
ãã®ã·ãªãŒãºã®éå»3åã®èšäºã§ã¯ã
Dynamic Access ControlãŸãã¯å
ã®ãµãŠã³ããšããŠ
Dynamic Access Control ãDACãšåŒã°ããè峿·±ãæ¯èŒçæ°ãããã¯ãããžãŒã«ã€ããŠèª¬æããŠããŸããã ã€ãŸãã以åã«èŠã€ãããã®ãæ£ç¢ºã«æãåºããšã
æåã®èšäºã§ãã®æè¡ã®ç®çãšãMicrosoftã®ä»¥åã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŒã¿ã®ã¢ã¯ã»ã¹èš±å¯ã管çããæ¹æ³ã«é¢ããå©ç¹ã«ã€ããŠè©±ããŸããã ãã®ã·ãªãŒãº
ã®2çªç®ã®èšäºã§ã¯ãã¹ããŒãã¡ã³ããã¹ããŒãã¡ã³ãã®ã¿ã€ããæ¡ä»¶åŒãªã©ããã®ãã¯ãããžãŒã®äžå¯æ¬ ãªéšåã«çŠç¹ãåœãŠãŸããã
3çªç®ã®éšåã¯æ¯èŒçå°ããããªãœãŒã¹ã®ããããã£ãªã©ã®æŠå¿µã«ã€ããŠåŠã¶ããšãã§ããŸããã 仿¥ã¯ãçè«ãšå®éã®äŸãçµã¿åãããŠãããŸãããŸãããã®èšäºã®ã¿ã€ãã«ããæãããªããã«ããªãœãŒã¹ããããã£ã®ãããã¯ãç¶ããŸãããªãœãŒã¹ããããã£ã®ãªã¹ããªã©ã«ã€ããŠç°¡åã«èª¬æããŸãã
ããã«ããã®è峿·±ããµã€ã¯ã«ã®ãã®4çªç®ã®èšäºã§ã¯ããã¡ã€ã«åé¡ãªã©ã®ãããã¯ã«å€ãã®æ³šæãåãããããã®å®è£
ã«ã€ããŠã¯ãã
ãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒ ããªã©ã®ããŒã«ããŸãã¯ããç°¡åã«FSRMã«ã€ããŠåŠç¿ããŸãã ãããã£ãŠããã®ããŒã«ã®ç®çãFSRMã䜿çšããéã®äžè¬çãªååãããã³æåã®åé¡ãšåé¡èŠåã«ã€ããŠåŠç¿ããŸãã ã€ãŸããã芧ã®ãšããããã®èšäºã«ã¯å€ãã®è³æããããŸãããããŠãç§ãæãããã«ãå€ãã®æ°ããè峿·±ãæ
å ±ãåŠã¶ããšãã§ããŸãã ãã®å Žåãå
ã«é²ã¿ãŸãããã
ãªãœãŒã¹ããããã£ãªã¹ã
ãªãœãŒã¹ã®ããããã£ãäœã§ãããã«ã€ããŠã¯ãåã®èšäºã§ãã§ã«åŠã³ãŸããã èŠããã«ã
ãªãœãŒã¹ã®ããããã£ã¯ããªãœãŒã¹ã®ç¹æ§ãèšè¿°ããç¹å®ã®ãšã³ãã£ãã£ã§ããããã¡ã€ã«ããã©ã«ããªã©ã®ãªããžã§ã¯ãã§ããå ŽåããããŸãã ãªãœãŒã¹ã®ããããã£ãããã«è©³ããèŠãŠããããã®ãªã¹ããäœã§ãããã倿ããŠã¿ãŸããããããã«ã€ããŠã¯ããã®èšäºã®ãã®ã»ã¯ã·ã§ã³ã§èª¬æããŸãã ãªãœãŒã¹ããããã£ãªã¹ãã¯ãActive Directoryãã¡ã€ã³ãµãŒãã¹ã®ã»ãã¥ãªãã£ã°ã«ãŒããšããçšåºŠæ¯èŒã§ããŸãã ãªãããã ãããªãã¯å°ããã ãããŠãããã§ã¯ãã¹ãŠãç°¡åã§ãã ã»ãã¥ãªãã£ã°ã«ãŒããšåæ§ã«ã
ãªãœãŒã¹ããããã£ãªã¹ãã䜿çšãããšã以åã«äœæãããªãœãŒã¹ããããã£ãªããžã§ã¯ããè«ççã«ã°ã«ãŒãåã§ããŸãã ã€ãŸããå
¬åŒã®å®çŸ©ã«ããã°ããããã®ãªãœãŒã¹ããããã£ã®ãªã¹ãã䜿çšããŠè«ççã«ã°ã«ãŒãåããããªãœãŒã¹ããããã£ãªããžã§ã¯ãã¯ãç¹å®ã®ãã¡ã€ã«ãµãŒããŒã§äœ¿çšãããªãœãŒã¹ããããã£ãªããžã§ã¯ãã®éžæãããã»ãããå²ãåœãŠãããã«äœ¿çšãããæãç°¡åã§å¹æçãªæ¹æ³ãæäŸããŸãã
äŒç€ŸãŸãã¯ãã¹ããã³ãã§ãWindows Server 2012ããã³Windows Server 2012 R2ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®Active Directory管çã»ã³ã¿ãŒã§ãªãœãŒã¹ããããã£ãªããžã§ã¯ãã®äœæãéå§ããåã«ãæåã®ãªããžã§ã¯ãã
