ç®æ¬¡
Active Directory (AD)ã¯ãçŸä»£ã®äŒæ¥ITã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãšã£ãŠæ¬ ãããªãèŠçŽ ã§ããActive Directoryã¯ãMicrosoftãWindowsãã¡ã€ã³ãããã¯ãŒã¯çšã«éçºãããã£ã¬ã¯ããªãµãŒãã¹ã§ããŠãŒã¶ãŒãã³ã³ãã¥ãŒã¿ã¢ã«ãŠã³ãããããã¯ãŒã¯ãªãœãŒã¹ãªã©ãæŽçã»ç®¡çããã®ã«äžå¯æ¬ ãªããŒã«ã§ãã
ADã¯ããããã¯ãŒã¯ã€ã³ãã©ã®é»è©±åž³ã®ãããªãã®ã§ãWindowsã³ã³ãã¥ãŒã¿åãã®äžå åãããèªèšŒã»æ¿èªãµãŒãã¹ãæäŸããŸããADã¯ããŠãŒã¶ãŒãæã£ãŠããèªèšŒæ å ±ãæ£ãããã©ããã確èªãïŒèªèšŒïŒããã®ãŠãŒã¶ãŒã®åœ¹å²ãã°ã«ãŒãã®ã¡ã³ããŒã·ããã«åºã¥ããŠãã¢ã¯ã»ã¹ã§ãããã¡ã€ã«ãã¢ããªã±ãŒã·ã§ã³ã決å®ïŒæ¿èªïŒããããã«èšèšãããŠããŸãã
ç°¡åã«èšãã°ãADã¯ã°ã«ãŒãããªã·ãŒç®¡çããã¡ã€ã³ãµãŒãã¹ãLDAPïŒLightweight Directory Access ProtocolïŒã®ãµããŒããšãã£ãäž»èŠãªæ©èœãšã³ã³ããŒãã³ããæäŸããŸãã
- ã°ã«ãŒãããªã·ãŒç®¡çã¯ã管çè ãè€æ°ã®ãã·ã³éã§ç¹å®ã®èšå®ãå®è¡ããããšãå¯èœã«ããŸãã
- ãã¡ã€ã³ãµãŒãã¹ã¯ãéå±€çãªçµç¹æ§é ãæäŸãã忣ãããã¯ãŒã¯ã«ããããŠãŒã¶ãŒãšããã€ã¹éã®çžäºäœçšã管çããã®ã«åœ¹ç«ã¡ãŸãã
- LDAPã®ãµããŒãã¯ãã€ã³ã¿ãŒããããä»ããç°ãªãçš®é¡ã®ãœãããŠã§ã¢éã®éä¿¡ãå¯èœã«ããŸãã
ADã¯ãäŒæ¥ã®ãããã¯ãŒã¯ç°å¢å šäœã®ã»ãã¥ãªãã£ã確ä¿ããªãããç§©åºãç¶æããäžã§éèŠãªåœ¹å²ãæãããŸããããã«ãããããŒã ã¯ãŠãŒã¶ãŒãã³ã³ãã¥ãŒã¿ã远å ããã€ã¹ããã®ä»ã®ãªãœãŒã¹ã1ã€ã®äžå€®ãã±ãŒã·ã§ã³ããå¹ççã«ç®¡çã§ããããã«ãªãããããã¯ãŒã¯ç®¡çãããå¹ççã«ãªããŸãã
ç¡æãã©ã€ã¢ã«
ç¡æãã©ã€ã¢ã«ã®ãç³ãèŸŒã¿æé
- åŒç€Ÿã®ãµã€ããŒã»ãã¥ãªã㣠ãšãã¹ããŒãã貎瀟ã«äŒºããã»ãã¥ãªãã£ç°å¢ãè©äŸ¡ããŠãè åšãªã¹ã¯ã蚺æããŸãã
- 24 æé以å ã«æå°éã®æ§æã§ã30 æ¥éãå©çšããã ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããŸãã
