ãã®ãããç¬èªã®éäžåã¢ã¯ã»ã¹ã«ãŒã«ãšããªã·ãŒã®äœæã«ååãªæ³šæãæããåçå¶åŸ¡ãã¯ãããžãŒã®å®è£ åŸã«çºçããå¯èœæ§ã®ãããã¹ãŠã®ç¶æ³ãå®å šã«äºæž¬ããããã«å¿ èŠãªæéãè²»ããããšãéåžžã«éèŠã§ããå®çšŒåç°å¢ãžã®ã¢ã¯ã»ã¹ã ããã§ã¯ãæåã«å®éšå®€ã§ãã¹ãŠã®ãã¹ããå®è¡ããå¯èœã§ããã°ãã€ãããã°ã«ãŒãã§å®è¡ããããšãéåžžã«éèŠã§ããããããªããšãçµæãæãäºæž¬äžèœã«ãªãå¯èœæ§ããããŸãã ååãšããŠããã®ã·ãªãŒãºã®æåŸã®èšäºã®1ã€ã§åçã¢ã¯ã»ã¹å¶åŸ¡ã®èšç»ã«æ»ãããããã®ãããã¯ã®ãã®æ®µéã«ã€ããŠè©³ãã説æããã®ã¯ç¡æå³ã§ãã
ä»æ¥ã¯ãéäžåã¢ã¯ã»ã¹ã«ãŒã«èªäœã®æå®ãéäžåã¢ã¯ã»ã¹ããªã·ãŒãªã©ã®åé¡ãæ€èšããŸãã ãã®ãããªã«ãŒã«ãšããªã·ãŒãäœæãç·šéãåé€ããæ¹æ³ãåŠç¿ããŸãã ããã«ããã®èšäºã§ã¯ãéäžã¢ã¯ã»ã¹ããªã·ãŒã®é åžãšé©çšã«ã€ããŠåŠç¿ããŸãã ãã®ãµã€ã¯ã«ã®4çªç®ã®èšäºã®å Žåã®ããã«ããã®èšäºã«ã¯å€ãã®è³æããããããæåã®ã»ã¯ã·ã§ã³ã«é²ã¿ãŸãã
éäžã¢ã¯ã»ã¹ã«ãŒã«
éäžåã¢ã¯ã»ã¹ã«ãŒã«ã®äœæãéå§ããåã«ããããå®éã«äœã§ããããã®ãããªãªããžã§ã¯ããäœã®ããã§ãããã決å®ããå¿ èŠããããŸãã å®çŸ©äžã ã»ã³ãã©ã«ã¢ã¯ã»ã¹ã«ãŒã«ã¯ããŠãŒã¶ãŒã°ã«ãŒãããŠãŒã¶ãŒãšããã€ã¹ã®èŠä»¶ãããã³ãªãœãŒã¹ããããã£ã«åœ±é¿ãã1ã€ä»¥äžã®æ¡ä»¶ãå«ããããšãã§ããæ¿èªã«ãŒã«ã®è¡šçŸã§ãã çæãããäžå åãããã¢ã¯ã»ã¹ã«ãŒã«ã«ãã£ãŠããªãœãŒã¹ã®ç¹å®ã®é åãžã®ã¢ã¯ã»ã¹ã誰ã«èš±å¯ããããã決ãŸããŸãã åçã¢ã¯ã»ã¹å¶åŸ¡ã®ãã¯ãããžãŒã®ãã¹ãŠã®ãªããžã§ã¯ããšåæ§ã«ããã®ãããªã«ãŒã«ã«ã¯äžæã®ååãšããã¡ãããªãã·ã§ã³ã§æ確ãªèª¬æãå«ããå¿ èŠããããŸãã ããã«ããã§ã«ææããããã«ããããã®ã«ãŒã«ã«ã¯ãSDDLèšèªïŒã»ãã¥ãªãã£èšè¿°åå®çŸ©èšèªïŒã®æ¡ä»¶åŒã§ããç¹å®ã®åŒãå«ãŸããŠããŸãã
ãŸããããã€ãã®éäžåã¢ã¯ã»ã¹ã«ãŒã«ãçµã¿åãããŠãéäžåã¢ã¯ã»ã¹ããªã·ãŒãäœæããããšãã§ããŸãã äžè¬ã«ããã¡ã€ã³ã«å¯ŸããŠ1ã€ä»¥äžã®éäžåã¢ã¯ã»ã¹ã«ãŒã«ãå®çŸ©ãããŠããå Žåããã¡ã€ã«ãªãœãŒã¹ç®¡çè ã¯äŸ¿å®äžãç¹å®ã®ã«ãŒã«ãç¹å®ã®ãªãœãŒã¹ããã³ããžãã¹èŠä»¶ã«ãããã³ã°ã§ããŸãã
ååãšããŠãéäžåã¢ã¯ã»ã¹ã«ãŒã«ã«é¢ããçè«çãªéšåã«é¢ããŠã¯ãæ¬è³ªçã«ã¯äœãèšãããšã¯ãªãã®ã§ãããèå³æ·±ãéšåã§ããå®çšçãªéšåã«ç§»ããŸãããã 次ã«ãéäžã¢ã¯ã»ã¹ã«ãŒã«ã®äœæãç·šéãåé€ã«ã€ããŠèª¬æããŸãã ç§ãã¡ã¯èªç¶ã«å§ãŸããŸã
äžå€®ã®ã¢ã¯ã»ã¹ã«ãŒã«ãäœæãã
ãŸã第äžã«ãããã©ã«ãã§ã¯ãµãŒããŒäžã«éäžã«ãŒã«ã¯äœæãããªãããšã«æ³šæããå¿ èŠããããŸãã ãããã£ãŠãéäžåãããã¢ã¯ã»ã¹ã«ãŒã«ãããã«äœ¿çšããããã«éäžåãããã¢ã¯ã»ã¹ããªã·ãŒã䜿çšããã«ã¯ãããããèªåã§äœæããå¿ èŠããããŸãã ç¬èªã®éäžåã¢ã¯ã»ã¹ã«ãŒã«ãäœæããããšèªäœã¯é£ãããããŸããã ãã®ããã»ã¹ã§ã¯ãActive DirectoryãµãŒããŒã®å šäœç®¡çãŸãã¯Windows PowerShellãªã©ã®ããŒã«ã䜿çšããŠãã®ã¿ã¹ã¯ãå®è¡ã§ããããããã®ã·ãªãŒãºã®ä»¥åã®ãã¹ãŠã®èšäºã§èª¬æãããã¹ãŠã®ãªããžã§ã¯ããäœæããããšãæãåºãããããšãã§ããŸãã ãã¡ãããActive DirectoryãµãŒããŒã®å šäœç®¡çã»ã³ã¿ãŒã®ã³ã³ãœãŒã«ããéå§ããŸãã å šäœã®ããã»ã¹ã¯æ¬¡ã®ãšããã§ãã
- ãã¡ã€ã³ã³ã³ãããŒã©ãŒã§ã ãActive Directory管çã»ã³ã¿ãŒãã³ã³ãœãŒã«ãéãå¿ èŠããããŸããããã§ã移è¡ããŒãé åã§ãåçã¢ã¯ã»ã¹å¶åŸ¡ãããŒããéžæãã ãäžå€®ã¢ã¯ã»ã¹ã«ãŒã«ã ïŒ åçã¢ã¯ã»ã¹å¶åŸ¡>äžå€®ã¢ã¯ã»ã¹ã«ãŒã« ïŒãéžæããå¿ èŠããããŸãã ãã®ã³ã³ãœãŒã«ã®åæç»é¢ã®åçã¢ã¯ã»ã¹å¶åŸ¡ã¿ã€ã«ã§ãªãã·ã§ã³çªå·3- ãéäžã¢ã¯ã»ã¹ã«ãŒã«ã®äœæããéžæããŠããã®ããŒãã«ç§»åããããšãã§ããŸã ã
- ãã®æé ã®2çªç®ã®ã¹ãããã§ã¯ã次ã®å³ã«ç€ºãããã«ã詳现ãã€ã³ãŸãã¯ã¿ã¹ã¯ãã€ã³ã®ã³ã³ããã¹ãã¡ãã¥ãŒãã[ äœæ ]ãªãã·ã§ã³ãŸãã¯ã»ã³ãã©ã«ã¢ã¯ã»ã¹ã«ãŒã« ïŒ æ°èŠ>ã»ã³ãã©ã«ã¢ã¯ã»ã¹ã«ãŒã« ïŒãéžæããå¿
èŠããããŸãã ïŒ
å³ 1.æ°ããäžå€®ã¢ã¯ã»ã¹ã«ãŒã«ãäœæãã - å³çªå·2ã«ç€ºãããã«ã衚瀺ããããã€ã¢ãã°ããã¯ã¹ã§ã3ã€ã®ç°ãªãã°ã«ãŒãã§å¿
èŠãªã³ã³ãããŒã«èŠçŽ ã®å€ã決å®ããå¿
èŠããããŸããæ°ããã«ãŒã«ãäœæããã«ã¯ãå
šäœãšããŠãäžäœã°ã«ãŒãã®æåã®ã³ã³ãããŒã«ã®ã¿ãå
¥åããã ãã§ååã§ãã ãããããŸãæåã«ïŒ
- ã°ã«ãŒããäžè¬ã ïŒ äžè¬ ïŒã ãã®ã°ã«ãŒãã«ã¯ããã€ãããã¯ã¢ã¯ã»ã¹ã³ã³ãããŒã«ãã¯ãããžãŒã®äœæããããªããžã§ã¯ãã®ã»ãšãã©ã«ã€ããŠãã»ãŒæšæºã®ãã©ã¡ãŒã¿ãŒã»ããããããŸãã ãã®ã°ã«ãŒãã§ã¯ã次ã®3ã€ã®äž»èŠãªãã©ã¡ãŒã¿ãŒãå®çŸ©ã§ããŸãã
