Windows Server 2008 R2ã®Active Directoryãã¡ã€ã³ãµãŒãã¹ã®ç£æ»
ITç°å¢ã¯éçã§ã¯ãããŸããã 远跡ããã³èšé²ãå¿
èŠãªã·ã¹ãã ã§ã¯ãæ¯åæ°åã®å€æŽãçºçããŸãã æ§é ã®ãµã€ãºãšè€éãã倧ããã»ã©ã管çããã³ããŒã¿é瀺ã®ãšã©ãŒã®å¯èœæ§ãé«ããªããŸãã å€æŽã®ç¶ç¶çãªåæïŒæåãŸãã¯å€±æïŒããªããã°ãçã«å®å
šãªç°å¢ãæ§ç¯ã§ããŸããã 管çè
ã¯ã誰ãããã€ãäœãå€æŽãããã®ãã誰ã«æš©éãå§ä»»ãããã®ããå€æŽã®å Žåã«äœãèµ·ãã£ãã®ãïŒæåãŸãã¯å€±æïŒãå€ããã©ã¡ãŒã¿ãŒãšæ°ãããã©ã¡ãŒã¿ãŒã®å€ãã·ã¹ãã ã«ãã°ã€ã³ããããã¢ã¯ã»ã¹ã§ããªãã£ã人ãåé€ãã人ã«åžžã«çããå¿
èŠããããŸãããŒã¿ãªã©ã å€æŽã®ç£æ»ã¯ITã€ã³ãã©ã¹ãã©ã¯ãã£ç®¡çã®äžå¯æ¬ ãªéšåã«ãªããŸããããå€ãã®å Žåãæè¡çãªåé¡ã«ãããçµç¹ã¯åžžã«ç£æ»ã«æ³šæãæã£ãŠããŸããã çµå±ã®ãšãããäœãã©ã®ããã«ç£èŠããããå®å
šã«æ確ã§ã¯ãªãããã®åé¡ã®ããã¥ã¡ã³ããåžžã«åœ¹ç«ã€ãšã¯éããŸããã 远跡ããå¿
èŠãããã€ãã³ãã®æ°ã¯ãããèªäœããã§ã«è€éã§ãããããŒã¿éãå€ããæšæºããŒã«ã¯äŸ¿å©ã§ã¯ãªãã远跡ã¿ã¹ã¯ãç°¡çŽ åã§ããŸããã ã¹ãã·ã£ãªã¹ãã¯ãç£æ»ãåå¥ã«æ§æããæé©ãªç£æ»ãã©ã¡ãŒã¿ãŒãèšå®ããå¿
èŠããããŸããããã«ãçµæãåæããéžæããã€ãã³ãã«é¢ããã¬ããŒããäœæããå¿
èŠããããŸãã Active Directory / GPOãExchange ServerãMS SQL Serverãä»®æ³ãã·ã³ãªã©ãããã€ãã®ãµãŒãã¹ããããã¯ãŒã¯äžã§å®è¡ãããŠãããããéåžžã«å€ãã®ã€ãã³ããçæãããããã説æã ãã§ã¯æ¬åœã«å¿
èŠãªãã®ãéžæããããšã¯éåžžã«å°é£ã§ãã
ãã®çµæã管çè
ã¯ããã¯ã¢ããã¢ã¯ãã£ããã£ãååã§ãããšèŠãªããåé¡ãçºçããå Žåã«å€ãèšå®ã«ããŒã«ããã¯ããããšã奜ã¿ãŸãã ç£æ»ãå®æœãã決å®ã¯ãå€ãã®å Žåãé倧ãªã€ã³ã·ãã³ãã®åŸã«ã®ã¿è¡ãããŸãã 次ã«ã
äŸãšããŠWindows Server 2008 R2ã䜿çšããŠActive Directoryç£æ»ãæ§æãã
æ¹æ³ãèŠãŠãããŸã
ãActive Directoryç£æ»
Windows Server 2008ã§ã¯ã以åã®Windows Server 2003ãšæ¯èŒããŠãã»ãã¥ãªãã£ããªã·ãŒã§æ§æãããç£æ»ãµãã·ã¹ãã æ©èœãæŽæ°ãããç£èŠãã©ã¡ãŒã¿ãŒã®æ°ã53å¢å ããŸããWindowsServer 2003ã§ã¯ããã£ã¬ã¯ããªãµãŒãã¹ã€ãã³ãã®ç£æ»ã®å
å«ããã³éã¢ã¯ãã£ãåãå¶åŸ¡ãããã£ã¬ã¯ããªãµãŒãã¹ã¢ã¯ã»ã¹ç£æ»ããªã·ãŒã®ã¿ããããŸããã ããã§ãã«ããŽãªã¬ãã«ã§ç£æ»ã管çã§ããŸãã ããšãã°ãActive Directoryç£æ»ããªã·ãŒã¯4ã€ã®ã«ããŽãªã«åãããŠãããããããã«ç¹å®ã®ãã©ã¡ãŒã¿ãŒãæ§æãããŠããŸãã