- ãã«ãŒããã€ã³ãã®ãã¯ãããžãŒãå®éã«ãäœéšããã ããŸãã
- çµç¹ãæã€ã»ãã¥ãªãã£ã®è匱æ§ã«é¢ããã¬ããŒãããæäŸããŸãããã®ã¬ããŒãã¯ããµã€ããŒã»ãã¥ãªãã£æ»æã®å¯Ÿå¿ã«çŽã¡ã«ã掻çšããã ãããšãã§ããŸãã
ãã©ãŒã ã«å¿ èŠäºé ããå ¥åã®äžããç³èŸŒã¿ãã ããã远ã£ãŠãæ åœè ãããé£çµ¡ãããŠããã ããŸãã
Proofpointã®æ åœè ããŸããªããé£çµ¡ããããŸãã
Active Directoryã®ä»çµã¿ãšç®ç
Active Directoryã¯ãã³ã³ãã¥ãŒã¿ããŠãŒã¶ãŒã¢ã«ãŠã³ããé£çµ¡å ãã°ã«ãŒããçµç¹åäœãå ±æãã©ã«ããªã©ããããã¯ãŒã¯å ã®ãããããªãœãŒã¹ãããªããžã§ã¯ãããšããŠæ å ±ãä¿åããŸãããªããžã§ã¯ãã¯ååãšå±æ§ã«ãã£ãŠåé¡ãããŸããæ å ±ã¯ãã¯ãšãªã®ããã©ãŒãã³ã¹ãåäžãããããã«æé©åãããæ§é åããŒã¿ã¹ãã¢ã«ä¿åããããããã¯ãŒã¯ãŠãŒã¶ãŒãå¿ èŠãªæ å ±ãç°¡åã«èŠã€ããŠå©çšã§ããããã«ããŸãã
ã€ãŸããActive Directoryã®ç®çã¯ãçµç¹ãéå°ãªITãªãœãŒã¹ã䜿çšããããšãªãããããã¯ãŒã¯ã®å®å šæ§ãšæŽçæŽé ãç¶æã§ããããã«ããããšã§ããActive Directoryãã¡ã€ã³ãµãŒãã¹ã¯ãWindowsãã¡ã€ã³ã«ãããäž»èŠãªãã£ã¬ã¯ããªãµãŒãã¹ã§ããããããã¯ãŒã¯ã«æ¥ç¶ããããŠãŒã¶ãŒããµãŒãã¹ãããã€ã¹ã«é¢ããæ å ±ãéå±€æ§é ã«æ ŒçŽãã管çãã圹å²ãæ ã£ãŠããŸãã
Active Directoryãã¡ã€ã³ãµãŒãã¹ãšã¯ïŒ
Active Directory ãã¡ã€ã³ãµãŒãã¹ïŒAD DSïŒãšã¯ãMicrosoftã®Active Directoryã®ããã¯ããŒã³ã®ãããªãã®ã§ãäŒæ¥ãçµç¹ã䜿çšãã忣ãããã¯ãŒã¯å ã®ãŠãŒã¶ãŒãšããã€ã¹éã®çžäºäœçšã管çããŸããADãã¡ã€ã³ãµãŒãã¹ã«ã¯ããã¡ã€ã³ãšãŠãŒã¶ãŒã®éä¿¡ãå¯èœã«ããéäžåãã£ã¬ã¯ããªãå«ãŸããŠããŸãããããã¯ãŒã¯ã«æ¥ç¶ããããŠãŒã¶ãŒããµãŒãã¹ãããã€ã¹ã®æ å ±ãéå±€æ§é ã§ä¿åã»ç®¡çããŸãã