- ãåå ããã§ã¯ãã¹ãŠãæ確ã§ãããã®ãããªåã«ãŒã«ãèå¥ããã«ã¯ãå¿ ããã®ååã瀺ãå¿ èŠããããŸãã ååã¯äžæã§ãè±æ°å圢åŒã§ç€ºãããŠããå¿ èŠããããŸãããã®ãã©ã¡ãŒã¿ãå ¥åããããšã¯ãã¢ã¯ã»ã¹ã«ãŒã«ãäœæããããã®åææ¡ä»¶ãšèŠãªãããŸãã ã¡ãªã¿ã«ãäžå€®ã¢ã¯ã»ã¹ã«ãŒã«ãèšç»ãããšãã¯ãã«ãŒã«åã®æ倧æåæ°ã64æåã§ããããšã«æ³šæããŠãã ããã ã€ãŸãããã®å¶éãè¶ ããªãããã«ããå¿ èŠããããŸãã ããšãã°ããã®äŸã§ã¯ãã«ãŒã«ã®ååãã ã¢ãã£ãªãšã€ãã®ãªãœãŒã¹ãäžå€®ããŒã±ãã£ã³ã°æ åœè ã«èªã¿åãæš©é ããšåŒã³ãŸãã ãªãã£ã¹ ã;
- 説æ ãªãã·ã§ã³ã®ããã¹ããã£ãŒã«ãã§ããã説æãããã°ãæ°åãŸãã¯ãã以äžã®éäžã¢ã¯ã»ã¹ã«ãŒã«ãçæãããå Žåã«åœ¹ç«ã¡ãŸãã ååãšåæ§ã«ããã®ãã£ãŒã«ãã®æåæ°ãå¶éãããŠããŸãã ã«ãŒã«ã®èª¬æãæ倧1024æåã«åããå¿ èŠããããŸããããããªããšããã®ãããªã«ãŒã«ãäœæã§ããŸããã 説æã§ã¯ãã äŒç€Ÿã®æ¯åºã®ã¿ãŒã²ãããªãœãŒã¹ã«ã€ããŠãæ¬ç€Ÿã®ããŒã±ãã£ã³ã°ãªãœãŒã¹ãžã®èªã¿åãã¢ã¯ã»ã¹ãèš±å¯ãã ããšèšè¿°ããŠããŸãã
- 誀ã£ãåé€ã«å¯Ÿããä¿è·ïŒèª€ã£ãåé€ããä¿è·ããïŒ ã ãã¡ã€ã³ç®¡çè ãšãšã³ã¿ãŒãã©ã€ãºç®¡çè ã®ã»ãã¥ãªãã£ã°ã«ãŒãã®ç®¡çè ã®ã¿ããã®ãããªã«ãŒã«ãäœæãå€æŽããŸãã¯åé€ã§ããããšãèæ ®ããŠããã«ãŒã«äœæè 以å€ã®å šå¡ãçŸåšã®ã«ãŒã«ãåé€ã§ããªãããã«ããActive DirectoryãµãŒããŒã®å šäœç®¡çãªããžã§ã¯ãã®æšæºãã§ãã¯ããã¯ã¹ã
- ã¿ãŒã²ãããªãœãŒã¹ã°ã«ãŒã ãã®ãã€ã¢ãã°ããã¯ã¹ã®2çªç®ã®ã°ã«ãŒãã¯ãéäžåã¢ã¯ã»ã¹ã«ãŒã«ã®ããããã¹ã³ãŒãã決å®ããããã«äœ¿çšãããŸãã ãã®ãããªã¹ã³ãŒãã¯ã以åã«äœæããããªãœãŒã¹ããããã£ãªããžã§ã¯ããããããæ¡ä»¶åŒãšããŠå®çŸ©ããããšã§äœæãããŸãã ãããã£ãŠãäœæããã«ãŒã«ã«ã€ããŠãã»ãšãã©ãã¹ãŠã®å¯èœãªç¯å²ã決å®ã§ããŸãã éäžã¢ã¯ã»ã¹ã«ãŒã«ãåããã£ã¹ã¯é åã®å°ããªã°ã«ãŒãã«ã®ã¿é©çšããããšããã°ãã°åãå ¥ããããŠãããšããäºå®ã«ãããããããããã©ã«ãå€ã®ãŸãŸã«ããŠããããšãã§ãããããã«ãŒã«ã¯ãã¹ãŠã®å¯èœãªã¿ãŒã²ãããªãœãŒã¹ã«é©çšãããŸãã æšæºã®ANDãŸãã¯ORæŒç®åã䜿çšããŠããã®ãããªæ¡ä»¶åŒãã°ã«ãŒãåã§ããŸãã ããã«ãããè€éãªã·ããªãªãäœæããããã«ãè€æ°ã®æ¡ä»¶åŒãåæã«ã°ã«ãŒãåããŠããã®ãããªçµæã®ç¯å²ãçµã¿åãããããšãã§ããŸãã ã€ãŸããã«ãŒã«ã®ããã©ã«ãã¹ã³ãŒããå€æŽããå Žåã¯ã[ ç·šé ]ãã¿ã³ãã¯ãªãã¯ããŸãã
- æš©éã°ã«ãŒã ã ãã©ã¡ãŒã¿ãŒã®ãã®æåŸã®ã°ã«ãŒãã®ãããã§ã次ã®2ã€ã®ç°ãªãæ©èœã䜿çšããŠãäœæããã«ãŒã«ã®ã¢ã¯ã»ã¹èš±å¯ãäºåã«å®çŸ©ã§ããŸãã
- 次ã®æš©éãææ¡ãããæš©éãšããŠäœ¿çšããŸã ã å ¬åŒã®å®çŸ©ã«ããã°ããã®ãã©ã¡ãŒã¿ãŒã䜿çšãããšãã·ã¹ãã ã®åäœã«åœ±é¿ãäžããããšãªããã¿ãŒã²ãããªããžã§ã¯ããžã®ã¢ã¯ã»ã¹èŠæ±ã®çµæãç£æ»ã§ããŸãã ã€ãŸãããã®ãªãã·ã§ã³ãéžæããããšã§ã察å¿ãããªã¹ãã®èš±å¯ãšã³ããªããäœæããéäžåã¢ã¯ã»ã¹ã«ãŒã«ã®ææ¡ãããèš±å¯ãšã³ããªã®ãªã¹ãã«è¿œå ã§ããŸãã ææ¡ãããã¢ã¯ã»ã¹èš±å¯ã®ãªã¹ããç£æ»ãã¡ã€ã«ã·ã¹ãã ãšçµã¿åãããŠãçŸåšã®ã¢ã¯ã»ã¹èš±å¯ã®ãªã¹ãã«ããã¢ã¯ã»ã¹èš±å¯ãå€æŽããã«ããŠãŒã¶ãŒããªãœãŒã¹ã«å¯ŸããŠåããå¹æçãªã¢ã¯ã»ã¹ãã·ãã¥ã¬ãŒãã§ããŸãã ææ¡ãããã¢ã¯ã»ã¹èš±å¯ã¯ãã€ãã³ããã°ã§ç¢ºèªã§ããç¹å¥ãªç£æ»ã€ãã³ããçæããŸããã€ãã³ããã°ã§ã¯ããŠãŒã¶ãŒãè¡ã£ããã¹ãŠã®ã¢ã¯ã»ã¹è©Šè¡ããã詳现ã«ç¢ºèªã§ããŸãã
- çŸåšã®æš©éãšããŠæ¬¡ã®æš©éã䜿çšããŸã ã ãã®ãªãã·ã§ã³ãéžæããããšã«ããããã®ãããªã«ãŒã«ã衚瀺ãããéäžã¢ã¯ã»ã¹ããªã·ãŒã®å ¬éåŸã«ã¿ãŒã²ãããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãæäŸã§ããŸãã ã€ãŸããçŸåšã®ã¢ã¯ã»ã¹èš±å¯ã®ãªã¹ãã¯ããã¡ã€ã«ãµãŒããŒã«äžå€®ã¢ã¯ã»ã¹ã«ãŒã«ãå±éãããšãã«Windowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãèªã¿åãè¿œå ã®ã¢ã¯ã»ã¹èš±å¯ãè¡šããŸãã æ¢ã«è¿°ã¹ãããã«ãéäžåã¢ã¯ã»ã¹ã«ãŒã«ã¯æ¢åã®ã»ãã¥ãªãã£èšå®ã«çœ®ãæãããã®ã§ã¯ãããŸãããæ¿èªã決å®ããéãWindowsã¯éäžåã¢ã¯ã»ã¹ã«ãŒã«ã®ã¢ã¯ã»ã¹èš±å¯ãNTFSã¢ã¯ã»ã¹èš±å¯ã®çŸåšã®ãªã¹ããããã³å ±æãªãœãŒã¹ã®ã¢ã¯ã»ã¹èš±å¯ã®ãªã¹ããå¿ ãè©äŸ¡ããŸãã
ãã®å Žåã2çªç®ã®ãªãã·ã§ã³ã§åæ¢ããå€ãã®ã»ãã¥ãªãã£ãªãã·ã§ã³ã«æ¢ã«æ £ããŠãããã€ã¢ãã°ã®[ ç·šé ]ãã¿ã³ãã¯ãªãã¯ããåŸã ãèªã¿åããšå®è¡ãæš©éãå²ãåœãŠãããã ããµã³ãŒã«ã¹ããŒã±ã¿ãŒ ããªã©ã®å¿ èŠãªã°ã«ãŒããè¿œå ããŸãããªãã³ã«éåžžã®ãèªæžã ã
å³ 2.æ°ããäžå€®ã¢ã¯ã»ã¹ã«ãŒã«ãäœæããããã®ãã€ã¢ãã°ããã¯ã¹
- ã°ã«ãŒããäžè¬ã ïŒ äžè¬ ïŒã ãã®ã°ã«ãŒãã«ã¯ããã€ãããã¯ã¢ã¯ã»ã¹ã³ã³ãããŒã«ãã¯ãããžãŒã®äœæããããªããžã§ã¯ãã®ã»ãšãã©ã«ã€ããŠãã»ãŒæšæºã®ãã©ã¡ãŒã¿ãŒã»ããããããŸãã ãã®ã°ã«ãŒãã§ã¯ã次ã®3ã€ã®äž»èŠãªãã©ã¡ãŒã¿ãŒãå®çŸ©ã§ããŸãã
- ãã¹ãŠã®èšå®ãå®çŸ©ããããã¢ã¯ã»ã¹ã«ãŒã«ãå®å šã«ä¿åã§ããŸãã
