ãã®èšäºã¯ãçµéšè±å¯ãªç®¡çè ããšã³ãžãã¢ã«ãšã£ãŠæçšã§ã¯ãªãå¯èœæ§ããããŸã
ãªã¹ã¯
ãŒããäžæ¹åã®åæãäžåžãæ°ã«å ¥ããªãã£ãå Žåãäœãæ©èœããªãããéãå²ãåœãŠãªãããã¹ãŠãå£ãã-DirSyncãšAD FSãåæ¢ããDirSyncãåé€ããAD DSã®MSOL_AD_Syncã¢ã«ãŠã³ããåé€ããOffice 365ããåæã¢ã«ãŠã³ããåé€è»¢éãã»ããã¢ããããŸããæå°ã€ã³ãã©èŠä»¶
AD FSãµãŒããŒãWindows Server 2008以éããã¡ã€ã³ã¡ã³ããŒãéãã¡ã€ã³ã³ã³ãããŒã©ãŒDirSync'AçšãµãŒããŒïŒAD DSãšOffice 365ãåæããããã®MicrosoftãŠãŒãã£ãªãã£ïŒãWindows Server 2003以éããã¡ã€ã³ã¡ã³ããŒãéãã¡ã€ã³ã³ã³ãããŒã©ãŒãNET Framework 3.0ãŸãã¯3.5ããã³Powershell
åããã©ã¬ã¹ãããã®AD DS 2003æ··å\ãã€ãã£ãã¢ãŒã以äžã ãã¡ã€ã³å ã®ãšã³ã¿ãŒãã©ã€ãºç®¡çè ã¢ã«ãŠã³ãã MSOL_AD_Syncã®äœæã«ã®ã¿äœ¿çšããããã°ã€ã³\ãã¹ã¯ãŒãã¯DirSync'eã®ã©ãã«ãä¿åãããŸããã ã¢ã«ãŠã³ãã«ã¯ãAD DSã®å€æŽãèªã¿åããåæããæš©å©ãä»äžãããŸãã
Office 365ã®ç®¡çè ã¢ã«ãŠã³ããOffice 365ã§ãã¡ã€ã³ã確èªããŸãã ã ãã¡ã€ã³åã¯æ€èšŒæžã¿ã®ãã¡ã€ã³ãšäžèŽããªãå ŽåããããŸãããã®å Žåããã¡ã€ã³ã®UPNãµãã£ãã¯ã¹ãè¿œå ãããŠãŒã¶ãŒããã®ãµãã£ãã¯ã¹ã«ãã€ã³ãããã ãã§ãã
AD FSãçºè¡ããããã®èšŒææžïŒèªå·±çœ²åããããã®ã§ãããã¹ãã«äœ¿çšã§ããŸãïŒ
泚 ïŒDirSyncã¯ããŒã80ããã³443ã§åäœãããããã·ãµãŒããŒãžã®ãã°ã€ã³æ¹æ³ãç¥ããŸããããããã·ãµãŒããŒã«å¥ã®ãç©Žããéããå¿ èŠãããããã§ãã 50,000人ãè¶ ãããŠãŒã¶ãŒãåæããã«ã¯ãæ¬æ ŒçãªSQLãµãŒããŒãã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã
Office 365
æåã«AD DSãšã®åæãã¢ã¯ãã£ãã«ããå¿ èŠããããŸãããã®ã¹ãããã¯ãåæããªã³ã«ããã®ã«æ倧24æéïŒå®éã«ã¯ãããããçãïŒããããŸãã1.ãŠãŒã¶ãŒã»ã¯ã·ã§ã³ã®Office 365ããŒã¿ã«ã«ç§»åããŸãã
2.ãActive Directory Synchronizationããæ€çŽ¢ãããã»ããã¢ããããã¿ã³ãæŒããŸã
3.衚瀺ããããŠã£ã³ããŠã®é ç®çªå·3ã§ã[ã¢ã¯ãã£ãå]ãã¯ãªãã¯ããŠåæããªã³ã«ããŸã
4.ãã©ã°ã©ã4ã§ãDirSyncãããŠã³ããŒãããŸãã
AD FS