ADãã¡ã€ã³ãµãŒãã¹ã¯ãããŒã¿ãéå±€çãªçµç¹æ§é ã§æ ŒçŽããããã®æ§é åãããæ¹æ³ãæäŸããããšã§ã ãããã¯ãŒã¯éçšã®ç®¡çãæ¯æŽãã管çè ãåããããã¯ãŒã¯å ã®ç°ãªã ãã¡ã€ã³ã«ãŸããããŠãŒã¶ãŒã®ã¢ã¯ã»ã¹æš©ãã·ã¹ãã æ§æã管çããããããŸããADãã¡ã€ã³ãµãŒãã¹ã¯ãŸãããã°ã€ã³æ©èœãèªèšŒãããã£ã¬ã¯ããªãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããããšã§ãã»ãã¥ãªãã£ãçµ±åããŸããããã¯ã以äžã®äž»èŠãªæ©èœã«ãã£ãŠå®çŸããŸãã
- ãŠãŒã¶ãŒèªèšŒïŒ ADãã¡ã€ã³ãµãŒãã¹ã¯ããããã¯ãŒã¯äžã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããåã«ãŠãŒã¶ãŒãèªèšŒããèš±å¯ãããå人ã ããã·ã¹ãã ã®ç¹å®ã®éšåã«ã¢ã¯ã»ã¹ã§ããããã«ããŸãã
- ããŒã¿ã¹ãã¬ãŒãžïŒ ãŠãŒã¶ãŒåããã¹ã¯ãŒããé»è©±çªå·ãªã©ã®ãã£ã¬ã¯ããªããŒã¿ãä¿åããçµç¹å ã®ãªãã¬ãŒã·ã§ã³ã®åçåãæ¯æŽããŸãã
- ããªã·ãŒã®å®æœïŒ ã°ã«ãŒãããªã·ãŒãªããžã§ã¯ãïŒGPOïŒã«ããã管çè ã¯äžåºŠã«è€æ°ã®ãã·ã³ã«ã»ãã¥ãªãã£ããªã·ãŒãé©çšããããšãã§ããŸããçµæãé«ã¬ãã«ã®ã»ãã¥ãªãã£ãç¶æããªãããæéãç¯çŽã§ããŸãã
Active Directoryãã¡ã€ã³ãµãŒãã¹ã«ã¯è€æ°ã®ãµãŒãã¹ãçµ±åãããŠããããã®äžã«ã¯ãã¡ã€ã³ã³ã³ãããŒã©ãŒãå«ãŸããŸãããã¡ã€ã³ã³ã³ãããŒã©ãŒã¯ãADãã¡ã€ã³ãµãŒãã¹ã®åœ¹å²ãæãããµãŒããŒã§ãããWindowsã®ãã¡ã€ã³åãããã¯ãŒã¯å ã®å šãŠã®ãŠãŒã¶ãŒãšã³ã³ãã¥ãŒã¿ãèªèšŒããã³æ¿èªãããœãããŠã§ã¢ã®ã€ã³ã¹ããŒã«ãã¢ããããŒããå«ããå šããã€ã¹ã«å¯Ÿããã»ãã¥ãªãã£ããªã·ãŒãå²ãåœãŠãŠæœè¡ããŸãã
Active Directoryã®æ§æèŠçŽ
Active Directoryã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ãå¹ççãªãããã¯ãŒã¯éçšã®ããã«ã·ãŒã ã¬ã¹ã«é£æºããè€æ°ã®èŠçŽ ã§æ§æãããŠããŸãã
- ãã¡ã€ã³ïŒ ã³ã³ãã¥ãŒã¿ããŠãŒã¶ãŒãªã©ããã¹ãŠã®ãªããžã§ã¯ãã管çäžã«çœ®ãããè«çã°ã«ãŒã
- ãã©ã¬ã¹ãïŒ å ±éã®ã¹ããŒããå ±æããããé£ç¶ããããŒã ã¹ããŒã¹ã圢æããªãè€æ°ã®ããªãŒã®éãŸã
- ããªãŒïŒ ä¿¡é Œé¢ä¿ã§çµã°ãã1ã€ä»¥äžã®ãã¡ã€ã³ãå«ãéå±€çãªé 眮