ã芧ã®ãšãããè€éãªããšã¯äœããããŸããã ããã§ããããããå°ãç°ãªãæ¹æ³ã䜿çšããŠããŸãã¯ããæ£ç¢ºã«ã¯Windows PowerShellãªã©ã®åŒ·åãªç®¡çããŒã«ã䜿çšããŠãäžå åãããã¢ã¯ã»ã¹ã«ãŒã«ãäœæããããšãæ€èšããŸãã ãã®ãããªããªã·ãŒã管çããPowerShellã³ãã³ãã¬ãããå®å šã«èŠçŽãããšããã®ã·ãªãŒãºã®åã®èšäºã§èª¬æãããªãœãŒã¹ããããã£ãªã¹ãã管çããå Žåãšåæ§ã«ã3ã€ã®ç°ãªãã³ãã³ãã¬ãããã€ãŸãNew-ADCentralAccessRuleãåºå¥ã§ããŸããæ°ããäžå åãããã¢ã¯ã»ã¹ããªã·ãŒSet-ADCentralAccessRuleãäœæã§ããŸããããã«ãããæ¢åã®ã«ãŒã«ãç·šéã§ããŸãããŸãã Remove-ADCentralAccessRuleãäœæã§ããŸããããã¯ãåŸè ã®åé€ãããããæ åœããŸãã PowerShellã䜿çšããæ¢åã®ã¢ã¯ã»ã¹ã«ãŒã«ã®ç·šéãšåé€ã¯éåžžã«ç°¡åã§ããããããããã®æäœã¯çŸåšã®èšäºã§ã¯åçŽã«çç¥ãããŸãã ãããŠãæ°ããéäžã¢ã¯ã»ã¹ããªã·ãŒã®äœæãéå§ããŸãã
ããšãã°ã ã ããŒã±ãã£ã³ã°ãŠãããã«åé¡ããããã¹ãŠã®ãªãœãŒã¹ãžã®ããŒã±ãã£ã³ã°æ åœè ã®ã¢ã¯ã»ã¹ãèš±å¯ããããªã·ãŒ ããšãã説æãšãšãã«ãã ããµã³ãŒã«ã¹ããŒã±ãã£ã³ã°æ åœè ã®ããŒã±ãã£ã³ã°ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ ããšããããªã·ãŒãäœæããå¿ èŠããããŸããåé¡ã ãã®å ŽåãPowerShellã³ãã³ãã¯æ¬¡ã®ããã«ãªããŸãã
New-ADCentralAccessRule -CurrentAcl:"O:SYG:SYD:AR(A;;FA;;;S-1-5-21-3046794806-2660339953-3139999740-1107)" -description:", , Marketing" -Name:" - " -ProposedAcl:$null -ProtectedFromAccidentalDeletion:$true -ResourceCondition:"(@RESOURCE.Department_MS == `"Marketing`")" -Server:"DC.biopharmaceutic.local"
ããã§ïŒ
- Nameãã©ã¡ãŒã¿ãŒã¯ãäœæããããªããžã§ã¯ãã®ååãæ åœããŸãã ãã®èšå®ã®ç®çãšå¶éã¯ããµãŒããŒã®å šäœç®¡çã³ã³ãœãŒã«ã®æ©èœãšå®å šã«äžèŽããŠããŸãã
- Descriptionãã©ã¡ãŒã¿ãŒã¯ãäœæããŠããã«ãŒã«ã®èª¬æã瀺ãããšãç®çãšããŠããŸãã
- CurrentACLãã©ã¡ãŒã¿ãŒã䜿çšãããšãäœæããŠããã¢ã¯ã»ã¹ã«ãŒã«ã®ã¢ã¯ã»ã¹èš±å¯ã®çŸåšã®ãªã¹ããå®çŸ©ã§ããŸã ã ãã®ãã©ã¡ãŒã¿ãŒã®å€ã®æãé£ããéšåã¯ãããã§ãã¹ãŠã®ã¢ã¯ã»ã¹èš±å¯ãSDDLã§èšè¿°ãããçã圢åŒã§æå®ããå¿ èŠãããããšã§ãã ãã®ãªãã·ã§ã³ã䜿çšããå ŽåãæãéèŠãªããšã¯ã ACE Stringsããã³SID Stringsããã¥ã¡ã³ãã泚ææ·±ã調ã¹ãããšã§ãã äžè¬ã«ããã®ãã©ã¡ãŒã¿ãŒã«é¢é£ãããšã©ãŒã¯æ±ºå®çãªãã®ã«ãªãå¯èœæ§ãããããããã®ãã©ã¡ãŒã¿ãŒã®æ瀺ã®æ£ç¢ºããåžžã«å確èªããŠãã ããã
- ProposedAclãã©ã¡ãŒã¿ãŒã¯ãææ¡ãããã¢ã¯ã»ã¹èš±å¯ãå®çŸ©ããŸããããã¯ãåã®ãã©ã¡ãŒã¿ãŒãšåã圢åŒã§æå®ããããã®èšäºã®æ¬¡ã®ãµãã»ã¯ã·ã§ã³ã§è©³ãã説æããŸãã
- ProtectedFromAccidentalDeletionãã©ã¡ãŒã¿ãŒã¯ãéäžã¢ã¯ã»ã¹ã«ãŒã«ãäœæããããã®ãã€ã¢ãã°ããã¯ã¹ã®äžè¬çãªã°ã«ãŒãã®æšæºãã©ã¡ãŒã¿ãŒã§ããã誀ã£ãŠåé€ãããªãããã«ä¿è·ããŸãã
- ResourceConditionãã©ã¡ãŒã¿ãŒã¯ãå€ããã®ã«ãŒã«ã®æ¡ä»¶ã§ãããã©ã¡ãŒã¿ãŒã§ãã ãã®äŸïŒ @ RESOURCE.Department_MS == `` Marketing` " ïŒã§ã¯ããã¹ãŠã声ã«åºããŠçºé³ãããã®ãšåãæ¹æ³ã§æå®ãããŸããã€ãŸããéšéïŒDepartment_MSïŒã®ãªãœãŒã¹ïŒ@RESOURCEïŒã¯ãMarketingã®å€ïŒ` `Marketing` "ïŒã ãã®ãããªæ¡ä»¶ãæ£ããæ§æããæ¹æ³ãåŠã¶ã«ã¯å€ãã®ç·Žç¿ãå¿ èŠã§ãããŸããå¿ èŠã«å¿ããŠãã«ãŒã«ãäœæããåŸãå®æçã«Windows PowerShellãã°ãæåã§èª¿ã¹ãããšãã§ããŸãã
- Serverãã©ã¡ãŒã¿ãŒã¯ãåçŽã«ã«ãŒã«ãäœæãããµãŒããŒã®ååã§ãã ãã®ç¹å®ã®ã±ãŒã¹ã§ã¯ããµãŒããŒåã¯ãã¡ã€ã³diopharmaceutic.localã®DCã§ããããããã®ãã©ã¡ãŒã¿ãŒã«å¯Ÿå¿ããå€ãååŸããŸãã
ãã®ã³ãã³ãã®åºåã¯éåžžã«åçŽã§ãããšã©ãŒã衚瀺ãããªãå Žåã¯ããã¹ãŠãæ£åžžã§ãããéäžã¢ã¯ã»ã¹ã«ãŒã«ãäœæãããŠããŸãã ãã®ã³ãã³ãã®åºåäŸã以äžã«ç€ºããŸãã
å³ 3. Windows PowerShellã䜿çšããŠéäžåã¢ã¯ã»ã¹ã«ãŒã«ãäœæãã
æ¢åã®äžå€®ã¢ã¯ã»ã¹ã«ãŒã«ãå€æŽãã
æ°ãããªããžã§ã¯ããäœæããåŸããããå€æŽããããšãå¿ èŠã«ãªãç¶æ³ã¯åžžã«ãããŸãã äœæäžã«ééããçºçããããå¿ èŠãªè§£å床ãè¿œå ããã®ãå¿ããããæå®ãããæ¡ä»¶ãååã«å æ¬çã§ã¯ãªãã£ããªã©ãå€ãã®ãªãã·ã§ã³ããããŸãã ããããæãéèŠãªããšã¯ãå¿ èŠãªæ å ±ãäžè¶³ããŠããå Žåãäœæããããªããžã§ã¯ããå€æŽããå¿ èŠããããšããããšã§ãã ãã¡ããããã®ãããªç¶æ³ã«ã¯éåžžãéäžåã¢ã¯ã»ã¹ã«ãŒã«ãé©çšãããæ¢åã®ãªããžã§ã¯ããå€æŽããããã«è¶ èªç¶çãªã¢ã¯ã·ã§ã³ã¯å¿ èŠãããŸããã 倧ãŸãã«èšãã°ãã«ãŒã«èªäœãäœæãããåãããŒãã«ç§»åãïŒ ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡>ã»ã³ãã©ã«ã¢ã¯ã»ã¹ã«ãŒã« ïŒã詳现ãã€ã³ã®ãªã¹ãã§ãã®ãããªã«ãŒã«ãèŠã€ããŠããã[ ããããã£â ïŒ ãããã㣠ïŒã