-
ãã£ã¬ã¯ããªãµãŒãã¹ã¢ã¯ã»ã¹ ïŒ
ãã£ã¬ã¯ããªãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ ïŒ;
-
ãã£ã¬ã¯ããªãµãŒãã¹ã®å€æŽ ïŒãã£ã¬ã¯ããªãµãŒãã¹ã®å€æŽïŒ;
-
ãã£ã¬ã¯ããªãµãŒãã¹ã¬ããªã±ãŒã·ã§ã³ ïŒãã£ã¬ã¯ããªãµãŒãã¹ã¬ããªã±ãŒã·ã§ã³ïŒ;
-
詳现ãªãã£ã¬ã¯ããªãµãŒãã¹ã¬ããªã±ãŒã·ã§ã³ ã
ã°ããŒãã«ç£æ»ããªã·ãŒããã£ã¬ã¯ããªãµãŒãã¹ã¢ã¯ã»ã¹ã®ç£æ»ããæå¹ã«ãããšããã£ã¬ã¯ããªãµãŒãã¹ããªã·ãŒã®ãã¹ãŠã®ãµãã«ããŽãªãèªåçã«ã¢ã¯ãã£ãã«ãªããŸãã
Windows Server 2008ã®ç£æ»ã·ã¹ãã ã¯ããªããžã§ã¯ãã®äœæãå€æŽã移åãããã³åŸ©å
ã®ãã¹ãŠã®è©Šè¡ã远跡ããŸãã å€æŽãããå±æ§ã®ä»¥åããã³çŸåšã®å€ãšãæäœãå®è¡ãããŠãŒã¶ãŒã®ã¢ã«ãŠã³ãããã°ã«èšé²ãããŸãã ãã ããå±æ§ã®ãªããžã§ã¯ããäœæãããšãã«ããã©ã«ãã®ãã©ã¡ãŒã¿ãŒã䜿çšãããå Žåããããã®å€ã¯ãã°ã«èšé²ãããŸããã
泚ïŒWindows Server 2003ã§ã¯ãç£æ»ã¯å€æŽãããå±æ§ã®ååã®ã¿ãç»é²ããŸãããWindows Server 2008 R2ã§ã¯ãç£æ»ã¯æ¬¡ã䜿çšããŠå®è£
ãããŸãã
-ã°ããŒãã«ç£æ»ããªã·ãŒïŒGAPïŒ;
-ã·ã¹ãã ã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒSACLïŒ-ç£æ»ãå®è¡ãããæäœãå®çŸ©ããŸãã
-ã¹ããŒã -ã€ãã³ãã®ãªã¹ãã®æçµçãªåœ¢æã«äœ¿çšãããŸãã
ããã©ã«ãã§ã¯ãã¯ã©ã€ã¢ã³ãã·ã¹ãã ã®ç£æ»ã¯ç¡å¹ã«ãªã£ãŠããããµãŒããŒã·ã¹ãã ã®å Žåã
Active Directoryãã£ã¬ã¯ããªãµãŒãã¹ãµãã«ããŽãªãã¢ã¯ãã£ãã«ãªã£ãŠãããæ®ãã¯ç¡å¹ã«ãªã£ãŠããŸãã ã°ããŒãã«ããªã·ãŒãç£æ»ãã£ã¬ã¯ããªãµãŒãã¹ã¢ã¯ã»ã¹ããæå¹ã«ããã«ã¯
ãã°ã«ãŒãããªã·ãŒç®¡çãšãã£ã¿ãŒãåŒã³åºããŠã
ã»ãã¥ãªãã£èšå®/ããŒã«ã«ããªã·ãŒ/ç£æ»ããªã·ãŒãã©ã³ãã«ç§»åããå¿
èŠããããŸããããã§ãããªã·ãŒãã¢ã¯ãã£ãã«ããå¶åŸ¡ã€ãã³ãïŒæåã倱æïŒãèšå®ã§ããŸãã
å³1ãã£ã¬ã¯ããªãµãŒãã¹ã¢ã¯ã»ã¹ç£æ»ããªã·ãŒã®æå¹å2çªç®ã®æ¹æ³ã¯ãèšå®ã«
auditpolã³ãã³ãã©ã€ã³ãŠãŒãã£ãªãã£ã䜿çšããŠããã©ã¡ãŒã¿ãŒãèšå®ãããå®å
šãªGAPãªã¹ããååŸããããšã§ãã
auditpolã§ã¯ ã次ã®ã³ãã³ããå
¥åããŸãã
> auditpol /list /subcategory:*
å³2 auditpolã䜿çšããŠã€ã³ã¹ããŒã«ã®ãªã¹ããååŸããããªã·ãŒ