ã°ããŒãã«ãªãœãŒã¹ããããã£ãªã¹ã ã ãã®ãããªãªãœãŒã¹ããããã£ã®ãªã¹ãã¯Active Directoryãã©ã¬ã¹ãå
šäœã«å¯ŸããŠäœæããããã®ãªã¹ãã¯äŒç€Ÿã®ãã¹ãŠã®ãã¡ã€ã«ãµãŒããŒã«äœ¿çšãããããããã®ãªããžã§ã¯ãã«å«ãŸãããªãœãŒã¹ããããã£ã¯ãã¹ãŠã®å Žåã«é©çšãããŸãã ãã®ãããWindows Server 2012/2012 R2ãã¡ã€ã«ãµãŒããŒã«ã¯ãæ¢ã«æåã§äœæãããªãœãŒã¹ããããã£ã®ãªã¹ããå«ããããšãã§ããŸãã
远å ã®ã»ãã¥ãªãã£èšå®ã®ãªãœãŒã¹ããããã£ã®ãããã®ãªã¹ããšããªãœãŒã¹ããããã£ã®ãªã¹ããç¹ã«ã°ããŒãã«ãªãœãŒã¹ããããã£ãªã¹ãã«è¿œå ããæ¡ä»¶åŒãšãã£ã¿ãŒã®ãããã§ãã»ãã¥ãªãã£ãªãœãŒã¹ããããã£ã®ãªããžã§ã¯ãã衚瀺ãããŸãã ãããŠãŸãã«ãã®çç±ãããäœããã®çš®é¡ã®ãªãœãŒã¹ããããã£ãªããžã§ã¯ããæ¿èªã«äœ¿çšããå¿
èŠããããšèããå Žåããã®ãããªãªããžã§ã¯ããã°ããŒãã«ãªãœãŒã¹ããããã£ãªã¹ãã«è¿œå ããå¿
èŠããããŸãã ããŠããã¡ã€ã«ãµãŒããŒäžã®ãªãœãŒã¹ããããã£ã®ãã®ãããªãªã¹ãã¯ãããããæ¢ã«æšæž¬ãããŠããããã«ãã°ã«ãŒãããªã·ãŒãªã©ã®ãã¯ãããžã®æ©èœãçŽæ¥äœ¿çšããŠæ§æãããŸãã
ãªãœãŒã¹ããããã£ãªã¹ããäœæããã³æ§æãã
å®éããã®èšäºã®ãã®éšåã«ã¯çè«çãªè³æãããŸããªãã®ã§ããããããã©ã¯ãã£ã¹èªäœã«é²ã¿ããã®ãããªãªãœãŒã¹ããããã£ã®ãªã¹ããäœæããã³æ§æããæ¹æ³ã確èªããŸãã 以åã®å Žåãšåæ§ã«ããã®ãããªã¿ã¹ã¯ã¯ãActive DirectoryãµãŒããŒã®å
šäœç®¡çãšWindows PowerShellã®äž¡æ¹ã䜿çšããŠå®è¡ã§ããŸãã ãã¡ãããäž¡æ¹ã®æ¹æ³ãæ€èšããŸãã
Active DirectoryãµãŒããŒã®å
šäœç®¡çã䜿çšããŠãªãœãŒã¹ããããã£ãªã¹ããäœæããã³æ§æãã
ãªãœãŒã¹ããããã£ãªã¹ãã䜿çšããŠå®è¡ãããæãäžè¬çãªã¿ã¹ã¯ã¯ãæ¢åã®ãªãœãŒã¹ããããã£ãªããžã§ã¯ããã°ããŒãã«ãªãœãŒã¹ããããã£ãªã¹ãã«è¿œå ããããšãªã®ã§ã以äžã«ã€ããŠåŠç¿ããŸãã
- ã°ããŒãã«ãªãœãŒã¹ããããã£ãªã¹ãã«æ°ãããªããžã§ã¯ãã远å ããã«ã¯ã©ãããã°ããã§ããã
- ãªãœãŒã¹ããããã£ã®ç¬èªã®ãªã¹ããäœæããããã«ãªãœãŒã¹ããããã£ãªããžã§ã¯ãã远å ããã«ã¯ã©ãããã°ããã§ããã
- ãŸãããªãœãŒã¹ããããã£ãªã¹ããªããžã§ã¯ããããªãœãŒã¹ããããã£ãèŠã€ããæ¹æ³ã«ã€ããŠãåŠç¿ããŸãã
é çªã«å§ããŸããããã€ãŸããæ°ãããªãœãŒã¹ããããã£ãªããžã§ã¯ããæšæºã®
ã°ããŒãã«ãªãœãŒã¹ããããã£ãªã¹ãã«è¿œå ããŸãã ããã«ã¯ã次ã®ãã®ãå¿
èŠã§ãã
- ãã¡ã€ã³ã³ã³ãããŒã©ãŒã§ã Active DirectoryãµãŒããŒã®å
šäœç®¡çã¹ãããã€ã³ãéããŸãããªã¹ããšãªã¢ã§[ ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡]ããŒããéžæãã[ ãªãœãŒã¹ããããã£ãªã¹ã ]ããŒããéžæããå¿
èŠããããŸãïŒ[ ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡]> [ãªãœãŒã¹ããããã£ãªã¹ã] ïŒã
- ããŠããã®ã¹ãããã§ã¯ã ããªãœãŒã¹ããããã£ãªã¹ãããšãªã¢ã§ã°ããŒãã«ãªãœãŒã¹ããããã£ãªã¹ããªããžã§ã¯ããéžæãããã®ããããã£ãã€ã¢ãã°ããã¯ã¹ãéãããšãã§ããŸããããã§ã ã ãªãœãŒã¹ãããã㣠ãã°ã«ãŒãã®ã远å ããã¿ã³ãã¯ãªãã¯ããå¿