- çµç¹åäœïŒOUïŒïŒ ãã¡ã€ã³å ã®ã³ã³ãããªããžã§ã¯ãã§ããŠãŒã¶ãŒãã°ã«ãŒããã³ã³ãã¥ãŒã¿ãªã©ã®ãªããžã§ã¯ããå«ã
- ã°ã«ãŒãããªã·ãŒïŒ çµç¹å ã§ã®ã³ã³ãã¥ãŒã¿ããŠãŒã¶ãŒã®æäœæ¹æ³ãå®çŸ©ããèšå®ã®éãŸã
ãã¡ã€ã³ã¯ãããã¯ãŒã¯ãªããžã§ã¯ããã°ã«ãŒãåããã»ãã¥ãªãã£ããªã·ãŒãé©çšããŸãããã©ã¬ã¹ãã¯ãã¡ã€ã³ããªãŒãå«ã¿ãåäžã®ã¹ããŒããšããŒã¿æ§æãå ±æããŸããããªãŒã¯é¢é£ãããã¡ã€ã³ã®éãŸãã§ããªãœãŒã¹ã®å ŽæãåçŽåããŸããOUã¯ãã¡ã€ã³å ã®ã³ã³ããã§ã管çã¿ã¹ã¯ãåçŽåããŸãããããã®èŠçŽ ã調åããŠæ©èœããããšã§ãActive Directoryã®å¹çãšããã©ãŒãã³ã¹ãæé©åãããŸãã
Active Directoryå°å ¥ã¡ãªãã
Active Directoryã¯åãªãçµ±åãã£ã¬ã¯ããªãµãŒãã¹ã§ã¯ãªããITãªãã¬ãŒã·ã§ã³ã®ç°¡çŽ åãšãããã¯ãŒã¯ã»ãã¥ãªãã£ã®åŒ·åãç®æãçµç¹ã«ãšã£ãŠãããããã®ãªãè³ç£ãšãªããŸãããŸããADã«ã¯ããã€ãã®éèŠãªã¡ãªããããããŸãã
ãŠãŒã¶ãŒç®¡çã®åçå
ADã¯ããããã¯ãŒã¯å šäœã§ãŠãŒã¶ãŒãäœæã倿Žãåé€ããããã®äžå åããããã©ãããã©ãŒã ãæäŸããããšã§ããŠãŒã¶ãŒã¢ã«ãŠã³ã管çãç°¡çŽ åããŸãããããã¯ãŒã¯å ã®åã ã®ãã·ã³ã«æåã§ä»å ¥ããå¿ èŠããªããªããŸãã
ãããã¯ãŒã¯ã»ãã¥ãªãã£ã®åŒ·å
ADã®åŒ·åºãªã»ãã¥ãªãã£æ©èœã¯ããµã€ããŒè åšããæ©å¯ããŒã¿ãä¿è·ããŸããã°ã«ãŒãããªã·ãŒãšã¢ã¯ã»ã¹ã³ã³ãããŒã«ã¯ã峿 Œãªãã¹ã¯ãŒãèŠä»¶ã宿œãã瀟å ã§ã®åœ¹å²ã«åºã¥ããŠãç¹å®ã®ãã¡ã€ã«ãã¢ããªã±ãŒã·ã§ã³ãžã®ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ãå¶éããŸãã
ãªãœãŒã¹å ±æã®ç°¡çŽ å
ADã䜿çšãããšãããªã³ã¿ãŒããã¡ã€ã«ãªã©ã®ãªãœãŒã¹ããããã¯ãŒã¯å šäœã§å ±æããã®ãæ Œæ®µã«ç°¡åã«ãªããŸãã管çè ã¯ãããã®ãªãœãŒã¹ãäžå çã«ç®¡çãã远å ã®ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããããšãªãããã¹ãŠã®ãŠãŒã¶ãŒãå©çšã§ããããã«ããããšãã§ããŸãã
ããè¯ãã°ã«ãŒãããªã·ãŒã®å®è£