ããã£ã¬ã¯ããªãµãŒãã¹ã¢ã¯ã»ã¹ããã¢ã¯ãã£ãã«ã
ãŸã ã
> auditpol /set /subcategory:"directory service changes" /success:enable
泚ïŒã³ãã³ãã«é¢ãã詳现æ
å ±ã¯ã次ã®ã³ãã³ããå®è¡ããŠååŸã§ããŸãã
auditpol / håŸ
æ©ããªãããã«ããã¡ã€ã³ã³ã³ãããŒã©ãŒããªã·ãŒãæŽæ°ããŸãã
> gpupdate
ç£æ»ããªã·ãŒã®ãµãã«ããŽãª
ãã£ã¬ã¯ããªãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ã«ãããã³ãŒã
4662ã®ã»ãã¥ãªãã£ãã°ã«ã€ãã³ããçæãããŸããããã¯ãã€ãã³ããã¥ãŒã¢ã³ã³ãœãŒã«ã®[
Windowsãã°-ã»ãã¥ãªã㣠]ã¿ãã䜿çšããŠè¡šç€ºã§ããŸãã
å³3ã€ãã³ããã¥ãŒã¢ãŒãšã€ãã³ããã¥ãŒã¢ãŒã€ãã³ãã衚瀺ãã代ããã«ãPowerShell Get-EventLogã³ãã³ãã¬ããã䜿çšã§ããŸãã äŸïŒ
PS> Get-EventLog security | ?{$_.eventid -eq 4662}
泚ïŒGet-EventLogã³ãã³ãã¬ããã¯ãç¹å®ã®æ¡ä»¶ïŒAfterãAsBaseObjectãAsStringãBeforeãComputerNameãEntryTypeãIndexãInstanceIDãListãLogNameãMessageãNewestãSourceãããã³UserNameïŒã«åŸã£ãŠã€ãã³ãããã£ã«ã¿ãŒåŠçãã14ã®ãã©ã¡ãŒã¿ãŒãåãå
¥ããããšãã§ããŸããå³4 Get-EventLogã䜿çšããŠã€ãã³ãã®ãªã¹ããååŸããããã«ãããã€ãã®ä»ã®ã€ãã³ã
5136 ïŒå±æ§å€æŽïŒã
5137 ïŒå±æ§äœæïŒã
5138 ïŒå±æ§åé€ã®ãã£ã³ã»ã«ïŒãããã³
5139 ïŒå±æ§ã®ç§»åïŒãèšé²ãããŸãã
䟿å®äžãã€ãã³ããã¥ãŒã¢ãŒã³ã³ãœãŒã«ã§ç¹å®ã®ã€ãã³ããéžæããã«ã¯ããã£ã«ã¿ãŒãšã«ã¹ã¿ã ãã¥ãŒãããã³ä»ã®ãµãŒããŒãããã°ããŒã¿ãåéã§ãããµãã¹ã¯ãªãã·ã§ã³ã䜿çšããŸãã
è¡š1. Windows Server 2008ã®Active Directoryã€ãã³ãç£æ»ã€ãã³ãã®ãªã¹ã
è³æ ŒèšŒæã®æ€èšŒ
IDã¡ãã»ãŒãž
4774ã¢ã«ãŠã³ãã¯ãã°ã€ã³ã«ããããããŸããã
4775ãã°ã€ã³ã¢ã«ãŠã³ãããããã§ããŸããã§ããã
4776ãã¡ã€ã³ã³ã³ãããŒã©ãŒã¢ã«ãŠã³ãã®è³æ Œæ
å ±ã確èªããããšããŸããã
4777ãã¡ã€ã³ã³ã³ãããŒã©ãŒã¢ã«ãŠã³ãã®è³æ Œæ
å ±ã®æ€èšŒã«å€±æããŸããã
ã³ã³ãã¥ãŒã¿ãŒã¢ã«ãŠã³ã管ç
IDã¡ãã»ãŒãž
4741ã³ã³ãã¥ãŒã¿ãŒã¢ã«ãŠã³ããäœæãããŸããã
4742ã³ã³ãã¥ãŒã¿ãŒã¢ã«ãŠã³ããå€æŽãããŸããã
4743ã³ã³ãã¥ãŒã¿ãŒã¢ã«ãŠã³ããåé€ãããŸããã
é
åžã°ã«ãŒã管ç
IDã¡ãã»ãŒãž
4744ã»ãã¥ãªãã£æ€èšŒãç¡å¹ãªããŒã«ã«ã°ã«ãŒããäœæãããŸããã