èŠããããŸããŸãã¯ããã®ãªããžã§ã¯ããéžæããŠã ãã¿ã¹ã¯ããšãªã¢ã®ã ãªãœãŒã¹ããããã£ã®è¿œå ããªã³ã¯ãã¯ãªãã¯ããŸãã ããã§2çªç®ã®æ¹æ³ã䜿çšããŸãããªãœãŒã¹ããããã£ã®ãªã¹ãã®ããããã£ãã€ã¢ãã°ããã¯ã¹ã«ã€ããŠã¯ãåŸã§è©³ããèŠãããã§ãã

å³ 1.äœæ¥ãŠã£ã³ããŠãããªãœãŒã¹ããããã£ã®æ¢åã®ãªã¹ããžã®ãªãœãŒã¹ããããã£ã®è¿œå
- ããã§ããªãœãŒã¹ããããã£ãéžæããããã®ãã€ã¢ãã°ããã¯ã¹ã§ãå·ŠåŽã®ãªã¹ãããå¿
èŠãªãªãœãŒã¹ããããã£ãªããžã§ã¯ããéžæããå¿
èŠããããŸããæ¬¡ã«ã ãæ¬¡ã®ãªãœãŒã¹ããããã£ã远å ããšãªã¢ã«ãã®ãããªãªããžã§ã¯ãã远å ã§ãã察å¿ãããã¿ã³ãã¯ãªãã¯ããå¿
èŠããããŸãïŒ åœç¶ãè€æ°ã®ãªãœãŒã¹ããããã£ãªããžã§ã¯ãã远å ããå¿
èŠãããå Žåã¯ãCTRLããŒãæŒããªããéžæã§ããŸãã ãªããžã§ã¯ãã远å ãããã ãOKããã¿ã³ãã¯ãªãã¯ããŠå€æŽãä¿åããŸãã ããšãã°ããã®å Žåãåã®èšäºã§äœæãããRegionãªããžã§ã¯ãã远å ãããŸãã

å³ 2.ãªã¹ãã«è¿œå ãããªãœãŒã¹ããããã£ãªããžã§ã¯ãã®éžæ
ã芧ã®ãšãããæé ã¯éåžžã«ç°¡åã§ãã
次ã«ããªãœãŒã¹ããããã£ã®æ°ãããªã¹ããäœæããäœææã«ããã«ããã€ãã®ãªãœãŒã¹ããããã£ãªããžã§ã¯ãã远å ããããšããŸãã ããã¯ã©ã®ããã«èŠããŸããïŒ
- 次ã®å³ã«ç€ºãããã«ãåãActive DirectoryãµãŒããŒã®å
šäœç®¡çãµã€ããã€ãŸã[ ãªãœãŒã¹ããããã£ãªã¹ã]ããŒãã§ã[ äœæ]ãéžæãã[ æ°èŠ äœæ] > [ãªãœãŒã¹ããããã£ãªã¹ã]ãéžæããŸãã

å³ 3.ãªãœãŒã¹ããããã£ã®æ°ãããªã¹ããäœæãã
- å®éã«ãåã«è¡šç€ºããã[ ãªãœãŒã¹ããããã£ãªã¹ãã®äœæ ]ãã€ã¢ãã°ããã¯ã¹ã¯ããã®ã·ãªãŒãºã®ä»¥åã®èšäºã§åºäŒã£ã以åã®ãã¹ãŠã®ãã€ã¢ãã°ãããã¯ããã«ã·ã³ãã«ã«èŠããŸãã ããã§ã¯ã以äžã®å³ã«èŠãããããã«ãã³ã³ãããŒã«ã®å€æŽã®å¯Ÿè±¡ãšãªã察象ã¯4ã€ã ãã§ãã
- ãåå ãã¡ããããããæåã§ãããå®éããã®ãããªãªã¹ããæ£åžžã«äœæããããã«å
¥åããå¿
èŠãããå¯äžã®ããã¹ããã£ãŒã«ãã§ãã ãã®ååã¯äžæã§ããå¿
èŠãããã ãªãœãŒã¹ããããã£ãªã¹ãããŒããåé¡ãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ãããã³Active DirectoryãµãŒããŒã®å
šäœç®¡çã³ã³ãœãŒã«ã®ä»ã®èŠçŽ ãšããŸããŸãªã·ã¹ãã ã³ã³ããŒãã³ãã«è¡šç€ºãããŸãã ãªãœãŒã¹ããããã£ã®å Žåãšåæ§ã«ããªãœãŒã¹ããããã£ã«è±æ°å圢åŒã§ååãä»ããããšãã§ããŸãã ããšãã°ããªãœãŒã¹ããããã£ã®ãªã¹ãã¯ã First RPL ããšåŒã°ããŸãã
- 説æ Windows Serverãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§äœæã§ããã»ãšãã©ãã¹ãŠã®ãªããžã§ã¯ããšåæ§ã«ããªãœãŒã¹ããããã£ãªã¹ãã®èª¬æã远å ã§ããŸãã ããªãããã®ãããªãªã¹ããããããäœæããå Žåãããã¯ç¢ºãã«éå®ããŸãã ã»ãšãã©ã®å Žåããã®ããã¹ããã£ãŒã«ãã®æå€§æåæ°ã¯1024ã§ããããšãã°ããã®å Žåã説æãšããŠããªãœãŒã¹ããããã£ã®æåã®ãã¹ããªã¹ãããšèšããŸãã
