã«ã¯ãã¾ãADã¨AADã«ã¤ãã¦ç解ããå¿ è¦ãããã¾ãããã®ãããADãAADãAADCã®é ã«èª¬æãã¦ããã¾ãã Active Directory(AD) Active Directory(AD)ã¯ãªã³ãã¬ãã¹ã®ID管çãã©ãããã©ã¼ã ã§ããWindows Serverä¸ã§åä½ããã½ããã¦ã§ã¢ã§ãçµç¹å ã®ã¦ã¼ã¶ã®IDæ å ±ã管çãããã¨ãã§ãã¾ããADã«ãã£ã¦ç¤¾å¡ãå¦çã®ã¦ã¼ã¶ã¢ã«ã¦ã³ããã¾ã¨ãã¦ç®¡çãããã¨ã容æã«ã§ããããã«ãªãã¾ããIDæ å ±ã¯ãã£ã¬ã¯ããªã¨å¼ã°ããé層æ§é ã§æ§æããã¾ããä¼æ¥ã®é¨ç½²ãå¦æ ¡ã®å¦é¨ã®ããã«ãã©ã«ãåãããã¦ãããããªã¤ã¡ã¼ã¸ã§ãã Azure Active Directory(AA
ãµã¼ãã©ãã¯ã«æããããã±ã¼ãã«ã«ç¾ãè¦ããNHK BS1ã®çªçµãã±ã¼ãã«ã¢ã¼ãï½ããªãã®ç¥ããªãç¾ã®ä¸çï½ããä»å¤10æ40åããæ¾é㸠ãµã¼ãã©ãã¯ã®è¡¨ãè£ãæµããããã«é ç·ããã¦ãã大éã®ã±ã¼ãã«ããã¨ãã¨ãã¦åå¼·ããç¹ç´°ãããããã¯çå½åã®ãããªç¾ãããæãããããã¨ãããã¾ãããï¼ ãããããµã¼ãã«ã¤ãªãããå¤æ°ã®ã±ã¼ãã«ã«ç¾ãè¦ãã ãçªçµãã±ã¼ãã«ã¢ã¼ãï½ããªãã®ç¥ããªãç¾ã®ä¸çï½ããä»å¤ã11æ11æ¥å¤10æ40åããNHK BS1ã§æ¾éäºå®ã§ãã ä¸è¨ã¯TVerã§ã®çªçµç´¹ä»ã®ä¸æã ãã½ã³ã³ããµã¼ãã¼ãã¤ãªãè¨å¤§ãªã±ã¼ãã«ãã«ã©ãã«ã§æ´ç¶ã¨é ç·ãããã±ã¼ãã«ã«ç¬ç¹ã®ç¾ãè¦åºã人ã!é»ç·æ好家ã®å¥³åªã»ç³å±±è®è¯ãããã±ã¼ãã«ã¢ã¼ãã®ä¸çãæ¢è¨ª! æ¡å å½¹ã®ç³å±±è®è¯ããã次ã®ããã«ãã¤ã¼ããã¦ãã¾ããè¦åæ£ããæããããã±ã¼ãã«ãç¾ããã§ããã ãã¬ãã§ã±ã¼ãã«ãè¦ãã 11æ11
é¢é£ãã¼ã¯ã¼ã Microsoft Azure | Office 365 | Active Directory åç·¨ããActive Directoryãï¼ADï¼ã¨ãAzure ADãã®éããã¯ã©ã¦ãçã ãã®æ©è½ã¨ã¯ãã«ç¶ããMicrosoftã®IDã»ã¢ã¯ã»ã¹ç®¡çã·ã¹ãã ã§ãããActive Directoryãï¼ADï¼ã¨ãADã®ã¯ã©ã¦ããµã¼ãã¹çã§ãããAzure Active Directoryãï¼Azure ADï¼ã®éããç´¹ä»ãããä»åã¯ç¹ã«ãAzure ADã®ã¡ãªãããéç«ã¤3ã¤ã®ãã¤ã³ããç´¹ä»ãããã ãã¤ã³ã1ï¼ã·ã³ã°ã«ãµã¤ã³ãªã³ï¼SSOï¼ã®å®è£ ä½µãã¦èªã¿ãããè¦ãè¨äº ãMicrosoft 365ãã®ã»ãã¥ãªãã£å¯¾ç ãMicrosoft 365ãã§å¤è¦ç´ èªè¨¼ï¼MFAï¼ãå©ç¨ããMicrosoftæ¨å¥¨ã®æ¹æ³ã¨ã¯ï¼ ãMicrosoft 365ãã®ãã¹ã¯ã¼ãåæã«æ½ãâæå¤ãª
FreeIPA - Identity, Policy, Audit# Identity# Manage Linux users and client hosts in your realm from one central location with CLI, Web UI or RPC access. Enable Single Sign On authentication for all your systems, services and applications. Policy# Define Kerberos authentication and authorization policies for your identities. Control services like DNS, SUDO, SELinux or autofs. Trusts# Create mutual