4745ã»ãã¥ãªãã£æ€èšŒãç¡å¹ã«ãªã£ãŠããããŒã«ã«ã°ã«ãŒããå€æŽãããŸããã
4746ã»ãã¥ãªãã£æ€èšŒãç¡å¹ãªãŠãŒã¶ãŒãããŒã«ã«ã°ã«ãŒãã«è¿œå ãããŸããã
4747ã»ãã¥ãªãã£æ€èšŒãç¡å¹ã«ãªã£ãŠããããŒã«ã«ã°ã«ãŒããããŠãŒã¶ãŒãåé€ãããŸããã
4748ã»ãã¥ãªãã£æ€èšŒãç¡å¹ã«ãªã£ãŠããããŒã«ã«ã°ã«ãŒããåé€ããŸããã
4749ã»ãã¥ãªãã£æ€èšŒãç¡å¹ãªã°ããŒãã«ã°ã«ãŒããäœæãããŸããã
4750ã»ãã¥ãªãã£æ€èšŒãç¡å¹ã«ãªã£ãŠããã°ããŒãã«ã°ã«ãŒããå€æŽãããŸããã
4751ã»ãã¥ãªãã£æ€èšŒãç¡å¹ãªãŠãŒã¶ãŒãã°ããŒãã«ã°ã«ãŒãã«è¿œå ãããŸããã
4752ã»ãã¥ãªãã£æ€èšŒãç¡å¹ã«ãªã£ãŠããã°ããŒãã«ã°ã«ãŒããããŠãŒã¶ãŒãåé€ããŸããã
4753ã»ãã¥ãªãã£æ€èšŒãç¡å¹ã«ãªã£ãŠããã°ããŒãã«ã°ã«ãŒããåé€ããŸããã
4759ã»ãã¥ãªãã£æ€èšŒãç¡å¹ãªãŠãããŒãµã«ã°ã«ãŒããäœæãããŸããã
4760ã»ãã¥ãªãã£æ€èšŒãç¡å¹ã«ãªã£ãŠãããŠãããŒãµã«ã°ã«ãŒããå€æŽãããŸããã
4761ã»ãã¥ãªãã£æ€èšŒãç¡å¹ãªã¡ã³ããŒããŠãããŒãµã«ã°ã«ãŒãã«è¿œå ãããŸããã
4762ã»ãã¥ãªãã£æ€èšŒãç¡å¹ãªç¶æ
ã§ããŠãŒã¶ãŒããŠãããŒãµã«ã°ã«ãŒãããåé€ãããŸããã
ãã®ä»ã®ã¢ã«ãŠã³ã管çã€ãã³ã
IDã¡ãã»ãŒãž
4739ãã¡ã€ã³ããªã·ãŒãå€æŽãããŸããã
4782ã¢ã¯ã»ã¹ã¢ã«ãŠã³ãã®ãã¹ã¯ãŒãããã·ã¥ã
4793ãã¹ã¯ãŒãããªã·ãŒãã§ãã¯APIãåŒã³åºãããŸããã
ã»ãã¥ãªãã£ã°ã«ãŒã管ç
IDã¡ãã»ãŒãž
4727ã°ããŒãã«ãªã»ãã¥ãªãã£ãæå¹ãªã°ã«ãŒããäœæãããŸããã
4728ã»ãã¥ãªãã£ãæå¹ãªãŠãŒã¶ãŒãã°ããŒãã«ã°ã«ãŒãã«è¿œå ãããŸããã
4729ã°ããŒãã«ã»ãã¥ãªãã£ãæå¹ãªã°ã«ãŒããããŠãŒã¶ãŒãåé€ãããŸããã
4730ã»ãã¥ãªãã£ãæå¹ãªã°ããŒãã«ã°ã«ãŒããåé€ãããŸããã
4731ã»ãã¥ãªãã£ãæå¹ãªããŒã«ã«ã°ã«ãŒããäœæãããŸããã
4732ã»ãã¥ãªãã£ãæå¹ãªãŠãŒã¶ãŒãããŒã«ã«ã°ã«ãŒãã«è¿œå ãããŸããã
4733ã»ãã¥ãªãã£ãæå¹ãªããŒã«ã«ã°ã«ãŒããããŠãŒã¶ãŒãåé€ããŸããã
4734ã»ãã¥ãªãã£ãæå¹ãªããŒã«ã«ã°ã«ãŒããåé€ããŸããã
4735ã»ãã¥ãªãã£ãæå¹ãªããŒã«ã«ã°ã«ãŒããå€æŽãããŸããã
4737ã»ãã¥ãªãã£ãæå¹ãªã°ããŒãã«ã°ã«ãŒããå€æŽãããŸããã
4754ãŠãããŒãµã«ã»ãã¥ãªãã£ãæå¹ãªã°ã«ãŒããäœæãããŸããã
4755ã»ãã¥ãªãã£ãæå¹ãªãŠãããŒãµã«ã°ã«ãŒããå€æŽãããŸããã
4756ã»ãã¥ãªãã£ãæå¹ãªãŠãŒã¶ãŒããŠãããŒãµã«ã°ã«ãŒãã«è¿œå ãããŸããã