- 誀ã£ãåé€ã«å¯Ÿããä¿è·ïŒèª€ã£ãåé€ããä¿è·ããïŒ ã ãã€ãã®ããã«ãããã¯äœæãããã»ãšãã©ãã¹ãŠã®ãªããžã§ã¯ãã§æ€åºã§ãããã©ã°ã§ããããã«ãããå€ãã®ç®¡çè
ã®ç掻ã倧å¹
ã«ç°¡çŽ åãããäœæããããªããžã§ã¯ããæå³ããªããŸãã¯æªæã®ããåé€ããä¿è·ãããŸãã
- ãªãœãŒã¹ã®ãããã㣠ããã¯ãäœæãããªã¹ãã«é¢é£ä»ããããšãã§ãããã¹ãŠã®ãªãœãŒã¹ããããã£ãªããžã§ã¯ããæå®ã§ããã°ã«ãŒãå
šäœã§ãã ããã©ã«ãã§ã¯ããã®ã°ã«ãŒãã«ã¯åäžã®ãªããžã§ã¯ãã¯è¿œå ãããŸãããããã¯ãåäžã®ãªãœãŒã¹ããããã£ãªãã§ãªã¹ãèªäœãäœæããããšãã§ããåŸè
ã®äœææã«è¿œå ã§ããããšãæå³ããŸãã ãã®ã°ã«ãŒãã«ãã®ãããªãªããžã§ã¯ãã远å ããã®ã¯éåžžã«ç°¡åã§ãã ãããè¡ãã«ã¯ã[ 远å ]ãã¿ã³ãã¯ãªãã¯ãããã®ã»ã¯ã·ã§ã³ã®åã®ã»ã¯ã·ã§ã³ã§ç¢ºèªãã[ãªãœãŒã¹ããããã£ã®éžæ ]ãã€ã¢ãã°ããã¯ã¹ã䜿çšããŠãå¿
èŠãªã¢ã¯ã·ã§ã³ãå®è¡ããŠå¿
èŠãªãªãœãŒã¹ããããã£ã远å ããå¿
èŠããããŸãã ã ããã«ã€ããŠã¯æ¢ã«èª¬æããŸããããã®äŸã§ã¯ãã å°å ããªãœãŒã¹ããããã£ã远å ãããŸãã

å³ 4.ãªãœãŒã¹ããããã£ã®æ°ãããªã¹ããäœæãã
- äž¡æ¹ã®ãã€ã¢ãã°ããã¯ã¹ã§è¡ããã倿Žãä¿åãããã®åŸããªãœãŒã¹ããããã£ã®æ°ãããªã¹ããäœæãããŸãã
ãªã¹ããããªãœãŒã¹ããããã£ãªããžã§ã¯ããåé€ãããããªã¹ãèªäœã®ããããã£ã倿Žãããããããšã¯ãæ°ãããªã¹ããäœæããã®ãšåãããã«å®è¡ãããããããã®æé ã詳ãã説æããããšã¯é¿ããŠãã ããã
Active Directory管çã»ã³ã¿ãŒã§ãªãœãŒã¹ããããã£ãªã¹ããªããžã§ã¯ããçŽæ¥æ€çŽ¢ããå¯èœæ§ãæ€èšããããšã¯ãã¯ããã«è峿·±ãã§ãããã åçŽã«æ°ä»ããªãããšã¯äžå¯èœãªã®ã§ã
Resource Property ListsããŒãã«ã¯
ããã®ããŒãã§ã®æ€çŽ¢ãªã©ã®ãªãã·ã§ã³ããã
ãŸã ã ãã®æ©èœã䜿çšãããšãå¿
èŠãªãªãœãŒã¹ããããã£ãªããžã§ã¯ãããªãœãŒã¹ããããã£ãªã¹ããããã³ãã®ä»ã®ãªããžã§ã¯ããããŒã«ã©ã€ãºã§ããŸãã ã¿ã¹ã¯ãã€ã³ã§[
ãã®ãµã€ãã§æ€çŽ¢ ]ãã¿ã³ãã¯ãªãã¯ãããšã
ã°ããŒãã«æ€çŽ¢ã«ç§»åã
ãŸã ã
ããã§ãã°ããŒãã«æ€çŽ¢ããŒãžã§ã[
å°å ]ããããããŠã³ãªã¹ããã[
ããã²ãŒã·ã§ã³ããŒã]> [ãã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡]ãéžæããæ€çŽ¢ããã¹ãããã¯ã¹ã«æ€çŽ¢ãªã¹ãã®ååãå
¥åããå¿
èŠããããŸãã ããšãã°ã次ã®å³ã«ç€ºãããã«ããæåããšå
¥åããŠããæ€çŽ¢ãã¿ã³ãã¯ãªãã¯ã§ããŸãã
å³ 5.ãªãœãŒã¹ããããã£ã®ãªã¹ãã®æ€çŽ¢ãå®è¡ããŸããWindows PowerShellã䜿çšããŠãªãœãŒã¹ããããã£ãªã¹ããäœæããã³æ§æãã
å°ãåã«è¿°ã¹ãããã«ãã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠå®è¡ããæäœãšãŸã£ããåãæäœããWindows PowerShellãªã©ã®ãã°ãããããŒã«ã䜿çšããŠå®è¡ã§ããŸããWindowsPowerShellã¯ãå€ãè¯ãã³ãã³ãã©ã€ã³ãå€ãã®ã·ã¹ãã 管çè
ã«æ¢ã«çœ®ãæããŠããŸãã ãããã£ãŠããªãœãŒã¹ããããã£ãªã¹ãèªäœã®ãªããžã§ã¯ãã管çããã«ã¯ã
New-ADResourcePropertyList ïŒãªãœãŒã¹ããããã£ã®æ°ãããªã¹ãã®äœæãæ
åœïŒã