äœæããã«ãŒã«ãå€æŽããããã«è¡šç€ºããããã€ã¢ãã°ããã¯ã¹ã§ã¯ã次ã®3ã€ã®ç¹ãé€ãããã®ãããªã«ãŒã«ãäœæãããšããšã»ãŒåãæ©äŒãæäŸãããŸãã
- ãŸããã«ãŒã«ã®ååãå€æŽããããšã¯ã§ããŸããã ããªãã«ã¯ãã®ãããªæ©äŒã¯ãããŸãããããã ãã§ãã
- 第äºã«ãçŸåšã®ã¢ã¯ã»ã¹èš±å¯ã®ç·šéã«å ããŠã ææ¡ãããã¢ã¯ã»ã¹èš±å¯ãæ§æããæ©äŒãäžããããŸããããã¯ãWindows PowerShellã䜿çšããéäžã¢ã¯ã»ã¹ã«ãŒã«ã®äœæäžã«æž¡ãããšã§èšåããŸããã ãããã®ææ¡ãããèš±å¯ã¯äœã§ããïŒ ãŸãã çŸåšã®ã¢ã¯ã»ã¹èš±å¯ãšææ¡ãããã¢ã¯ã»ã¹èš±å¯ã®éããç解ããå¿
èŠããããŸãã çŸåšã®æš©éã®ãªã¹ãã¯ãäžå€®ã¢ã¯ã»ã¹ã«ãŒã«ã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå®çŸ©ãããšã³ããªã§ãã ãããã®ã¢ã¯ã»ã¹èš±å¯ã¯ãéäžã¢ã¯ã»ã¹ããªã·ãŒã䜿çšããŠéäžã¢ã¯ã»ã¹ã«ãŒã«ãå±éããåŸã«æå¹ã«ãªããŸããããã«ã€ããŠã¯ããã®èšäºã®åŸåã§åŠç¿ããŸãã 次ã«ã ææ¡ãããã¢ã¯ã»ã¹èš±å¯ã¯ãããããã£ã衚瀺ããããæ¢åã®ã¢ã¯ã»ã¹ã«ãŒã«ãå€æŽããå Žåã«ã®ã¿æ€åºã§ããŸãã ææ¡ãããã¢ã¯ã»ã¹èš±å¯ã®ãªã¹ãã§ã¯ãææ¡ãããã¢ã¯ã»ã¹èš±å¯ã®ãªã¹ãã䜿çšããŠãçŸåšã®ã»ãã¥ãªãã£åå è
éã®ã¢ã¯ã»ã¹èš±å¯ã®ãã¹ãŠã®å¯èœãªå€æŽã衚瀺ã§ããŸãã ããããããã«ãããããããææ¡ãããã¢ã¯ã»ã¹èš±å¯ã®ãã®ãããªãªã¹ãã¯ããŠãŒã¶ãŒã®çŸåšã®ã¢ã¯ã»ã¹èš±å¯ã«ãŸã£ãã圱é¿ãäžããªããšããäºå®ã«æ³šæãæã䟡å€ããããŸãã ãŸãããã®ãããªäžéã®ã¢ã¯ã»ã¹èš±å¯ã衚瀺ããã³åæã§ããããã«ããã«ã¯ã ã ã¢ã¯ã»ã¹èš±å¯ã®ã¹ããŒãžã³ã°æ§æãæå¹ã«ãã ããã§ãã¯ããã¯ã¹ãã¢ã¯ãã£ãã«ããå¿
èŠãããããšã«æ³šæããŠãã ããã ããã«ãææ¡ãããæš©éã䜿çšããå Žåã¯ã次ã®æ©èœã«æ³šæããŠãã ããã
- ãã©ã¡ãŒã¿ãå€æŽãïŒç·šéïŒ ã æãããªããã«ããã®ãã¿ã³ãã¯ãªãã¯ãããšãè¿œå ã®ã»ãã¥ãªãã£èšå®çšã®ãã€ã¢ãã°ããã¯ã¹ã衚瀺ãããææ¡ãããæš©éã®ã°ã«ãŒãã«å¯ŸããŠæš©éãå€æŽãŸãã¯è¿œå ã§ããŸãã
- ææ¡ããããã©ã¡ãŒã¿ã®é©çš ã ãã®ãªãã·ã§ã³ã䜿çšãããšãçŸåšã®æš©éããææ¡ãããæš©éã®ã°ã«ãŒãã§å®çŸ©ããæš©éã«çœ®ãæããããšãã§ããŸãã
- çŸåšã®ãªãã·ã§ã³ããã³ã㌠ã åæ§ã«ããã®ãã©ã¡ãŒã¿ãŒã䜿çšãããšãå察ã®ã¢ã¯ã·ã§ã³ãå®è¡ã§ããŸããã€ãŸãããã®ã¢ã¯ã·ã§ã³ã¯ãææ¡ãããã¢ã¯ã»ã¹èš±å¯ã®ãªã¹ãã®ã¢ã¯ã»ã¹èš±å¯ããçŸåšã®ã¢ã¯ã»ã¹èš±å¯ã®ãªã¹ãã®ã¢ã¯ã»ã¹èš±å¯ã«åçŽã«çœ®ãæããŸãã
- 第äžã«ãæåã«äžåºŠèšå®ãããã¢ã¯ã»ã¹èš±å¯ãå€æŽããåŸãå€æŽãããäžå€®ã¢ã¯ã»ã¹ã«ãŒã«ã®ããããã£ãã€ã¢ãã°ããã¯ã¹ãéããã³ã«ãå¥ã®ã°ã«ãŒãã®æ©èœïŒ 以åã®ã¢ã¯ã»ã¹èš±å¯ã°ã«ãŒãïŒã䜿çšå¯èœã«ãªããŸãã ã«ãŒã«ãå€æŽãããšã©ããªããŸããïŒ äžå åãããã¢ã¯ã»ã¹ã«ãŒã«ã®ã¢ã¯ã»ã¹èš±å¯ãå€æŽããåŸããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯åæã®çŸåšã®ã¢ã¯ã»ã¹èš±å¯ã以åã®ã¢ã¯ã»ã¹èš±å¯ã°ã«ãŒãã®ãªã¹ãã«ã³ããŒããææ¡ãããã¢ã¯ã»ã¹èš±å¯ããæŽæ°ãããçŸåšã®ã¢ã¯ã»ã¹èš±å¯ã®ãªã¹ããšä»¥åã®ã¢ã¯ã»ã¹èš±å¯ã®ãªã¹ããä¿åããŸãã èŠããŠããã¹ãäž»ãªããšã¯ããã®ãªã¹ãã«ã¯ä»¥åã®ã¢ã¯ã»ã¹èš±å¯ã®ã¬ã³ãŒãã®ã³ããŒã1ã€ã ãå«ãŸããããšã§ãã ã€ãŸããActive DirectoryãµãŒããŒã®å šäœç®¡çã®æ©èœã¯ãçŸåšã®ã¢ã¯ã»ã¹èš±å¯ãªã¹ãã®ã¢ã¯ã»ã¹èš±å¯ã®ãã¹ãŠã®å€æŽã®å®å šãªå±¥æŽããµããŒãããŠããŸããã
次ã®å³ã§ãå€æŽãããéäžåã¢ã¯ã»ã¹ã«ãŒã«ã®ããããã£ãã€ã¢ãã°ããã¯ã¹ã確èªã§ããŸãã
å³ 4.å€æŽãããéäžåã¢ã¯ã»ã¹ã«ãŒã«ã®[ããããã£]ãã€ã¢ãã°ããã¯ã¹
æ¢åã®äžå€®ã¢ã¯ã»ã¹ã«ãŒã«ãåé€ãã
æ¢åã®éäžåã¢ã¯ã»ã¹ã«ãŒã«ãåé€ããæäœã¯ãå®è¡ã§ããæãåçŽãªæäœã§ããå¯èœæ§ãé«ããªããŸãã ãããè¡ãã«ã¯ãActive Directory管çã»ã³ã¿ãŒã®[ ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡]> [äžå€®ã¢ã¯ã»ã¹ã«ãŒã«]ããŒãã§ãäžèŠãªã¢ã¯ã»ã¹ã«ãŒã«ãéžæããã³ã³ããã¹ãã¡ãã¥ãŒãŸãã¯ã¿ã¹ã¯ããŒãã[ åé€]ã³ãã³ããéžæããŸãã 衚瀺ããã確èªç¢ºèªãã€ã¢ãã°ããã¯ã¹ã§ã ãã¯ãããã¿ã³ãã¯ãªãã¯ããå¿ èŠããããŸããããã¯ãéžæã決å®ããããšãæå³ããŸãã ããã ãã§ããã«ãŒã«ã¯å³åº§ã«åé€ãããŸãã
æš©éããªãããšã瀺ããã€ã¢ãã°ããã¯ã¹ã衚瀺ãããå Žåã¯ãåé€ããã«ãŒã«ã®ããããã£ãã€ã¢ãã°ããã¯ã¹ãéãã[ 誀ã£ãŠåé€ããªãããã«ä¿è·ãã ]ãªãã·ã§ã³ããªãã«ããŸãã ãã®åŸãæé ãç¹°ãè¿ããŠã«ãŒã«ãåé€ããŸãã
äžå€®ã¢ã¯ã»ã¹ããªã·ãŒã®ç®¡ç