4757ã»ãã¥ãªãã£ãæå¹ã«ãªã£ãŠãããŠãŒã¶ãŒããŠãããŒãµã«ã°ã«ãŒãããåé€ãããŸããã
4758ã»ãã¥ãªãã£ãæå¹ãªãŠãããŒãµã«ã°ã«ãŒããåé€ããŸããã
4764ã°ã«ãŒãã¿ã€ããå€æŽãããŸããã
ãŠãŒã¶ãŒã¢ã«ãŠã³ã管ç
IDã¡ãã»ãŒãž
4720ãŠãŒã¶ãŒã¢ã«ãŠã³ããäœæãããŸããã
4722ãŠãŒã¶ãŒã¢ã«ãŠã³ããæå¹ã«ãªã£ãŠããŸãã
4723ã¢ã«ãŠã³ãã®ãã¹ã¯ãŒããå€æŽãããŸããã
4724ãŠãŒã¶ãŒãã¹ã¯ãŒãããªã»ããããŸãã
4725ãŠãŒã¶ãŒã¢ã«ãŠã³ãã¯ç¡å¹ã§ãã
4726ãŠãŒã¶ãŒã¢ã«ãŠã³ããåé€ãããŸããã
4738ãŠãŒã¶ãŒã¢ã«ãŠã³ããå€æŽãããŸããã
4740ãŠãŒã¶ãŒã¢ã«ãŠã³ããããã¯ãããŠããŸãã
4765 SIDãã°ãã¢ã«ãŠã³ãã«è¿œå ãããŸããã
4766ã¢ã«ãŠã³ããã°SIDã®è¿œå ã«å€±æããŸããã
4767ãŠãŒã¶ãŒã¢ã«ãŠã³ãã®ããã¯ã解é€ãããŸããã
4780管çè
ã°ã«ãŒãã®ã¡ã³ããŒã§ããã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ããã€ã³ã¹ããŒã«ãããŠããŸãã
4781ã¢ã«ãŠã³ãåãå€æŽãããŸããã
4794ãã£ã¬ã¯ããªãµãŒãã¹ã®å埩ã¢ãŒããèšå®ããããšããŸããã
5376è³æ Œæ
å ±ãããŒãžã£ãŒïŒè³æ Œæ
å ±ãä¿åãããŸããã
5377è³æ Œæ
å ±ãããŒãžã£ãŒïŒè³æ Œæ
å ±ãããã¯ã¢ãããã埩å
ãããŸããã
ãã®ä»ã®ã€ãã³ã
IDã¡ãã»ãŒãž
1102ã¯ãªã¢ãããã»ãã¥ãªãã£ãã°
4624ãã°ã€ã³æå
4625ãã°ã€ã³ã«å€±æããŸãã
ç£æ»ããªã·ãŒãã©ã³ãã§ã¯ããã°ã€ã³/ãã°ãªã³ç£æ»ãã¢ã«ãŠã³ã管çç£æ»ããªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ãããªã·ãŒã®å€æŽãªã©ãä»ã®æ©èœãæå¹ã«ãªã£ãŠããŸãã ããšãã°ãå
±æãã©ã«ããŒã®äŸã䜿çšããŠããªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ã®ç£æ»ãèšå®ããŸãã ãããè¡ãã«ã¯ãåè¿°ã®ããã«ã
ãªããžã§ã¯ãã¢ã¯ã»ã¹ããªã·ãŒã®
ç£æ»ãã¢ã¯ãã£ãã«ããŠããããã©ã«ããŒãéžæãã[ãã©ã«ããŒã®
ãããã㣠]ã¡ãã¥ãŒãåŒã³åºããŸãã éãã[..ã®é«åºŠãªã»ãã¥ãªãã£èšå®]ãŠã£ã³ããŠã§ã[
ç£æ» ]ã¿ãã«ç§»åãã[
ç·šé ]ãã¿ã³ãã¯ãªãã¯ããŠãããç£æ»ãå®è¡ããã¢ã«ãŠã³ããŸãã¯ã°ã«ãŒãã
è¿œå ããŠæå®ããŸãã 次ã«ãç£èŠå¯Ÿè±¡ã®ã€ãã³ãïŒå®è¡ãèªã¿åãããã¡ã€ã«äœæãªã©ïŒãšçµæïŒæåãŸãã¯å€±æïŒã«æ³šç®ããŸãã ã
é©çš ããªã¹ãã䜿çšããŠãç£æ»ããªã·ãŒã®ç¯å²ã瀺ããŸãã å€æŽã確èªããŸãã
å³5å
±æãã©ã«ããŒç£æ»ã®æ§æããã§ããããã®ãã¹ãŠã®æäœãã»ãã¥ãªãã£ãã°ã«è¡šç€ºãããŸãã