Set-ADResourcePropertyList ïŒããããããªãœãŒã¹ããããã£ã®æ¢åã®ãªã¹ãã®å€æŽïŒã
Remove-ADResourcePropertyListãªã©ã®ã³ãã³ãã¬ããã䜿çšã§ããŸããã¡ããããªããžã§ã¯ãèªäœãåé€ããããšãç®çãšããŠããŸãã ããã«ãæ¢åã®ãªãœãŒã¹ããããã£ãªããžã§ã¯ãããªãœãŒã¹ããããã£ã®æ¢åã®ãªã¹ãã«
远å ããã«ã¯ã
Add-ADResourcePropertyListMemberã³ãã³ãã¬ããã䜿çšã§ããŸãïŒãªãœãŒã¹ããããã£ã®åé€ã«ã¯
Remove-ADResourcePropertyListMemberã³ãã³ãã¬ããã䜿çšãããŸãïŒã
次ã«ã2ã€ã®ã³ãã³ãã¬ããã䜿çšããæ¹æ³ãèŠãŠã¿ãŸãããããªãœãŒã¹ããããã£èªäœã®ãªã¹ãã®ãªããžã§ã¯ããäœæããæ¹æ³ãšãæ¢åã®ãªã¹ãã«ãªãœãŒã¹ããããã£ã远å ããæ¹æ³ã§ãã
ãªãœãŒã¹ããããã£ã®æ°ãããªã¹ããäœæãããã®å Žåãäžèšã®ã³ãã³ãã¬ããã䜿çšããŠãæ°ããã¡ã³ããŒã远å ããã«ãªããžã§ã¯ãã®ã¿ãäœæã§ããŸãã ã€ãŸããæ¬¡ã®ã³ãã³ããå®è¡ãããŸãã
New-ADResourcePropertyList -Name "Second TEST RPL" -Description " " -ProtectedFromAccidentalDeletion $true
ååãšããŠãããã§
Nameãã©ã¡ãŒã¿ãŒã¯äœæããããªããžã§ã¯ãã®ååãæ
åœãã
Descriptionã¯ãã®èª¬æã§ããããã©ã¡ãŒã¿ãŒ
㯠ProtectedFromAccidentalDeletionã§ãã以åã®èšäºã§æ¢ã«ç¥ã£ãŠããããã«ããªããžã§ã¯ããåé€ããä¿è·ããããšãç®çãšããŠããŸãã ã³ãã³ãã®åºåã¯éåžžã«åçŽã§ããã€ãŸãããšã©ãŒã衚瀺ãããªãå Žåããªããžã§ã¯ãã¯æ£åžžã«äœæãããŠããŸãã
äœæããããªãœãŒã¹ããããã£ãªã¹ããªããžã§ã¯ããžã®æ¢åã®ãªãœãŒã¹ããããã£ã®è¿œå ãã®ã¿ã¹ã¯ãå®è¡ãããšã䜿çšãããã³ãã³ãã¬ãããšãã®ãã©ã¡ãŒã¿ãŒã¯ãäžèŠè€éã«èŠãããããããŸããããå®éã«ã¯ããã§ã¯ãããŸããã ããã§ã¯ããªãœãŒã¹ããããã£ãªã¹ãèªäœã®ãªããžã§ã¯ããžã®LDAPãã¹ãæ£ããæå®ãã远å ããã¡ã³ããŒãæ£ããæå®ããããšããéå§ããå¿
èŠããããŸãã ãããæ¬è³ªçã«ãã¹ãŠã§ãã ãªãœãŒã¹ããããã£ã®ãªã¹ãã®ãªããžã§ã¯ãã«Regionãªããžã§ã¯ãã远å ãããšãäŸã¯æ¬¡ã®ããã«ãªããŸãã
Add-ADResourcePropertyListMember -Identity:"CN=Second TEST RPL,CN=Resource Property Lists,CN=Claims Configuration,CN=Services,CN=Configuration,DC=biopharmaceutic,DC=local" -Members:"CN=Region_88d0b81428dcc599,CN=Resource Properties,CN=Claims Configuration,CN=Services,CN=Configuration,DC=biopharmaceutic,DC=local"
ããã§ã
Identityãã©ã¡ãŒã¿ãŒã䜿çšãããšãã¡ã³ããŒã远å ãŸãã¯åé€ãããªãœãŒã¹ããããã£ãªã¹ãã®ãªããžã§ã¯ããæå®ã§ãã
Member sãã©ã¡ãŒã¿ãŒã䜿çšãããšã远å ãŸãã¯åé€ãããªãœãŒã¹ããããã£ãªããžã§ã¯ããæå®ã§ããŸãã
次ã®å³ãããããããã«ãããã2ã€ã®ã³ãã³ãã¬ããã¯æ¬¡ã®ããã«æ©èœããŸãã
å³ 6.ãªãœãŒã¹ããããã£ãäœæãããªãœãŒã¹ããããã£ã®ãªã¹ãã®ãªããžã§ã¯ãã«è¿œå ããããã®ã³ãã³ãã¬ããã®åºåãã¡ã€ã«ã®åé¡ãšãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒã®æŠèŠ