ãã§ã«éäžåã¢ã¯ã»ã¹ã«ãŒã«ãæ±ã£ãŠããã®ã§ãéäžåã¢ã¯ã»ã¹ããªã·ãŒã«ç¹åãããã®èšäºã®æ¬¡ã®ãããã¯ã«ç§»ã䟡å€ããããŸãã éäžã¢ã¯ã»ã¹ããªã·ãŒã¯ãWindows Server 2012ãµãŒããŒãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«æåã«ç»å Žããæ¿èªããªã·ãŒã§ãããæ¡ä»¶åŒãå«ãŸããŠããŸãã ååãšããŠããã®ãããªããªã·ãŒã¯ãéäžã¢ã¯ã»ã¹ã«ãŒã«ã®ãªããžã§ã¯ãã®ã³ã¬ã¯ã·ã§ã³ã§ãã Active DirectoryãµãŒããŒã®å šäœç®¡çã»ã³ã¿ãŒã䜿çšããŠãããã®ããªã·ãŒãäœæãããã®åŸã°ã«ãŒãããªã·ãŒæ©èœã䜿çšããŠããããé åžã§ããŸãã ããšãã°ãçµç¹ã®ããžãã¹èŠä»¶ã«ããã¡ã€ã«ã®ææè ãšãå人æ å ±ã®è¡šç€ºãèš±å¯ãããŠããäžéšã®éšéïŒäººäºéšéãªã©ïŒã®ã¡ã³ããŒã«ãããã¡ã€ã«ã®å人æ å ±ãžã®ã¢ã¯ã»ã¹ã®å¶éãå«ãŸããå Žåãããã¯å人æ å ±ãã¡ã€ã«ã«é©çšãããäžè¬çãªçµç¹ããªã·ãŒã§ããé 眮ãããçµç¹ãã¡ã€ã«ãµãŒããŒã åè¿°ããããã«ãéäžåã¢ã¯ã»ã¹ããªã·ãŒã«ã¯1ã€ä»¥äžã®éäžåã¢ã¯ã»ã¹ã«ãŒã«ãå«ããããšãã§ããéäžåã¢ã¯ã»ã¹ã«ãŒã«ã¯ããã€ãã®ç°ãªãéäžåã¢ã¯ã»ã¹ããªã·ãŒã®ã¡ã³ããŒã«ãªãããšãã§ããŸãã
ããã§ãåè¿°ããããã«ãéäžåãããã¢ã¯ã»ã¹ããªã·ãŒãå°çšãã¡ã€ã«ãµãŒããŒã«ãããã¡ã€ã«ãšãã©ã«ããŒãžã®ã¢ã¯ã»ã¹ã®ã»ãã¥ãªãã£ãé«ãããšããäºå®ã«æ³šæãæãå¿ èŠããããŸãã ãããŒã«ã«ã¢ã¯ã»ã¹ããªã·ãŒãéžæç管çããŒãã«ã眮ãæãããã®ã§ã¯ãããŸããåããã¡ã€ã«ãŸãã¯ãã©ã«ããŒã«æ¢ã«é©çšãããŠããã¢ã¯ã»ã¹ïŒDACLïŒã èšãæããã°ã圌ãã¯èª¿åããŠãããŠäžç·ã«åãã æãåçŽãªäŸãèããŠã¿ãŸããããéäžã¢ã¯ã»ã¹ããªã·ãŒã§ã¯ããŠãŒã¶ãŒã¯ãã¡ã€ã«ãµãŒããŒã«ããç¹å®ã®ããã¥ã¡ã³ãã䜿çšã§ããããšãæ確ã«ç€ºãããŠããŸãããDACLã¯ãã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ãæåŠãããŠãããšå€æããŸãã ãããã£ãŠããŠãŒã¶ãŒã¯ãã®ãããªããã¥ã¡ã³ãã«ã¢ã¯ã»ã¹ã§ããŸããã ãã®ãããªå¶éã¯ããã¡ã€ã«ãŸãã¯ãã©ã«ããŒèªäœãžã®ã¢ã¯ã»ã¹ãçŠæ¢ãŸãã¯èš±å¯ãããã¯ãããžã«é¢ä¿ãªããçŠæ¢èŠåãèš±å¯èŠåãããåžžã«åªå ãããããã«çºçããå¯èœæ§ããããŸãã
éäžåã¢ã¯ã»ã¹ããªã·ãŒãæå®ããããšã§å°ãç解ã§ããŸããããçµç¹ã«éäžåã¢ã¯ã»ã¹ããªã·ãŒãå®è£ ããåã«æºããå¿ èŠãããäºåçãªèŠä»¶ãç¥ã£ãŠããããšããå§ãããŸãã ãããã®èŠä»¶ã«ã¯ã次ã®äºå®ãå«ãŸããŸãã
- é©åãªå±æ§ã䜿çšããŠããŠãŒã¶ãŒã¢ã«ãŠã³ããŸãã¯ã³ã³ãã¥ãŒã¿ãŒã®ãªããžã§ã¯ãã«æ¥ç¶ãããã¯ã¬ãŒã ãäœæããå¿ èŠããããŸãã
- ãŸãããã¡ã€ã«ããããã£å®çŸ©ãäœæããå¿ èŠããããŸãã
- ãã¡ãããããžãã¹èŠä»¶ã«å¿ããŠã1ã€ä»¥äžã®éäžã¢ã¯ã»ã¹ã«ãŒã«ãäœæããå¿ èŠããããŸãã
- å°ãªããšã1ã€ã®éäžåã¢ã¯ã»ã¹ããªã·ãŒãªããžã§ã¯ããäœæãããã®çµæããã®ãã©ã¡ãŒã¿ãŒãå®çŸ©ããå¿ èŠããããŸãã
- ã°ã«ãŒãããªã·ãŒã®æ©èœã䜿çšããŠããããã®ããªã·ãŒããã¡ã€ã«ãµãŒããŒã«æ¡åŒµããå¿ èŠããããŸãã ãããã£ãŠãWindows Server 2012/2012 R2ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãå®è¡ããŠãããã¡ã€ã«ãµãŒããŒã¯ãåçã¢ã¯ã»ã¹å¶åŸ¡ã®ååšãšãçµç¹å ã§éäžã¢ã¯ã»ã¹ããªã·ãŒãäœæãããŠããããšãæ¢ã«ç¥ã£ãŠããŸãã
- æåŸã«ã移è¡å ãµãŒããŒã§ããããã®ããªã·ãŒãéžæãããããªãã¯ãã©ã«ããŒã«é©çšããå¿ èŠããããŸãã
ãã®ã»ã¯ã·ã§ã³ã®å®éã®éšåã«ç§»ããActive DirectoryãµãŒããŒã®å šäœç®¡çã³ã³ãœãŒã«ãšããŒã«ã䜿çšããŠããã®ãããªãªããžã§ã¯ãã«å¯Ÿããéäžåã¢ã¯ã»ã¹ã«ãŒã«ãäœæãç·šéãè¿œå ãåé€ããæ¹æ³ãããã³éäžåã¢ã¯ã»ã¹ããªã·ãŒãªããžã§ã¯ããåé€ããæ¹æ³ãèŠãŠã¿ãŸãããWindows PowerShell
äžå€®ã¢ã¯ã»ã¹ããªã·ãŒãäœæãã
éäžã¢ã¯ã»ã¹ããªã·ãŒã®ç®¡çã«é¢é£ããã¿ã¹ã¯ã¯ãéäžã¢ã¯ã»ã¹ã«ãŒã«ã®å®è£ ã«é¢é£ããã¿ã¹ã¯ãšéåžžã«äŒŒãŠããŸãã 次ã®äŸã¯ããã®èšäºã§äœæããæåã®ã¢ã¯ã»ã¹ã«ãŒã«ã«åºã¥ããéäžåã¢ã¯ã»ã¹ããªã·ãŒã®äœæã瀺ããŠããŸãã ãã®ããããã®ãããªããªã·ãŒãäœæããã«ã¯ã次ã®æé ãå®è¡ããå¿ èŠããããŸãã
- Active DirectoryãµãŒããŒã®å
šäœç®¡çã³ã³ãœãŒã«ã§ãä»åºŠã¯[ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡]> [äžå€®ã¢ã¯ã»ã¹ããªã·ãŒ]ããŒãïŒ[ ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡]> [äžå€®ã¢ã¯ã»ã¹ããªã·ãŒ] ïŒã«ç§»åããããã¿ã€ã«ã§[äžå€®ã¢ã¯ã»ã¹ããªã·ãŒã® äœæ ]çŸåšã®ã³ã³ãœãŒã«ã®ããŒã ç»é¢ã§ã®åçã¢ã¯ã»ã¹å¶åŸ¡ã 次ã®å³ã«ç€ºãããã«ããã®ããŒãããã詳现ãã€ã³ããã³ã³ããã¹ãã¡ãã¥ãŒãåŒã³åºããã詳现ãã€ã³ããæ°èŠããã³äžå€®ã¢ã¯ã»ã¹ããªã·ãŒãªãã·ã§ã³ãéžæããŸãã
å³ 5.éäžã¢ã¯ã»ã¹ããªã·ãŒã®äœæ - ãã®åŸã ã äžå€®ã¢ã¯ã»ã¹ããªã·ãŒã®äœæ ããã€ã¢ãã°ããã¯ã¹ã§ãå°æ¥ã®ã¢ã¯ã»ã¹ããªã·ãŒã«å¿
èŠãªãã¹ãŠã®ãã©ã¡ãŒã¿ãŒãå®çŸ©ã§ããŸãã éäžåã¢ã¯ã»ã¹ã«ãŒã«ãäœæãŸãã¯å€æŽããããã®ãã€ã¢ãã°ããã¯ã¹ãšã¯ç°ãªãããã®ãããªããªã·ãŒãäœæããå Žåã次ã®2ã€ã®ã°ã«ãŒãã®ãã©ã¡ãŒã¿ãŒã®ã¿ãç·šéã§ããŸãã