å€æ°ã®ãªããžã§ã¯ãã䜿çšããç£æ»ã®æ§æãç°¡çŽ åããã«ã¯
ã[芪ãªããžã§ã¯ãããã®ãã©ã¡ãŒã¿ãŒã®
ç¶æ¿]ãã§ãã¯ããã¯ã¹ããªã³ã«ããŸãã åæã«ã[
ç¶æ¿å
]ãã£ãŒã«ãã«ãèšå®ã®ååŸå
ã®èŠªãªããžã§ã¯ãã衚瀺ãããŸãã
ãã°ã«èšé²ãããã€ãã³ãããã现ããå¶åŸ¡ããã«ã¯ã
ã»ãã¥ãªãã£èšå®/ããŒã«ã«ããªã·ãŒ/é«åºŠãªç£æ»ããªã·ãŒã®æ§æã§æ§æãããŠãã
詳现ãªç£æ»ããªã·ãŒãé©çšããŸãã 10ã®ãµãã¢ã€ãã ããããŸãã
-ã¢ã«ãŠã³ããã°ãªã³-è³æ Œæ
å ±ã®æ€èšŒãKerberosèªèšŒãµãŒãã¹ãKerberosãã±ããæäœããã®ä»ã®ãã°ã€ã³ã€ãã³ãã®ç£æ»ã
-ã¢ã«ãŠã³ã管ç -ã¢ããªã±ãŒã·ã§ã³ã°ã«ãŒããã³ã³ãã¥ãŒã¿ãŒããã³ãŠãŒã¶ãŒã¢ã«ãŠã³ããã»ãã¥ãªãã£ããã³é
åžã°ã«ãŒãã®ç®¡çã®ç£æ»ã
-詳现ãªè¿œè·¡ -RPCããã³DPAPIã€ãã³ããããã»ã¹ã®äœæãšçµäºã
-DSãã£ã¬ã¯ããªãµãŒãã¹ãžã®ã¢ã¯ã»ã¹-
ãã£ã¬ã¯ããªãµãŒãã¹ã®ã¢ã¯ã»ã¹ãå€æŽãè€è£œãããã³è©³çŽ°ãªè€è£œã®ç£æ»ã
-ãã°ã€ã³/ãã°ã¢ãŠã -ã¢ã«ãŠã³ãã®ããã¯ã¢ãŠãããã°ã€ã³ãšãã°ã¢ãŠãã®ç£æ»ãIPSecã®äœ¿çšããããã¯ãŒã¯ããªã·ãŒãµãŒããŒã
-ãªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ -ã«ãŒãã«ãªããžã§ã¯ãã®ç£æ»ãèšè¿°åã®æäœãã¢ããªã±ãŒã·ã§ã³ã«ãã£ãŠäœæãããã€ãã³ããèªèšŒãµãŒãã¹ããã¡ã€ã«ã·ã¹ãã ããããªãã¯ãã©ã«ããŒããã£ã«ã¿ãªã³ã°ãã©ãããã©ãŒã ã
-ããªã·ãŒã®å€æŽ-ç£æ»ããªã·ãŒãèªèšŒãæ¿èªããã£ã«ã¿ãªã³ã°ãã©ãããã©ãŒã ãMPSSVCã»ãã¥ãªãã£ãµãŒãã¹ã«ãŒã«ãªã©ã®å€æŽã
-æš©å©ã®äœ¿çš -ããŸããŸãªã«ããŽãªã®ããŒã¿ãžã®ã¢ã¯ã»ã¹æš©ã®ç£æ»ã
-ã·ã¹ãã -ã·ã¹ãã ã®æŽåæ§ãã»ãã¥ãªãã£ã¹ããŒã¿ã¹ã®å€æŽãšæ¡åŒµãIPSecãã©ã€ãããã®ä»ã®ã€ãã³ãã®ç£æ»ã
-ã°ããŒãã«ãªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ã®ç£æ»-ãã¡ã€ã«ã·ã¹ãã ãšã¬ãžã¹ããªã®ç£æ»ã
å³6å©çšå¯èœãªè©³çŽ°ãªç£æ»ããªã·ãŒã®æ§æèšå®
ãŠãŒã¶ãŒã¢ã«ãŠã³ã管çã®ç£æ»ãã¢ã¯ãã£ãã«ãããšãäœæãå€æŽãåé€ããããã¯ãè¿œå ãããã³ãã¹ã¯ãŒããæš©éãªã©ã®ãã®ä»ã®ã¢ã«ãŠã³ãèšå®ãç£èŠã§ããŸãã ãããå®éã«ã©ã®ããã«æ©èœããããèŠãŠã¿ãŸããã-User
Account Managementãµãã«ããŽãªãéžæããŠã¢ã¯ãã£ãã«ããŸãã
auditpolã®ã³ãã³ãã¯æ¬¡ã®ããã«ãªããŸãã
> auditpol /set /subcategory:"User Account Management" /success:enable /failure:enable