AD FSãã€ã³ã¹ããŒã«ããåã«ãIISã«AD FSãå ¬éããããã«äœ¿çšããããã¡ã€ã³ãŸãã¯èªå·±çœ²å蚌ææžãã€ã³ããŒããŸãã¯çæããå¿ èŠããããŸããAD FS 2.0ãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããŸããADFSãµãŒããŒãããã·ã§ã¯ãªããAD FSãµãŒããŒãå¿ èŠã§ãã AD FS 2.0ãã€ã³ã¹ããŒã«ããåŸãIISã«ç§»åããAD FSãµã€ããããŒã443ãšèšŒææžã«ãã€ã³ãããŸãã
泚 ïŒããŒã80ãžã®ãã€ã³ããåé€ãããµã€ãèšå®ã§ãSSLãå¿ èŠããæå¹ã«ããããšããå§ãããŸãã ãããã¯ãã¹ãŠãIIS管çã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠçŽæçã«è¡ãããŸãã
次ã«ãAD FS 2.0管çã³ã³ãœãŒã«ã«ç§»åããAD FS 2.0ãµãŒããŒæ§æãŠã£ã¶ãŒããŸãã¯CïŒ\ Program Files \ Active Directory Federation Services 2.0 \ FsConfigWizard.exeãèµ·åããŸãã å®éãããã«ãããã«ãããã«... ãã¡ãŒã ãã€ã³ã¹ããŒã«ããå¿ èŠããããŸããADFSã®ãµãŒãã¹ã¢ã«ãŠã³ããæãŸããã§ãããã®æäœã«å¿ èŠãªæå°éã®è¿œå ã¢ã¯ã»ã¹èš±å¯ã¯ãOUãããã°ã©ã ããŒã¿ãã«å¯Ÿãããæžã蟌ã¿ãæš©éã§ãã
ãªã³ã¯_httpsïŒ//adfs_server_name/adfs/ls/idpinitiatedsignon.aspxãã¯ãªãã¯ããŠç¢ºèªã§ããŸãã
DirSyncãã€ã³ã¹ããŒã«ãã
ãã®ããã»ã¹ã¯éåžžã«ã·ã³ãã«ã§ãããã«å®å šãªãã®ã§ãã ã€ã³ã¹ããŒã«åŸãæ§æãŠã£ã¶ãŒããéããŸãã ç¹°ãè¿ããŸããã2ã€ç®ã®ãã€ã³ãã§Office 365管çè ã¢ã«ãŠã³ããæå®ããå¿ èŠãããïŒãã®æç¹ã§AD DSãšã®åæãæââå¹ã«ããå¿ èŠããããŸãïŒã3ã€ç®ã®æ®µèœã§ç®¡çè ã®ç®¡çè ã¢ã«ãŠã³ããæå®ããŸãã 4çªç®ã®æ®µèœã§ã¯ããRich Coexistanceããå«ããããæ±ããããŸããããã®èšäºã®ãã¬ãŒã ã¯ãŒã¯ã§ã¯èæ ®ããŸããã ã€ã³ã¹ããŒã«åŸããä»ãããã£ã¬ã¯ããªãåæãããã®ãã§ãã¯ãå€ãããšãã§ããŸããããã«ãããçŸåšåæããªãããã«ã§ããŸãããåæã¯3æéããšã«ã¹ã±ãžã¥ãŒã«ã«åŸã£ãŠã¹ã±ãžã¥ãŒã«ãããŸããä»ãå°ããéæ³ã
CïŒ\ Program Files \ Microsoft Online Directory Sync \ SYNCBUS \ Synchronization Service \ UIShell \ miisclient.exeã¯ãDirSyncã®é ãGUIã§ãïŒå®éã«ã¯ãéåžžã®Fim Synchronization Serviceã§ãïŒã ååãªç¥èãããã°ãèšå®ããè©ŠããŠã¿ããããšãã§ããŸãããGUIãä»ããèšå®ã®å€æŽã¯ãã€ã¯ããœããã«ãã£ãŠãµããŒããããŠããŸãããäœãå€æŽãå¿ èŠãªå Žåããã€ã¯ããœããã¯ãæ§æãŠã£ã¶ãŒãããå床å®è¡ããŸãã DirSync GUIãžã®ã¢ã¯ã»ã¹ãèš±å¯ãããŠããªãå Žåã¯ããã°ã€ã³ããã ãã§ã¢ã«ãŠã³ãã¯Fim Synch Serviceã°ã«ãŒãã«è¿œå ãããŠããŸãã