ADã®ã°ã«ãŒãããªã·ãŒæ©èœã«ããã管çè ã¯ã·ã¹ãã åäœãã·ã¹ãã äžã§ã®ãŠãŒã¶ãŒæŽ»åãã³ã³ãããŒã«ã§ããŸãããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®èšå®ããUSBããŒãã®ç¡å¹åã«è³ããŸã§ãã»ãã¥ãªãã£ã匷åããææ®µãã°ã«ãŒãããªã·ãŒã«ãã£ãŠç°¡åãã€å¹æçã«å®æœã§ããŸãã
ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã®è¿ éå
åé¡ãçºçããå ŽåãADã®ãããªæŽçãããã·ã¹ãã ãããã°ããŠãŒã¶ãŒã®ã¢ã¯ãã£ããã£ãã·ã¹ãã ã€ãã³ãã«é¢ãã詳现ãªãã°ãæäŸããããšã§ãåé¡ãè¿ éã«èšºæããããšãã§ããŸãã
Active Directoryã®ã»ãã¥ãªãã£å¯Ÿç
Active Directoryã®ã»ãã¥ãªãã£ã¯ãèªèšŒãæ¿èªããããã¯ãŒã¯ã¢ã¯ã»ã¹ãªã©ãå€ãã®èåŒ±ãªæ©èœã®äžå¿ç圹å²ãæ ã£ãŠãããããç¹ã«ãµã€ããŒã»ãã¥ãªãã£ããŒã ã«ãšã£ãŠéèŠãªçŠç¹ãšãªã£ãŠããŸããActive Directoryã®ã»ãã¥ãªãã£å¯Ÿçã¯ããŠãŒã¶ãŒèªèšŒæ å ±ãæ©å¯ããŒã¿ããœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ãçµç¹ã·ã¹ãã ãäžæ£ã¢ã¯ã»ã¹ããä¿è·ããããã«äžå¯æ¬ ã§ãã
以äžã«ãActive Directoryã®ã»ãã¥ãªãã£å¯Ÿçã®ãã¹ããã©ã¯ãã£ã¹ãã玹ä»ããŸãã
ãã¡ã€ã³ã³ã³ãããŒã©ãŒãä¿è·ãã
ãã¡ã€ã³ã³ã³ãããŒã©ãŒã¯ããŠãŒã¶ãŒåããã¹ã¯ãŒãããã®ä»ã®èªèšŒæ å ±ãä¿åããŒã¿ãšç §åããŠãŠãŒã¶ãŒãèªèšŒãããµãŒããŒã§ãããŸããæ§ã ãªITãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹èŠæ±ãæ¿èªïŒãŸãã¯æåŠïŒããŸãã匷åãªãã¹ã¯ãŒããå®è£ ããäžèŠãªãµãŒãã¹ãç¡å¹ã«ãããã¡ã€ã¢ãŠã©ãŒã«ã䜿ã£ãŠå€éšã®è åšããä¿è·ããããšã«ãã£ãŠããã¡ã€ã³ã³ã³ãããŒã©ãŒãä¿è·ããªããã°ãªããŸããã
ãã¹ã¯ãŒãä¿è·ããªã·ãŒãšå€èŠçŽ èªèšŒãå®è£ ãã
匷åãªãã¹ã¯ãŒããšå€èŠçŽ èªèšŒã¯ãADãžã®äžæ£ã¢ã¯ã»ã¹ã®é²æ¢ã«åœ¹ç«ã¡ãŸããè€éãªãã¹ã¯ãŒããäœæãã宿çã«å€æŽãããã¹ãŠã®ç¹æš©ã¢ã«ãŠã³ãã«å€èŠçŽ èªèšŒã䜿çšããŸãã