> gpudate
ã€ãã³ããã¥ãŒã¢ãŒã³ã³ãœãŒã«ã®ç£æ»ã·ã¹ãã ã«ã¯ãããã«ã€ãã³ãçªå·
4719ã衚瀺ãããŸããç£æ»èšå®ãå€æŽãããšãããªã·ãŒã®ååãšæ°ããå€ã衚瀺ãããŸãã
å³7ç£æ»ã·ã¹ãã ã«ããããªã·ãŒå€æŽã®ã³ãããã€ãã³ããäœæããã«ã¯ãActive Directoryã³ã³ãœãŒã«ïŒãŠãŒã¶ãŒãšã³ã³ãã¥ãŒã¿ãŒïŒãéããä»»æã®ã¢ã«ãŠã³ãã®ãã©ã¡ãŒã¿ãŒã®1ã€ãå€æŽããŸãïŒããšãã°ããŠãŒã¶ãŒãã»ãã¥ãªãã£ã°ã«ãŒãã«è¿œå ããŸãïŒã ã€ãã³ããã¥ãŒã¢ãŒã³ã³ãœãŒã«ã§ã¯ãããã€ãã®ã€ãã³ããããã«çæãããŸããçªå·ã
4732ããã³
4735ã®ã€ãã³ãã¯ãã»ãã¥ãªãã£ã°ã«ãŒãã®æ§æã®å€æŽã瀺ããæ°ããã»ãã¥ãªãã£ã°ã«ãŒãã¢ã«ãŠã³ãã®è¿œå ïŒå³8ã§çŽ«è²ã§åŒ·èª¿è¡šç€ºïŒã
æ°ããã¢ã«ãŠã³ããäœæããŸããã-ã·ã¹ãã ã¯ããã€ãã®ã€ãã³ããçæããŸãïŒ
4720 ïŒæ°ããã¢ã«ãŠã³ãã®äœæïŒã
4724 ïŒã¢ã«ãŠã³ããã¹ã¯ãŒãã®ãªã»ãããè©Šã¿ãŸãïŒãã³ãŒã
4738 ïŒã¢ã«ãŠã³ãã®å€æŽïŒããããŠæåŸã«
4722 ïŒæ°ããã¢ã«ãŠã³ãããªã³ã«ããïŒã®ããã€ãã®ã€ãã³ãã ç£æ»ã«ãããšã管çè
ã¯æ°æ§ã®å±æ§å€ã远跡ã§ããŸããããšãã°ãã¢ã«ãŠã³ããäœæãããšãUACå€ãå€æŽãããŸãã
å³8æ°ããã¢ã«ãŠã³ããäœæãããšãWindows Server 2008ç£æ»ã·ã¹ãã ã¯ããã€ãã®ã€ãã³ããçæããŸãããã«ã¿ã€ã ç£æ»ã·ã¹ãã ã®æ¬ ç¹
確ç«ããããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããŒã«ã¯ãå€ãã®å ŽåãåæããŒã«ã®åºæ¬ã»ããã®ã¿ãæäŸããŸãã å
¬åŒããã¥ã¡ã³ãïŒhttp://technet.microsoft.com/en-us/library/dd772623(WS.10).aspxïŒã¯ãããŒã«èªäœã®æ©èœãéåžžã«ãã説æããŠããŸãããå€æŽã远跡ããå¿
èŠããããã©ã¡ãŒã¿ãŒãéžæããã®ã«ã»ãšãã©åœ¹ç«ã¡ãŸããã ãã®çµæããã®åé¡ã®è§£æ±ºçã¯ã·ã¹ãã 管çè
ã«å®å
šã«ããã£ãŠãããã·ã¹ãã 管çè
ã¯ç£æ»ã®æè¡çåŽé¢ãå®å
šã«ç解ããå¿
èŠãããããã®æºåã¬ãã«ã«äŸåããŸãã ããã«ãçµæã®åæãããŸããŸãªã¬ããŒãã®äœæã¯åœŒã®è©ã«ããã£ãŠããŸãã
ç¹å®ã®ã€ãã³ããéžæããããããã«ãã€ãã³ããã¥ãŒã¢ãŒã®ã³ã³ãœãŒã«ã€ã³ã¿ãŒãã§ã€ã¹ã§ã¯ããã£ã«ã¿ãŒãšã«ã¹ã¿ã ãã¥ãŒãäœæã§ããŸãã ããŒã¿éžæã®ãã©ã¡ãŒã¿ãŒãšããŠãæ¥ä»ãã€ãã³ãã®ãã°ãšãœãŒã¹ãã¬ãã«ïŒé倧ãèŠåããšã©ãŒãªã©ïŒãã³ãŒãããŠãŒã¶ãŒãŸãã¯ã³ã³ãã¥ãŒã¿ãŒãããã³ããŒã¯ãŒããæå®ã§ããŸãã çµç¹ã«ã¯ãç£æ»ãå人çã«èšå®ããå¿