匷å¶åæã¯ãDirSync GUIãŸãã¯PowerShellãä»ããŠå®è¡ã§ããŸãã
1. Povershellãèµ·åããŸã
2.cd CïŒ\ Program Files \ Microsoft Online Directory Sync
3 .. \ DirSyncConfigShell.psc1
4.æ°ããStart-OnlineCoexistenceSyncãŠã£ã³ããŠã§
çµæã¯ãã€ãã³ããã°ãŸãã¯Office 365ããŒã¿ã«ã§è¡šç€ºã§ããŸãã
ãã¹ãå®è¡ã®å ŽåãåæããOUãéžæã§ããŸãã ãããè¡ãã«ã¯ãGUIã«ç§»åããSourceAD管çãšãŒãžã§ã³ããããã«ã¯ãªãã¯ãã[Active Directoryãã©ã¬ã¹ãã«æ¥ç¶]ã»ã¯ã·ã§ã³ã§[ã³ã³ãããŒ]ãã¯ãªãã¯ããŠãå¿ èŠãªã³ã³ãããŒãéžæããŸãã è€æ°ã®ãã¡ã€ã³ãããå Žåã¯ããªã¹ãããç®çã®ãã¡ã€ã³ãéžæãããã³ã³ããããã¯ãªãã¯ããŸãã åãã¡ã€ã³ã§ç¹°ãè¿ããŸãã
泚 ïŒãããè¡ããªããšããã¹ãŠã®OUã®ãã¹ãŠã®ã¢ã«ãŠã³ããOffice 365ãããé¢ãããŸãã ãµãŒãã¹ã¢ã«ãŠã³ããšãã«ãã€ã³ã¢ã«ãŠã³ããå«ã¿ãŸãã
AD FS 2.0ãã³ãã«-Office 365
AD FSãµãŒããŒã§Office 365ãæäœããããã«ããµã€ã³ã€ã³ã¢ã·ã¹ã¿ã³ããšPowerShellã¢ãžã¥ãŒã«ãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããŸãã æ°ããã·ã§ãŒãã«ããã[ã¹ã¿ãŒã]ã¡ãã¥ãŒãšãã¹ã¯ãããã«è¡šç€ºãããŸããããã¯ãOffice 365ãæäœããããã®powershellã§ãïŒæåã«import-module MSOnlineãå®è¡ãããšããéåžžã®ãpowershellã䜿çšã§ããŸãïŒããã¡ã€ã³ãçµ±åããŸãã
1. $ cred = Get-Credential-衚瀺ããããŠã£ã³ããŠã§ãOffice 365管çã¢ã«ãŠã³ãã®ãŠãŒã¶ãŒå/ãã¹ã¯ãŒããå ¥åããŸãã
2. Connect-MsolService âCredential $ cred-Office 365ã«æ¥ç¶ããŸãã
3. Set-MsolADFSContext âã³ã³ãã¥ãŒã¿ãŒ<AD FS 2.0ãµãŒããŒå>-ãªãã·ã§ã³ã®æé ãADFSãµãŒããŒãã€ã³ã¹ããŒã«ãããŠããã³ã³ãã¥ãŒã¿ãŒããã§ã¯ãªãpowershellãå®è¡ããå Žåã«ã®ã¿å¿ èŠã§ãã