éåžžã«å€ãã®å Žåããã¡ã€ã«ã¹ãã¬ãŒãžã管çãã管çè
ã¯ãä¿åãããããŒã¿éã®å¢å ããã®ãããªããŒã¿ã®ä¿åãšç®¡çã®ã³ã¹ãã«åœ±é¿ããå¯èœæ§ããããšããäºå®ã«é¢é£ããããŸããŸãªåé¡ã«çŽé¢ããŸããå人çãªãã¡ã€ã«ãææžãææªã®å Žåãã€ãŸãæ
å ±æŒããã
ãã€ã¯ããœããã¯ãã®åé¡ãèªèããããŒãããŒäŒæ¥ã®èª¿æ»ã䜿çšããŠããã¡ã€ã«ãµãŒããŒã«çŽæ¥ä¿åãããŠããæ°åã®ãã¡ã€ã«ã®ã³ã³ãã³ãã«åºã¥ããŠããŒã«ã©ã€ãºã§ããç¹å®ã®ã¡ã«ããºã ããµãŒããŒãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã«å®è£
ããå¿
èŠããããšããçµè«ã«éããŸãããäŒç€Ÿã®ããžãã¹ããŒãºã«é¢é£ããŠããŸãã äžèšã§èª¬æããåé¡ã«åºã¥ããŠãWindows Server 2008 R2ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ããçµç¹ãç¹å®ã®ããããã£ãå²ãåœãŠãŠãã¡ã€ã«ãåé¡ããWindowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ç¹å®ã®ã¡ã«ããºã ã䜿çšããŠç¹å®ã®æ©èœãå®è¡ã§ããããã«ãã
ãã¡ã€ã«åé¡ã€ã³ãã©ã¹ãã©ã¯ãã£ãªã©ã®ã€ãããŒã·ã§ã³ãæåã«ç»å ŽããŸãã宿ããåé¡ã«åºã¥ããŠããã®ãããªãã¡ã€ã«ã䜿çšããã¢ã¯ã·ã§ã³ã
ãã¡ã€ã«åé¡ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¯ãåé¡ããããã£ã®æ±ºå®ããã¡ã€ã«ã®èªååé¡ãã·ããªãªãå ŽæããŸãã¯ã³ã³ãã³ãã«åºã¥ãåé¡ãããã³åæããŒãžã§ã³ã§å®è£
ããããã¡ã€ã«ç®¡çã¿ã¹ã¯ã®é©çšãªã©ã®æ©èœãå«ãŸããŸããå®è¡ãããåé¡ã«åºã¥ããã«ã¹ã¿ã ã³ãã³ããããã³åé¡ããããã¡ã€ã«ã®ååžãæãå€ã瀺ããã¹ãŠã®çš®é¡ã®ã¬ããŒãã®çæ ãã¡ã€ã«ãµãŒããŒã
ãã¡ã€ã«åé¡ã¯ãªãã·ã§ã³ã§ããããã€ãããã¯ã¢ã¯ã»ã¹å¶åŸ¡ãªã©ã®ãã¯ãããžãŒãå®å
šã«å®è£
ããå Žåã«æšå¥šãããããã»ã¹ã§ãã ãã®ã·ãªãŒãºã®æåã®èšäºã§æ¢ã«èª¬æããŠããããã«ããã¡ã€ã«åé¡ã¯ãäŒæ¥ãªãœãŒã¹ã®äœ¿çšãæå³ãããç®çã®ããã«ãæãå¹ççãªæ¹æ³ã§è¿œè·¡ãã責任ããããŸãã ã€ãŸãããã®æ®µéã§ãåé¡ããæ
å ±ãšç¹å®ã®ã±ãŒã¹ã«é©ããå顿¹æ³ã決å®ããå¿
èŠããããŸãã ååãšããŠãããã¯ãŸãã«Active DirectoryãµãŒããŒã®å
šäœç®¡çã³ã³ãœãŒã«ã®æ©èœãWindows PowerShellã®æ©èœã䜿çšããå¿
èŠã®ãªãããã»ã¹ã§ãã ãªããã ããã«ã€ããŠã¯æ°åã§ããããŸãã
ãŸããè«ççãªè³ªåã¯ããã¡ã€ã«ã®åé¡ã ãã§ãªãããªãœãŒã¹ããããã£ãªã©ã®ãªããžã§ã¯ãéã«ã©ã®ãããªçš®é¡ã®æ¥ç¶ãååšããå¯èœæ§ããããããããŸããã å®éããªãœãŒã¹èªäœã®ããããã£ã䜿çšããŠãäŒæ¥ã®ãã¡ã€ã«ããã©ã«ããŒã®æ€èšŒã¹ããŒãã¡ã³ããèšå®ã§ããŸãã ãåç¥ã®ããã«ããã®ãããªæ€èšŒã¹ããŒãã¡ã³ãã¯ããªãœãŒã¹ããããã£ãäœæãããšãã«èªåã§æå®ããå€ã§ãã ãšããã§ããªãœãŒã¹ããããã£ã«ã¯ãã°ãããæ©èœããããŸããã€ãŸããç¹å®ã®ãã¡ã€ã«ã®ã«ã¹ã¿ãã€ãºãããæ€èšŒã¹ããŒãã¡ã³ãã¯ãNTFSãã¡ã€ã«ã·ã¹ãã ããå¥ã®ãã¡ã€ã«ã·ã¹ãã ã«ã³ããŒãŸãã¯ç§»åãããå Žåã§ãæ·»ä»ãããŸãããªãœãŒã¹ã¯ã¿ãŒã²ãããã¡ã€ã«ã®ä»£æ¿ããŒã¿ã«ä¿åãããŸãã