- ã°ã«ãŒããäžè¬ã ïŒ äžè¬ ïŒã åã®ã±ãŒã¹ãšåæ§ã«ããããã¯ããªã·ãŒãé©åã«ç¹åŸŽä»ããããšãã§ããäžè¬çãªãã©ã¡ãŒã¿ãŒã§ãã ããã§ã¯ãé·ãéç¥ããç解ãããŠãã3ã€ã®ãã©ã¡ãŒã¿ãŒãå®çŸ©ã§ããŸãã
- ãåå äœæããŠããããªã·ãŒã®ããããããååãæå®ã§ããŸãã ãã®äŸã§ã¯ããã®ã«ãŒã«ã¯ã Los Angeles Marketers ããšåŒã°ããŸãã
- 説æ äœæäžã®ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡ãªããžã§ã¯ãã®äžè¬çãªèª¬æã ãã®ãã£ãŒã«ãã«ã¯ãã Los Angeles Marketers Access Rulesã䜿çšãã环ç©ããªã·ãŒ ãã衚瀺ãããŸãã
- 誀ã£ãåé€ã«å¯Ÿããä¿è·ïŒèª€ã£ãåé€ããä¿è·ããïŒ ã ç¥ããªãéã«äœæããéäžã¢ã¯ã»ã¹ããªã·ãŒã®åé€ãçŠæ¢ãããã©ã¡ãŒã¿ãŒã ãããŸã§ã®ãã¹ãŠã®ã±ãŒã¹ãšåæ§ã«ããã®ããã¯ã¹ã®ãã§ãã¯ãå€ãããšã¯ããã次ã®ãã©ã¡ãŒã¿ãŒã®ã°ã«ãŒããæ€èšããŸãã
- ã°ã«ãŒããã¡ã³ããŒã ã äœæãããäžå€®éäžåã¢ã¯ã»ã¹ããªã·ãŒã®ãã®ã°ã«ãŒãã§ã¯ããã®ããªã·ãŒã®ã¡ã³ããŒã«ãªãäžå€®éäžåã¢ã¯ã»ã¹ã«ãŒã«ãæå®ã§ããŸãã [ è¿œå ]ãã¿ã³ãã¯ãªãã¯ãããšãéäžåã¢ã¯ã»ã¹ã«ãŒã«ãè¿œå ããããã®ãã€ã¢ãã°ããã¯ã¹ãç®ã®åã«è¡šç€ºãããŸããå·ŠåŽã®å¯Ÿå¿ãããªã¹ããã1ã€ä»¥äžã®ã«ãŒã«ãéžæããå¿ èŠããããŸãïŒäžå³ãåç §ïŒã å¿ èŠãªã«ãŒã«ãéžæããããäºéå±±æ¬åŒ§ä»ãã®äžçªäžã®ãã¿ã³ãã¯ãªãã¯ããŠããã®ãããªã«ãŒã«ãè¿œå ãããã¢ã¯ã»ã¹ã«ãŒã«ã®ãªã¹ãã«ç§»åããŸãã ãšããã§ããã®ãã€ã¢ãã°ããã¯ã¹ããçŽæ¥ããŠã£ã¶ãŒãïŒããæ£ç¢ºã«ã¯ãã€ã¢ãã°ããã¯ã¹ïŒãåŒã³åºããŠãæ°ããäžå€®ã¢ã¯ã»ã¹ã«ãŒã«ãè¿œå ã§ããŸãã
ã¡ãªã¿ã«ãåå è ã®éäžåã¢ã¯ã»ã¹ã«ãŒã«ã®ã°ã«ãŒãã®[ æš©éç¶æ ]åã«ã¯ããã®ã«ãŒã«ã«é©çšãããéäžåã¢ã¯ã»ã¹ã«ãŒã«ã§äœ¿çšãããæš©éã®ãªã¹ãããããŸãã 次ã®å³ã§ãããããã«ãã Proposed ãããã³ã Current ãïŒ ProposedãCurrent ïŒã®å€ã¯ããã®ãããªèš±å¯ã®æå¹ãªå€ãšããŠæ©èœããŸãã
å³ 6.éäžåã¢ã¯ã»ã¹ããªã·ãŒãäœæããããã®ãã€ã¢ãã°ããã¯ã¹ - ã°ã«ãŒããäžè¬ã ïŒ äžè¬ ïŒã åã®ã±ãŒã¹ãšåæ§ã«ããããã¯ããªã·ãŒãé©åã«ç¹åŸŽä»ããããšãã§ããäžè¬çãªãã©ã¡ãŒã¿ãŒã§ãã ããã§ã¯ãé·ãéç¥ããç解ãããŠãã3ã€ã®ãã©ã¡ãŒã¿ãŒãå®çŸ©ã§ããŸãã
- [ OK]ãã¿ã³ãã¯ãªãã¯ããŠãäœæãããéäžåã¢ã¯ã»ã¹ããªã·ãŒãä¿åããŸãã
GUIã¡ãœããã§ã¯ããã¹ãŠãæ確ã§ãããããããè€éãªã¡ãœãããã€ãŸãWindows PowerShellã䜿çšããŠéäžåã¢ã¯ã»ã¹ããªã·ãŒãäœæããæ¹æ³ã«é²ã¿ãŸãããã åºæ¬çã«ãéäžåã¢ã¯ã»ã¹ããªã·ãŒã®æ©èœãšé£æºããã³ãã³ãã¬ããã¯ãWindows PowerShellã䜿çšããŠãªãœãŒã¹ããããã£ãªã¹ãã管çããæ¹æ³ã«äŒŒãŠããŸãã ã€ãŸãã1ã€ã®ã³ãã³ãã¬ããã®å©ããåããŠããã®ãã¹ãŠã®ã¡ã³ããŒã§éäžã¢ã¯ã»ã¹ããªã·ãŒãå®å šã«äœæããããšã¯ã§ããŸããã æåã«ããªããžã§ã¯ãèªäœãäœæãã次ã«2çªç®ã®ã³ãã³ãã¬ããã䜿çšããŠãäœæããããªã·ãŒã«å¿ èŠãªã¢ã¯ã»ã¹ã«ãŒã«ãè¿œå ããå¿ èŠããããŸãã
次ã®5ã€ã®Windows PowerShellã³ãã³ãã¬ããã䜿çšããŠããããã®ãªããžã§ã¯ããæäœã§ããããšãããããŸãããNew-ADCentralAccessPolicyãããã«ãããéäžã¢ã¯ã»ã¹ããªã·ãŒãªããžã§ã¯ãèªäœãäœæã§ããŸããSet-ADCentralAccessPolicyãæ¢åã®ããªã·ãŒã®å€æŽãæ åœãRemove-ADCentralAccessPolicyãããã«ãããå®éã«ã¯ãäžèŠãªã¢ã¯ã»ã¹ããªã·ãŒãšãAdd-ADCentralAccessPolicyMemberããã³Remove-ADCentralAccessPolicyMemberã³ãã³ãã¬ãããåé€ããŸããéžæããããªã·ãŒã«éäžã¢ã¯ã»ã¹ã«ãŒã«ãè¿œå ãŸãã¯åé€ããããã«èšèšãããŠããŸãã次ã®äŸã§ã¯ãæ°ããéäžåã¢ã¯ã»ã¹ããªã·ãŒãè¿œå ããããã«1ã€ã®ã¢ã¯ã»ã¹ã«ãŒã«ãè¿œå ã§ãã2ã€ã®ã³ãã³ãã¬ããã®ã¿ãèæ ®ãããŸãããã®ããããŸãæåã«ã次ã®ã³ãã³ãã¬ããã䜿çšããå¿ èŠããããŸããã芧ã®ãšããããã®ã³ãã³ãã¬ããã«åé¡ã¯ãªãã¯ãã§ããããã§ãNameãã©ã¡ãŒã¿ãŒã¯ã«ãŒã«ã®ååããDescription-説æã¯Serverãã©ã¡ãŒã¿ãŒã䜿çšããŠäœæãããã«ãŒã«ã®ã¿ãŒã²ãããµãŒããŒãæå®ã§ããProtectedFromAccidentalDeletionãã©ã¡ãŒã¿ãŒã䜿çšãããšäœæãããªããžã§ã¯ãã®ãã以äžã®åé€ãçŠæ¢ããŸãã
New-ADCentralAccessPolicy -description:"Just another CAP" -Name:"Test CAP" -Server:"DC.biopharmaceutic.local" -ProtectedFromAccidentalDeletion:$true
æãèå³æ·±ãéšåã¯ãäœæããã«ãŒã«ã«äžå åãããã¢ã¯ã»ã¹ã«ãŒã«ãè¿œå ãã段éããå§ãŸããŸãã2çªç®ã®ã³ãã³ãã§ã¯ãããªã·ãŒã«è¿œå ãããäžå€®ã¢ã¯ã»ã¹ã«ãŒã«ãæå®ããå¿ èŠããããŸãããã®ãããªã³ãã³ãã¯æ¬¡ã®ããã«ãªããŸãïŒããã«ã¯2ã€ã®ãã©ã¡ãŒã¿ãŒã®ã¿ã衚瀺ãããŸããã€ãŸãã以åã«äœæããã«ãŒã«ãæå®ã§ããIdentityãã©ã¡ãŒã¿ãŒãšãå¿ èŠãªãã¹ãŠã®éäžã¢ã¯ã»ã¹ã«ãŒã«ãã³ã³ãã§åºåã£ãŠæå®ããå¿ èŠãããMembersãã©ã¡ãŒã¿ãŒã§ããéåžžã©ãããã³ãã³ãã®å®è¡åŸã«èŠåã衚瀺ãããªãå Žåããã¹ãŠãæ£ããäœæãããŠããŸãããããã®ã³ãã³ãã®åºåäŸã以äžã«ç€ºããŸãã