管çè ã¢ã¯ã»ã¹ãå¶éãã
ãã£ã¬ã¯ããªãžã®äžæ£ãªå€æŽãé²ãããã«ãADãžã®ç®¡çè ã¢ã¯ã»ã¹ãå¶éããŸããæš©éãäžããããæ åœè ã®ã¿ã管çè ã¢ã¯ã»ã¹ãæã€ã¹ãã§ãããããŠã管çè ã¢ã«ãŠã³ãã宿çã«ç£æ»ããŸãããããã®æš©éãå¶éããããšã§ãçµç¹ã®ãããã¯ãŒã¯å ã®æœåšçãªæ»æãã¯ãã«ãæžããããšãã§ããŸãã
Active Directoryãç£èŠãç£æ»ãã
ADã®ç£èŠãšç£æ»ã¯ãã»ãã¥ãªãã£äŸµå®³ã®æ€åºãšé²æ¢ã«åœ¹ç«ã¡ãŸããçµç¹ã¯ããŠãŒã¶ãŒã¢ã«ãŠã³ããã°ã«ãŒãã¡ã³ããŒã·ãããã¢ã¯ã»ã¹èš±å¯ãªã©ããã¹ãŠã®Active Directoryã®å€æŽãç£èŠããã³ç£æ»ããå¿ èŠããããŸããMicrosoftã®Advanced Threat Analytics (ATA)ã®ãããªç£æ»ããŒã«ã¯ãæœåšçãªè åšã䟵害ã瀺ãäžå¯©ãªæŽ»åãç°åžžãç£èŠããŸããç£æ»ãã°ã宿çã«èŠçŽãããšã§ãã·ã¹ãã ãžã®æ»æã®è©Šã¿ã瀺ããã¿ãŒã³ãåŸåãç¹å®ããããšãã§ããŸãã
ææ°ã®Active Directoryãç¶æãã
ADã«ææ°ã®ã»ãã¥ãªãã£ããããã¢ããããŒããé©çšããŠããããšã¯ãã»ãã¥ãªãã£äŸµå®³ã®é²æ¢ã«åœ¹ç«ã¡ãŸããçµç¹ã¯ãã»ãã¥ãªãã£ããªã·ãŒãšæé ã宿çã«èŠçŽããæŽæ°ããå¿ èŠããããŸãã
ãããã®ãã¹ããã©ã¯ãã£ã¹ã宿œããããšã§ãçµç¹ã¯ADã®ã»ãã¥ãªãã£äœå¶ã匷åããITã€ã³ãã©ãžã®ãªã¹ã¯ãæå°éã«æããããšãã§ããŸãã
Active Directory:äŒæ¥ã®ãªãœãŒã¹ç®¡ç
Active Directoryã¯ãä¿åãããããŒã¿ãæŽçãæé©åããã»ãã¥ã¢ã«ä¿ã€ç©¶æ¥µã®ãã£ã¬ã¯ããªãµãŒãã¹ã§ããActive Directoryãã¡ã€ã³ãµãŒãã¹ã«ãããITããŒã ã¯ãã¡ã€ã³ãšãµããã¡ã€ã³ã®éå±€ãäœæãããŠãŒã¶ãŒèªèšŒãæš©éä»äžããªãœãŒã¹ç®¡çã容æã«ããããšãã§ããŸãã
ADå°å ¥ã®ã¡ãªããã«ã¯ãã»ãã¥ãªãã£ã®åäžã管çã®ç°¡çŽ åãæ¡åŒµæ§ã®åäžãªã©ããããŸãããããããŒã ã¯ã匷åºãªãã¹ã¯ãŒãããªã·ãŒã宿çãªã¢ãã¿ãªã³ã°ãšãã£ããã¹ããã©ã¯ãã£ã¹ã宿œããç°å¢ãå®å šã«ä¿ã€å¿ èŠããããŸããADã®ãã«ãã¬ãã«æ§é ãšå€ãã®èŠçŽ ãçè§£ããããšã¯è€éã§ããããã®é©åãªå®è£ ã¯å¹ åºãçµç¹ã«å€ãã®å©ç¹ããããããŸãã