ã¿ãŒã²ãããã¡ã€ã«ã«ç¹å®ã®ã¡ã¿ããŒã¿ãã¡ã€ã«ãæ§æããå Žåããã¡ã€ã«åé¡ã€ã³ãã©ã¹ãã©ã¯ãã£ã«çŽæ¥é¢é£ããã®ã¯ããŸãã«ãªãœãŒã¹ã®ããããã£ã§ãã ãŸããæ¢ã«åé¡ãããŠãããã¡ã€ã«ã¯ãåçã¢ã¯ã»ã¹å¶åŸ¡ã®ãã¹ãŠã®æ©èœãç°¡åã«äœ¿çšããæ©èœãªã©ãå¿
èŠã«å¿ããŠç®¡çã§ããŸãã
äºåæªçœ®
åé¡ã®äºå段éã®1ã€ã¯ããªãœãŒã¹ããããã£ãªããžã§ã¯ãèªäœã䜿çšãããªãœãŒã¹ããããã£ãªã¹ãã®æ£ç¢ºãã€å®å
šãªæ§æã§ããæ¢ã«èª¬æããããã«ããããã¯ãã¡ã€ã«åé¡ããã»ã¹èªäœã«é¢äžããããã§ãã ãããŠãããã©ã«ãã®ãªãœãŒã¹ããããã£ãäœæãŸãã¯æå¹ã«ããŠãäœæãããªã¹ãã«è¿œå ããå¿
èŠãããããããã®æ®µéã§Active DirectoryãµãŒããŒã®å
šäœç®¡çã³ã³ãœãŒã«ãŸãã¯Windows PowerShellã䜿çšããå¿
èŠããããŸãã
å®çŸ©æžã¿ã®ãªãœãŒã¹ããããã£ãæå¹ã«ããã«ã¯ããµãŒããŒã®å
šäœç®¡çã®[
ãªãœãŒã¹ããããã£]ããŒãã«ç§»åããå¿
èŠãªãªãœãŒã¹ããããã£ãªããžã§ã¯ããéžæããæ¬¡ã®å³ã«ç€ºãããã«ããã®ã³ã³ããã¹ãã¡ãã¥ãŒãåŒã³åºããŠ[
æå¹å]ã³ãã³ããéžæããå¿
èŠããããŸãã
å³ 7.ç¡å¹åããããªãœãŒã¹ããããã£ã®æå¹åããã«ããã®äŸã§ã¯ã
Companyã
Departmentãªã©ã®ãªãœãŒã¹ããããã£ãå«ãŸããŠããããªãœãŒã¹ããããã£ã®ãªã¹ãã«è¿œå ãããŠããããšãåæãšããŠããŸãã
Windows PowerShellã®æ©èœã«ç§»ããŸãããã åè¿°ããããã«ãWindows PowerShellãªã©ã®ããŒã«ã䜿çšãããšãActive DirectoryãµãŒããŒã®å
šäœç®¡çã䜿çšããŠçŽæ¥å®è¡ã§ããæ©èœãšåãæ©èœããã¹ãŠäœ¿çšã§ããŸãã ã€ãŸãããªãœãŒã¹ããããã£ã®ç¹å®ã®ãªããžã§ã¯ããããšãã°
å人䜿çšãå«ããã«ã¯ã次ã®ã³ãã³ããå®è¡ããå¿
èŠããããŸãã
Set-ADResourceProperty -Enabled:$true -Identity:"CN=PersonalUse_MS,CN=Resource Properties,CN=Claims Configuration,CN=Services,CN=Configuration,DC=biopharmaceutic,DC=local" -Server:"DC.biopharmaceutic.local"
ã芧ã®
ãšãã ã
Enabledãã©ã¡ãŒã¿ãŒã䜿çšãããšã
Identityãã©ã¡ãŒã¿ãŒã䜿çšããŠæ¢ã«å®çŸ©ãããŠãããªããžã§ã¯ãèªäœãæå¹ã«ã§ããããšã«æ³šæããŠãã ããã
ãã¡ã€ã«åé¡ããã»ã¹
æåã®èšäºã§ããããã®åé¡ãå®è¡ããæ¹æ³ã¯ããã€ããããšè¿°ã¹ãŸããã ãããã®æ¹æ³ã¯æ¬¡ã®ãšããã§ãã
- æååé¡ã ã€ãŸãããããæãç°¡åãªæ¹æ³ã§ãããåé¡ããããã¡ã€ã«ã®ããããã£ãã¡ã€ã«ã®[ åé¡ ]ã¿ãã䜿çšããŠãäŒæ¥ãã¡ã€ã«ãæåã§åé¡ããæ©äŒãäžããããŸãã ãã®æ¹æ³ã«ã€ããŠè©³ãã説æããŸãã
- å Žæã«åºã¥ãåé¡ã çŸåšã®ãã¡ã€ã«å顿¹æ³ã¯ããã¡ã€ã«ã®ããããã£ãã€ã¢ãã°ã®å¯Ÿå¿ããã¿ãã䜿çšããŠæåã§ãã¡ã€ã«ãåé¡ããããšãšãäœæããåé¡ã«ãŒã«ã§ãã©ã«ããŒåé¡åã䜿çšããããšã®äž¡æ¹ã§äœ¿çšã§ããŸãã