Add-ADCentralAccessPolicyMember -Identity:"CN=Test CAP,CN=Central Access Policies,CN=Claims Configuration,CN=Services,CN=Configuration,DC=biopharmaceutic,DC=local" -Members:"CN= - ,CN=Central Access Rules,CN=Claims Configuration,CN=Services,CN=Configuration,DC=biopharmaceutic,DC=local" -Server:"DC.biopharmaceutic.local"
å³ 7. Windows PowerShellã䜿çšããŠéäžåã¢ã¯ã»ã¹ã«ãŒã«ãäœæãã
æ¢åã®éäžåã¢ã¯ã»ã¹ããªã·ãŒã®å€æŽãšåé€ã¯ããã®èšäºã§èª¬æãããã¹ãŠã®ã¿ã¹ã¯ã®äžã§æãç°¡åãªæäœã§ããå¯èœæ§ããããŸãããã®çµè«ã¯ãããããã£å€æŽã³ãã³ãã®å©ããåããŠãããã³ããªã·ãŒã®åé€äžã«æ°ãããã©ã¡ãŒã¿ãŸãã¯ããããã£ã«ééããªããšããçç±ã§äœæã§ããŸããç·šéæ¢åã®ã¢ã¯ã»ã¹ããªã·ãŒã«ãããªãã¯ãActive Directory管çã»ã³ã¿ãŒã«å¿ èŠãªããµã€ãã«ã¢ã¯ã»ã¹ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡>äžå€®ã¢ã¯ã»ã¹ããªã·ãŒãææã®ã¢ã¯ã»ã¹ããªã·ãŒãéžæããããããã®ã³ã³ããã¹ãã¡ãã¥ãŒããããŸãã¯ããã«ããã課é¡ãïŒã¿ã¹ã¯ïŒã³ãã³ããéžæãããããããã£ããïŒããããã£ïŒã
ããªãã¯ãåãã³ã³ããã¹ãã¡ãã¥ãŒãã¿ã¹ã¯ããŒããæ¢åã®éäžæ°ããã¢ã¯ã»ã¹ã«ãŒã«ã¢ã¯ã»ã¹ããªã·ãŒã«è¿œå ããå¿ èŠãããå Žåã¯ãŸããã¯ãªãã¯Â»éäžã¢ã¯ã»ã¹ã«ãŒã«ãè¿œå ãïŒè¿œå äžå€®ã¢ã¯ã»ã¹ã«ãŒã«ïŒããã®ãªãã·ã§ã³ãéžæãããšãéäžã¢ã¯ã»ã¹ããªã·ãŒãäœæããæé ã®ç¬¬2段éã§èª¬æããéäžã¢ã¯ã»ã¹ã«ãŒã«ãè¿œå ããããã®ãã€ã¢ãã°ããã¯ã¹ã衚瀺ãããŸãã
äžèŠãªéäžåã¢ã¯ã»ã¹ããªã·ãŒãåé€ããããšã§ãåé¡ãçºçããªããªããŸããåãããŒãã§ãããè¡ãã«ã¯ãäžå€®ã¢ã¯ã»ã¹ããªã·ãŒãç®çã®ãªããžã§ã¯ããéžæããã³ãã³ããå®è¡ãããåé€Â»ïŒåé€ããã³ã³ããã¹ãã¡ãã¥ãŒããïŒã
äžå€®ã¢ã¯ã»ã¹ããªã·ãŒãé åžãã
ãã¡ãããäžå€®éæš©çãªæ¿æ²»å®¶ã ãã§ã¯äœãåŸãããŸãããéçšãã¡ã€ã«ãµãŒããŒã§ãããã®äœ¿çšãéå§ããã«ã¯ãæåã«äžå çã«é åžããå¿ èŠããããŸããWindowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ã»ãšãã©ãã¹ãŠã®èšå®ã®é åžãèªååããæè¯ã®æ¹æ³ã¯ãã°ã«ãŒãããªã·ãŒã®æ©èœã䜿çšããããšã§ããçŸæç¹ã§ã¯ãã°ã«ãŒãããªã·ãŒã®å©ããåããŠãã·ã¹ãã ã®ã«ã¹ã¿ãã€ãºã«é¢ããŠæ³åã§ããã»ãšãã©ãã¹ãŠã®ããšãã§ããŸããããããã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ã«ããç¹å®ã®ã·ã¹ãã ãã©ã¡ãŒã¿ã§ããå Žåã¯ãäœåãã®ç®¡ççšãã³ãã¬ãŒããéçºãããŠããŸããã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ããå¿ èŠããããŸã-ããã«ã¯CSE GPSIæ¡åŒµããããŸãããã¹ã¯ãŒãããªã·ãŒã®å®çŸ©ãã·ã¹ãã ãµãŒãã¹ã®æ§æãã·ã¹ãã ã¬ãžã¹ããªãžã®ã¢ã¯ã»ã¹ã®å¶éããŸãã¯ããã°ã©ã ãžã®ã¢ã¯ã»ã¹ãå¶éããããªã·ãŒã®æ§æãªã©ãWindowsãã¡ã€ã¢ãŠã©ãŒã«ãŸãã¯IPSECã®ã«ãŒã«-Windowsæ§æããŒãããã®æ¢åã®ãã©ã¡ãŒã¿ãŒã圹ç«ã¡ãŸããç¹å®ã®ãœãããŠã§ã¢è£œåã®éäžæ§æãå®è¡ããå¿ èŠãããå Žåããã³ããŒã¯ã補åã®ç®¡ççšãã³ãã¬ãŒãããªãªãŒã¹ããããšã«ããããã§ã«å€ãã®äœæ¥ãè¡ã£ãŠããå¯èœæ§ããããŸããç®çã®ããªã·ãŒèšå®ãèŠã€ãããªãå Žåã§ããã°ã«ãŒãããªã·ãŒã®èšå®ããã€ã§ãå©çšã§ããŸããããã«ããããã¹ãç¯ããããé¢åãªã¹ã¯ãªãããæžãå¿ èŠããªããªããŸãã
ãããŠããã¡ããããã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡ãªã©ã®æè¡ã¯ãã°ã«ãŒãããªã·ãŒã®ã¯ã©ã€ã¢ã³ãåŽãæ¡å€§ããããšãªãããŠã¯ã§ããŸãããäœæãããã¹ãŠã®ã«ãŒã«ãšããªã·ãŒã¯æŠããŠActive Directoryãã¡ã€ã³ãµãŒãã¹ã«ä¿åããããããå¿ èŠãªã³ã³ãããŒãããã®ãããªãªããžã§ã¯ããåé€ãããããã§æå®ããããã©ã¡ãŒã¿ãŒãç¹å®ã®ã³ã³ãã¥ãŒã¿ãŒã«é åžããã ãã§ããèšèã§èšãã°ãããã¯éåžžã«åçŽã«èãããŸããããã®ãããªæé ãå®éã«äœã§ããããèŠãŠã¿ãŸãããã
ãã®ããã以åã«äœæããéäžåã¢ã¯ã»ã¹ããªã·ãŒããã¡ã€ã«ãµãŒããŒã«é åžããã«ã¯ã次ã®æé ãå®è¡ããå¿ èŠããããŸãã
- « » ( Group Policy Management ), , « Dynamic Access Control 01 », ;
- CSE . \\ Windows\ \ ( Computer Configuration \ Policies\Windows Settings \ Security Settings\File System ). Microsoft, , , « . 6: , , ». , Windows Server 2012, , « » ( Central Access Policy ) . , , , , « » ( Manage Central Access Policies⊠):
å³ 8. GPME - « » ( Central Access Policies Configuration ), . , , « » ( Available Central Access Policies ) ( , CTRL ), , « » ( Add ), « » ( Applicable Central Access Policies ):
å³ 9. - , .