ADé¢é£ã®ä½æ¥ããã¦ããéã«ã ç¹å®ã®ã¯ã©ã¤ã¢ã³ããã©ã®ADãµã¼ãã¼ã§èªè¨¼ããã¦ãããã 確èªãããæ©ä¼ãå¤ãã§ãã æ®æ®µã¯ãecho %logonserver%ãã³ãã³ãã§ç¢ºèªãã¦ããã®ã§ããã æè¿ã®Windowsã§ã¯é«éãã°ãªã³æ©è½ãªã©ã®å½±é¿ã§ååãã°ãªã³ããADãµã¼ãã¼ã è¿ããããã¨ãããããã§ãã ä¸å¿ã以ä¸ã®ã³ãã³ãã§ç¢ºèªãã§ãããã§ãã nltest /dsgetdc:ãã¡ã¤ã³å ãããªåºåãè¿ã£ã¦ãã¾ãã 1è¡ç®ã®ãDCãæ¬ãèªè¨¼ããã¦ããADãµã¼ãã¼ã§ããã DC: \\testadserver.example.local ã¢ãã¬ã¹: \\10.1.1.100 ãã¡ã¤ã³ GUID: d674291a-6b42-4b03-aac0-59d84fe9adba ãã¡ã¤ã³å: example.local ãã©ã¬ã¹ãå: example.local DC ãµã¤ãå: Main æ¬
Microsoft Entra Connect ã¯ããã¤ããªãã ID ã®ç®æ¨ãæºããã¦å®ç¾ããããã«è¨è¨ããããªã³ãã¬ãã¹ã® Microsoft ã¢ããªã±ã¼ã·ã§ã³ã§ãã ç®æ¨ãæºããæé©ãªæ¹æ³ãè©ä¾¡ãã¦ããå ´åã¯ãã¯ã©ã¦ãããã¼ã¸ã ã½ãªã¥ã¼ã·ã§ã³ã§ãã Microsoft Entra ã¯ã©ã¦ãåæã«ã¤ãã¦ãæ¤è¨ãã¦ãã ããã éè¦ Azure AD Connect V1 㯠2022 å¹´ 8 æ 31 æ¥ã«å»æ¢ããããµãã¼ããããªããªãã¾ããã Azure AD Connect V1 ã®ã¤ã³ã¹ãã¼ã«ã¯ãäºæããåä½ããªããªãå¯è½æ§ãããã¾ãã Azure AD Connect V1 ãã¾ã 使ã£ã¦ããå ´åã¯ãç´ã¡ã« Microsoft Entra Connect V2 ã«ã¢ããã°ã¬ã¼ãããå¿ è¦ãããã¾ãã Microsoft Entra Connect V2.0 ã移åããåã«ãã¯ã©ã¦ã
ãããã§ããããããªããï¼ãããããã¾ã æ©ãããããªããï¼ãã¨ãã¤ãè«äºã«ãªã(ï¼)å®å ¨ãã«ã¯ã©ã¦ãç°å¢ããããªã³ãã¬ãã¹ã®Active Directoryããã¡ã¤ã«ãµã¼ãã¼ãããªã³ã¿ãµã¼ãã¼ãå ¨é¨æ¨ã¦ã¦ããã«ã¯ã©ã¦ãç°å¢ã§åé¡ãªãããããªããï¼ãã®ããã«èãã¦ããæ¹ãå¤ãã¨æãã¾ãã ã¨ã¯ãããç¹ã«ã¨ã³ã¿ã¼ãã©ã¤ãºç°å¢ã§ã¯ããããã¾ã ç¡çã ãããã¨ãã声ã大ããã§ãããå®éã®ã¨ãããªã³ãã¬ãã¹ã«ããè¨å¤§ãªè³ç£ãã©ã®ããã«ç§»è¡ãã¦ããã®ãâ¦ã¨ãããã¨ã§ç¾å®çã«èããããªãçµç¹ãå¤ãã¨æãã¾ãã ã§ããï¼ è¦æ¨¡ãå°ããã¨ããã§æ¢åè³ç£ã対ãã¦ãªããããããç°å¢ãæ´ãããã¨ããç¶æ³ã§ããã°Microsoft 365ãã¤ãã£ã¦ãã«ã¯ã©ã¦ãã§ç°å¢ãæ´ããã®ã¯é常ã«ç¾å®çã§æåãªåè£ã ã¨æãã¾ããã¨ãããç§ãITç°å¢ãå ¨é¨ã³ã³ããã¼ã«ã§ãããªã絶対ã«ãããã¾ãã ã¨ãããã¨ã§ããã«ã¯ã©ã¦ãã®æ¤è¨¼ç°å¢
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}