4. Convert-MSOLDomainToFederated-domainname <domain.com>-ãrootããã¡ã€ã³ã®ååãæå®ããŸããoffice365.domain.comãå€æããå¿ èŠãããå Žåãoffice365.domain.comããã³domain.comãã¡ã€ã³ã確èªããå¿ èŠããããŸãã ãã ãããã¡ã€ã³ãå€æãããšãã¯ãoffice365.domain.comã§ã¯ãªãdomain.comãæå®ããå¿ èŠããããŸãã ãã¡ã€ã³ãšãã¹ãŠã®ãµããã¡ã€ã³ãå€æãããŸãã
泚 ïŒãã®æäœã®åŸããã¡ã€ã³ãæ¢ã«ãã§ãã¬ãŒã·ã§ã³ãããŠãããããAD FS-Office 365ãã³ãã«ãæ§æãããŠããªãããæ£ããæ§æãããŠããªãå ŽåããŠãŒã¶ãŒã¯Office 365ã䜿çšã§ããŸãã ã
5. Update-MSOLFederatedDomain âdomainname <domain.com>
Office 365ã®ãã°ã€ã³ããŒãžã«ç§»åããŠãã¹ãŠãæ£ããè¡ããããšããã¹ã¯ãŒããã£ãŒã«ãã䜿çšã§ããªããªã£ãŠããããšãããããŸãã
ISAãŸãã¯TMGã䜿çšããŠAD FSãµãŒããŒãå ¬éãã
éåžžã®Webãµã€ããšããŠå ¬éãããŠããŸãããããã€ãã®ãã¥ã¢ã³ã¹ããããŸãã1.é«ãããæåããããã¯ããhttpsãããã³ã«ã®ããããã£ã®æ£èŠåããªãã«ãªã£ãŠããããšã確èªããŸãã
2.ãªã³ã¯å€æããªãã«ããå¿ èŠããããŸãã
3.ã«ãŒã«ã®èšå®ã§ãISAãµãŒããŒã³ã³ãã¥ãŒã¿ããã®èŠæ±ã衚瀺ãããŠããããã«èŠãããã確èªããå¿ èŠããããŸã
4.ãªã¹ããŒèšå®ã§ãAD FSã®ã€ã³ã¹ããŒã«æã«IISã«ã€ã³ããŒããã蚌ææžãè¿œå ããå¿ èŠããããŸãã
å ¬éãããã Office 365ããŒã¿ã«ãŸãã¯outlook.comã䜿çšããŠäœæ¥ããã¹ãã§ããŸãã SSOãã©ãã«ã·ã¥ãŒãã£ã³ã°ã«æé©ãªãµã€ã ã
泚 ïŒãŠãŒã¶ãŒãäœæ¥ããã«ã¯ãã©ã€ã»ã³ã¹ãå²ãåœãŠãå¿ èŠããããŸã;ãã¹ããŠãŒã¶ãŒã®å Žåãã©ã€ã»ã³ã¹ãæåã§å²ãåœãŠãããšãã§ããŸãã powershellã䜿çšããŠããŠãŒã¶ãŒã«ã©ã€ã»ã³ã¹ãäžæ¬è¿œå ã§ããŸãã
ãŸãšã
ãã®çµæããŠãŒã¶ãŒã¯ãã³ã³ãã¥ãŒã¿ãŒãããã¡ãŒã«ããã¯ã¹ãšãã¹ã¯ãŒãã䜿çšããŠOffice 365ã«ãã°ã€ã³ã§ããäœæ¥ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãªããŸãã ãã¹ãŠã®ãã¹ã¯ãŒãã¯AD DSã«ä¿åãããŸãã ãã¹ã¯ãŒãã¯åæãããŸããïŒããã«ã¯AD FSãå¿ èŠã§ãïŒã ãŠãŒã¶ãŒæ å ±ã®å€æŽã¯ãã¹ãŠãã€ãã£ãã®AD DSã«å¯ŸããŠè¡ãããOffice 365ã«èªåçã«è€è£œãããŸãã
ãã®èšäºã誰ãã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã
ãã®çµéšã¯ãFIM 2010ã䜿çšããéã®ããµã€ãããšããŠåŸãããŸããããã®ããã°ã©ã ã®åšãã«ã³ãã¥ããã£ããªãã®ã¯æ®å¿µã§ããå°æ¥FIMã«ã€ããŠæžãäºå®ã§ãã