ååãšããŠãéäžã¢ã¯ã»ã¹ããªã·ãŒã管çã§ããã°ã«ãŒãããªã·ãŒã®æ©èœã®ã©ã³ã¯ã«ã¯ã©ã€ã¢ã³ãåŽã®æ¡åŒµæ©èœãè¿œå ãããŠãããããæ§æããããªã·ãŒã¯ãã¬ããªã±ãŒã·ã§ã³ã«åå ãããã¹ãŠã®ãã¡ã€ã³ã³ã³ãããŒã©ãŒã®SYSVOLãã©ã«ããŒã«äœããã®åœ¢åŒã§ä¿åããå¿ èŠããããŸããããšãã°ãçæãããããªã·ãŒèšå®ããã¡ã€ã³ã³ã³ãããŒã©ãŒã§ããŒã«ã©ã€ãºããã«ã¯ããã©ã«ããŒCã«ç§»åããå¿ èŠããããŸãã\ Windows \ SYSVOL \ domain \ Policies \ {6DF180BA-22E3-4D52-A34F-158633E56956} \ Machine \ Microsoft \ Windows NT \ Capãããã§C ïŒ\ Windows \ SYSVOL \ domain \ Policiesã¯ããã¡ã€ã³ã§äœæããããã¹ãŠã®GPOããããã£ã¬ã¯ããªãžã®ãã¹{6DF180BA-22E3-4D52-A34F-158633E56956}ã§ããäœæããã³æ§æãããã°ããã®GPOèªäœã®GUIDïŒã°ã«ãŒãããªã·ãŒç®¡çãšãã£ã¿ãŒããçŽæ¥ãããããŒãã®ããããã£ãã€ã¢ãã°ãåŒã³åºãããšã§ç¢ºèªã§ããŸãïŒãããã³Machine \ Microsoft \ Windows NT \ Capã¯æ¢ã«æå®ãããããªã·ãŒèšå®ã決å®ããããã¡ã€ã«ã眮ãããŠãããã©ã«ããŒã
ãã®ãã£ã¬ã¯ããªã«ã¯ãcap.infãšåŒã°ããåäžã®.infãã¡ã€ã«ããããŸãïŒCentral Access Policyã®ç¥ïŒããã®ãã¡ã€ã«ã¯æå·åãããŠããªããããå¿ èŠã«å¿ããŠãã®å 容ã衚瀺ã§ããŸããããšãã°ãç§ã®å Žåããã®ãããªãã¡ã€ã«ã«ã¯æ¬¡ã®è¡ãå«ãŸããŸãã
[Version]
Signature = "$ Windows NT $"
[CAPS]
ãCN =ãã¹ãCAPãCN =ã»ã³ãã©ã«ã¢ã¯ã»ã¹ããªã·ãŒãCN =ã¯ã¬ãŒã æ§æãCN =ãµãŒãã¹ãCN =æ§æãDC =ãã€ãªå»è¬åãDC =ããŒã«ã«ã
"CN =ããµã³ãŒã«ã¹ããŒã±ã¿ãŒãCN =ã»ã³ãã©ã«ã¢ã¯ã»ã¹ããªã·ãŒãCN =ã¯ã¬ãŒã æ§æãCN =ãµãŒãã¹ãCN =æ§æãDC =ãã€ãªå»è¬åãDC =ããŒã«ã«Â»
ãã®ãããªãã¡ã€ã«ã®å 容ãããã¹ãŠãæ確ã§ããããã以äžè©³çŽ°ã«æ€èšãã¹ãã§ã¯ãªããšèããŠããŸãã倧ãŸãã«èšããšãã芧ã®ãšãããActive Directoryãã¡ã€ã³ãµãŒãã¹ã«æ ŒçŽãããŠããéäžã¢ã¯ã»ã¹ããªã·ãŒã®ååãšå Žæã決å®ããèå¥åãããã§èŠã€ããããšãã§ããŸãã
ãã®INFãã¡ã€ã«ã§ã¯ãããªã·ãŒã®ååãšãã®å Žæã®ã¿ãèŠã€ããããšãã§ããŸããã€ãŸãããã®ãããªãã¡ã€ã«ãåä¿¡ããåŸãã¢ã¯ã·ã§ã³ããŸã£ããå®è¡ãããªãå Žåããã®å Žåãã¯ã©ã€ã¢ã³ãã¯ã«ãŒã«ã¯èšããŸã§ããªãããã®ãããªããªã·ãŒãäœã§ããããåã«ç¥ããŸããããã®ããããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯ãããããã®ããªã·ãŒã®ç®çãšããªã·ãŒã§ã§ããããšãæ£ããç解ãããããã«ãäœããã®ã¢ã¯ã·ã§ã³ãåããã¡ã«ããºã ãå®è£ ããå¿ èŠããããŸãã幞ããªããšã«ãWindows Server 2012/2012 R2ã§ã¯ããã¹ãŠãããã«å®è£ ãããŠããŸããã°ã«ãŒãããªã·ãŒèšå®ãæŽæ°ããåŸãauditse.dllã·ã¹ãã ã©ã€ãã©ãªã¯ãéäžç®¡çãããã¢ã¯ã»ã¹ããªã·ãŒã«é¢ããå¿ èŠãªæ å ±ãINFãã¡ã€ã«ããèªã¿åãããããŠãLDAPã¯ãšãªãéããŠãã¯ã©ã€ã¢ã³ããµã€ãã®æ¡åŒµã«ãããã·ã¹ãã ã«å¿ èŠãªãã¹ãŠã®ããŒã¿ããã¡ã€ã³ãµãŒãã¹ããåä¿¡ãããã¿ãŒã²ããã³ã³ãã¥ãŒã¿ãŒã®ã·ã¹ãã ã¬ãžã¹ããªã«æžã蟌ãŸããŸãã
ãã®ãããªãã©ã¡ãŒã¿ãŒãããŒã«ã©ã€ãºããã³èª¿æ»ããå Žåã¯ãã¬ãžã¹ããªãšãã£ã¿ãŒã䜿çšããregerditãŠã£ã³ããŠã§HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Lsa \ CentralizedAccessPoliciesã»ã¯ã·ã§ã³ã«ç§»åããå¿ èŠããããŸãããŸããCAPEã»ã¯ã·ã§ã³ã«ã¯éäžåã¢ã¯ã»ã¹ã«ãŒã«ããããCAPã»ã¯ã·ã§ã³ã«ã¯éäžåã¢ã¯ã»ã¹ããªã·ãŒãæ åœãããã©ã¡ãŒã¿ãŒãããããšã«æ³šæããŠãã ãããããšãã°ãã«ãŒã«ãšã¢ã¯ã»ã¹ããªã·ãŒã®äž¡æ¹ã«ã€ããŠãNameãã©ã¡ãŒã¿ãŒãšDescriptionãã©ã¡ãŒã¿ãŒãèŠã€ããããšãã§ããŸããç¹å®ã®ãªããžã§ã¯ãã®ååãšèª¬æãããããæ åœããŸãã次ã®å³ã§ãããããã«ãã¬ãžã¹ããªã®ãã®ã»ã¯ã·ã§ã³ã§ã¯ããã©ã¡ãŒã¿ãŒãšå ±ã«é åžãããã¹ãŠã®éäžåã¢ã¯ã»ã¹ããªã·ãŒãå«ããµãããŒãèŠã€ããããšãã§ããŸãã
å³ 10.éäžåã¢ã¯ã»ã¹ããªã·ãŒããã³ã«ãŒã«ã®ç¹å®ã®ãã©ã¡ãŒã¿ãŒãå«ãã¬ãžã¹ããªã»ã¯ã·ã§ã³
ååãšããŠãããã2ã€ã®ã»ã¯ã·ã§ã³ã®åãã©ã¡ãŒã¿ãŒã«ã€ããŠèª¬æããããšã«ã¯ããŸãæå³ããªãã®ã§ããã®èšäºã§ã¯åçŽã«æ€èšããŸããã
äžå€®ã¢ã¯ã»ã¹ããªã·ãŒã®é©çš
éäžåã¢ã¯ã»ã¹ã«ãŒã«ã®äœæãéäžåã¢ã¯ã»ã¹ããªã·ãŒã®èšå®ãã«ãŒã«ãžã®è¿œå ãã°ã«ãŒãããªã·ãŒæ©èœã䜿çšããéäžåã¢ã¯ã»ã¹ããªã·ãŒã®é åžãªã©ãäžèšã®ãã¹ãŠã®æé ãå®äºãããããã®æé ã®æåŸã®éšåãå®äºã§ããŸããã€ãŸãããã¡ã€ã«ãµãŒããŒã§ãã¹ããããŠããã¿ãŒã²ãããã©ã«ããŒãŸãã¯ãã¡ã€ã«ãžã®éäžã¢ã¯ã»ã¹ããªã·ãŒã®é©çšã§ããã¬ãžã¹ããªã«ãã©ã¡ãŒã¿ãŒãäœæããçŽåŸã«ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯ç¹å®ã®éäžã¢ã¯ã»ã¹ã«ãŒã«ãšããªã·ãŒãããŒã«ã«ã»ãã¥ãªãã£ã·ã¹ãã ã«é åžããŸãã
éäžåã¢ã¯ã»ã¹ããªã·ãŒãé©çšããã«ã¯ã次ã®æé ãå®äºããå¿ èŠããããŸãã
- Windows , . « » ( Properties );
- «» ( Security ), , , «» ( Advanced );
- , «» , «» « » ( Permissions, Auditing, Effective Access ) « » ( Central Policy ), . .
, . , . , « -», , . , , , Active Directory . , . :
å³ 11. - , . , , SACL . , S-1-17, , , .
ãããã«
ãã®ããããã®èšäºã§ã¯ãåçã¢ã¯ã»ã¹å¶åŸ¡ã«ã€ããŠåŒãç¶ã説æããŸããã Active DirectoryãµãŒããŒã®å šäœç®¡çã³ã³ãœãŒã«ãšWindows PowerShellã®æ©èœã®äž¡æ¹ã䜿çšããŠãéäžåã¢ã¯ã»ã¹ã«ãŒã«ãšã¯äœãããã®ãããªã«ãŒã«ã管çããæ¹æ³ãåŠç¿ããŸãããããã«ããã®èšäºã§ã¯ãã¢ã¯ã»ã¹ã«ãŒã«ã®éåœãã€ãŸããäžå åãããã¢ã¯ã»ã¹ããªã·ãŒã®ã¡ã³ããŒã·ããã«ã€ããŠè©³ãã説æããŸããããŸãããããã®ããªã·ãŒã管çããæ¹æ³ãåŠã³ãŸããããŸããã°ã«ãŒãããªã·ãŒã䜿çšããŠãã®ãããªã¢ã¯ã»ã¹ããªã·ãŒã®é åžã«ã€ããŠåŠã¶ããšãã§ããŸãããŸãããã®èšäºã®æåŸã®å°ããªã»ã¯ã·ã§ã³ã§ã¯ãçæããã³é åžãããéäžã¢ã¯ã»ã¹ããªã·ãŒããã¡ã€ã«ãµãŒããŒã§ãã¹ããããã¿ãŒã²ãããã©ã«ããŒããã³ãã¡ã€ã«ã«é©çšããæ¹æ³ã«ã€ããŠèª¬æããŸããã
ãã®ã·ãªãŒãºã®æ¬¡åã®èšäºã§ã¯ãåçã¢ã¯ã»ã¹å¶åŸ¡æè¡ã®è©³çŽ°ãåŒãç¶ãæ€èšããæ¡ä»¶åŒãšææ¡ãããã¢ã¯ã»ã¹èš±å¯ãéäžåã¢ã¯ã»ã¹ããªã·ãŒã®äœ¿çšã®ããã€ãã®ãå®éã®ãäŸãããã³è°è«ããæéããªãã£ãä»ã®å€ãã®èå³æ·±ãç¹ã«ã€ããŠè©³ãã説æããŸããã®ãµã€ã¯ã«ã®æåã®5ã€ã®èšäºã§èšåããŠãã ããã