èŠãããã°ã«ãŒãããã³ãŠãããã«çµ±åãããå€æ°ã®ãŠãŒã¶ãŒãããå ŽåããããŸããããã®æ©èœã¯ã€ã³ã¿ãŒãã§ãŒã¹ã§ã¯æäŸãããŸããã
å³ 9ã€ãã³ããã¥ãŒã¢ãŒã³ã³ãœãŒã«ã§ã®ã€ãã³ããã£ã«ã¿ãŒã®æ§æã«ãŒã«ãã«ã¹ã¿ã ãã¥ãŒã§ããªã¬ãŒãããå Žåãã¿ã¹ã¯ãäœæã§ããŸãïŒ
ã¿ã¹ã¯ãã€ãã³ãã«ãã€ã³ãã¡ãã¥ãŒïŒïŒããã°ã©ã ãå®è¡ãããé»åã¡ãŒã«ã¡ãã»ãŒãžãéä¿¡ããããŸãã¯ãã¹ã¯ãããã«ã¡ãã»ãŒãžã衚瀺ããŸãã
å³10ã€ãã³ããã¥ãŒã¢ãŒã³ã³ãœãŒã«ã§ã®ã¿ã¹ã¯ã®äœæãã ããã¢ã©ãŒãã®å®è£
ãç¹ã«ã€ãã³ãã®éžæã¯ãå®å
šã«ç®¡çè
ã«å§ããããŠããŸãã
å€æŽãããå±æ§ã以åã®å€ã«ããŒã«ããã¯ããå¿
èŠãããå Žåããã®ã¢ã¯ã·ã§ã³ã¯æåã§å®è¡ãããŸã-ã³ã³ãœãŒã«ã¯ãã©ã¡ãŒã¿ãŒã®å€ã®ã¿ã衚瀺ããŸãã
å³11 Windows Server 2008ç£æ»ã·ã¹ãã ã¯ã䟿å©ãªããŒã«ããã¯ã®æ段ãæäŸããã«ãå€ãå±æ§å€ãšæ°ããå±æ§å€ã®ã¿ãè¿ããŸãäžéšã®ã»ãã¥ãªãã£æšæºã§ã¯ãç£æ»ããã»ã¹äžã«åéãããããŒã¿ãé·æéä¿åããå¿
èŠããããŸãïŒããšãã°ãæ倧7幎éã®SOXïŒã ãããã·ã¹ãã æ段ã§å®è£
ããããšã¯å¯èœã§ãããéåžžã«å°é£ã§ãã ã»ãã¥ãªãã£ãã°ïŒããã³ãã®ä»ïŒã®ãµã€ãºã¯128 MBã«å¶éãããŠãããå€æ°ã®ã€ãã³ãããããšãããŒã¿ã¯æ°æéã§äžæžãïŒã€ãŸã倱ãããŸãïŒããå¯èœæ§ããããŸãã ãããåé¿ããã«ã¯ãã€ãã³ããã¥ãŒã¢ãŒã§ãã°ããããã£ãŠã£ã³ããŠãåŒã³åºãå¿
èŠããããŸãããã®ãŠã£ã³ããŠã§ã¯ã[
èšå
¥æã«ãã°ãã¢ãŒã«ã€ããã]ãã§ãã¯ããã¯ã¹ããªã³ã«ããŠããã°ã®ãµã€ãºãå¢ãããã¢ãŒã«ã€ããæå¹ã«ããŸã
ã ã€ãã³ããäžæžãããªãã§ãã ãã ãã
å³12å€ãã»ãã¥ãªãã£ã€ãã³ãã倱ããªãããã«ããã°ã®ãµã€ãºãå¢ãããŠã¢ãŒã«ã€ããæå¹ã«ããŸãããããä»ã§ã¯å€ãã®ã¢ãŒã«ã€ãã§ã€ãã³ããæ€çŽ¢ããåé¡ã解決ããå¿
èŠããããŸãã
ãŸããéåžžã®ç£æ»ã·ã¹ãã ã®å¶éã«ã¯ãã°ã«ãŒãããªã·ãŒã®å¶éãããç£èŠæ©èœãå«ãŸããããšã«æ³šæãã䟡å€ããããŸãã éåžžã®æ段ã«ãããã®å€æŽã®äºå®ãç£èŠã§ãããšããäºå®ã«ãããããããå€æŽããããã©ã¡ãŒã¿ãŒã®å€ã¯åºå®ãããŠããªããããæ£ç¢ºã«äœãå€æŽãããæ°ããå€ãäœã«ãªã£ãã®ããšãã質åã«çããããšã¯äžå¯èœã§ãã ç¶æ³ã«ãã£ãŠã¯ããã§ååã§ãããæ¬æ Œçãªç£æ»ãšåŒã¶ããšã¯å°é£ã§ãã
***
ãã®èšäºã¯ããWindows Server 2008 R2ã®Active Directoryç£æ»ã®å®å
šã¬ã€ãã[PDF]ã®äžéšã§ãã çããã©ãŒã ã«èšå
¥ããŠããã®
ãªã³ã¯ããããŠã³ããŒãã§ããŸãã