- ã³ã³ãã³ãããŒã¹ã®åé¡ãšåæ§ã«ã åæ§ã«ãããã¯ãåé¡ã«ãŒã«èªäœã§ã³ã³ãã³ãåé¡åã䜿çšããŠäžè¬çã«å±éãããæãè峿·±ãéäžåæ£æ¹åŒã§ãã ãã¡ã€ã«ãåé¡ããããã®ããŒã«ã®ã»ããã«ã¯ããã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒãªã©ã®ããŒã«ã䜿çšããŠæ€åºããã³æ§æã§ããå人ããŒã¿ã決å®ããããã®çµã¿èŸŒã¿ã«ãŒã«ãå«ãŸããŠããŸãã
ãã¡ã€ã«ãåé¡ããããã»ã¹ã«ç§»ããŸãããã ãããŠãç§ãã¡ã¯ä»ããå§ããŸã
æåãã¡ã€ã«åé¡
æååé¡ããã»ã¹ã¯éåžžã«ç°¡åã§ãã ãŸãããã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒãæåã§ãã¡ã€ã«ãåé¡ã§ããããã«ããå¿
èŠããããŸãããã®åŸãç©çãŸãã¯è«çãŠãããã«å¿ããŠãå¿
èŠãªã³ã³ãã¥ãŒã¿ãŒã䜿çšã§ãããªãœãŒã¹ããããã£ã®ç¹å®ã®ãªã¹ããå®çŸ©ã§ããŸããæçµçã«ããŠãŒã¶ãŒãŸãã¯èš±å¯ããã人ãç¹å®ã®ãã¡ã€ã«ãŸãã¯ãã©ã«ããŒã ããã¯ãã¹ãŠéåžžã«ã·ã³ãã«ã«èŠããŸãã ãã®å Žåãäœãããå¿
èŠãããããã¹ãããããšã«èŠãŠã¿ãŸãããã
- ãŸãã ã°ã«ãŒãããªã·ãŒç®¡çã¹ãããã€ã³ãéããå¿
èŠãªãŠãããã®ã°ã«ãŒãããªã·ãŒãªããžã§ã¯ããäœæããå¿
èŠããããŸããããã«ããããã¡ã€ã«ã®æååé¡ã«çŽæ¥é¢é£ãã2ã€ã®ãã©ã¡ãŒã¿ãŒã決å®ãããŸãã ããšãã°ããã®å Žåããã®ãããªãªããžã§ã¯ãã¯ããã¡ã€ã³å
šäœã«é¢é£ä»ããããã°ã«ãŒãããªã·ãŒãªããžã§ã¯ãã File Classification ãã«ãªããŸãã ãã®ãããªGPOãäœæããããããããéžæããŠã°ã«ãŒãããªã·ãŒç®¡çãšãã£ã¿ãŒãéããŸãã
- 衚瀺ãããGPMEã¹ãããã€ã³ã§ãã ã³ã³ãã¥ãŒã¿ãŒã®æ§æ \ ããªã·ãŒ \ 管ççšãã³ãã¬ãŒã \ ã·ã¹ãã \ ãã¡ã€ã«åé¡ã€ã³ãã©ã¹ãã©ã¯ã㣠ãããŒãïŒ ã³ã³ãã¥ãŒã¿ãŒæ§æ \ ããªã·ãŒ \ 管ççšãã³ãã¬ãŒã \ ã·ã¹ãã \ ãã¡ã€ã«åé¡ã€ã³ãã©ã¹ãã©ã¯ã㣠ïŒã«ç§»åããå¿
èŠããããŸããã°ã«ãŒãããªã·ãŒèšå®ããããããæ§æããŸãã 圌ãã¯äœã§ããïŒ
- ãã¡ã€ã«åé¡ã€ã³ãã©ã¹ãã©ã¯ãã£ïŒãšã¯ã¹ãããŒã©ãŒã®åé¡ã¿ãã衚瀺ããŸã ã ãã®ããªã·ãŒèšå®ã䜿çšãããšãã¿ãŒã²ããã³ã³ãã¥ãŒã¿ãŒã§ãéžæãããã¡ã€ã«ã®ããããã£ãã€ã¢ãã°ããã¯ã¹ã«[ åé¡ ]ã¿ãã衚瀺ã§ããããã«ãªããŸãã ãã®ãã©ã¡ãŒã¿ãŒã«ã¯ãªãã·ã§ã³ãã»ãšãã©ãªããããèšå®ããã«ã¯ãã¹ã€ãããã æå¹ ããªãã·ã§ã³ã«èšå®ããã ãã§ãã æ¬¡ã®å³ãããããããã«ãæ§æãããããªã·ãŒèšå®ã¯æ¬¡ã®ãšããã§ãã

å³ 8.æ§æãããåé¡ã¿ãã®è¡šç€ºããªã·ãŒèšå®
- ãã¡ã€ã«åé¡ã€ã³ãã©ã¹ãã©ã¯ãã£ïŒåé¡ããããã£ãªã¹ããæå®ããŸã ã æ¬¡ã«ããã®ããªã·ãŒèšå®ã䜿çšããŠãéžæããçµç¹åäœã«å¯Ÿå¿ããã³ã³ãã¥ãŒã¿ãŒãšå
±ã«é©çšããããªãœãŒã¹ããããã£ã®ç¹å®ã®ãªã¹ããå®çŸ©ã§ããŸãã ãã®ãªãã·ã§ã³ãæå¹ã«ããããšã§ã察å¿ããããã¹ããã£ãŒã«ãã«é¢å¿ã®ãããªãœãŒã¹ããããã£ã®ãªã¹ãã®ååãæå®ããå¿
èŠããããŸãã ããšãã°ã次ã®å³ã«èŠãããããã«ããã®äŸã§ã¯ãäžèšã®ããã€ãã®ã»ã¯ã·ã§ã³ã§äœæããããªãœãŒã¹ããããã£ã®ãªã¹ãã®ãªããžã§ã¯ããæå®ããŠããŸãã

å³ 9.ãã¡ã€ã«åé¡ããããã£ã®ãªã¹ãã®å®çŸ©
- ã°ã«ãŒãããªã·ãŒèšå®ãæ§æããåŸãã°ã«ãŒãããªã·ãŒç®¡çãšãã£ã¿ãŒã®ã¹ãããã€ã³ãéããŠãã³ãã³ãã©ã€ã³ïŒãŸãã¯Windows PowerShellïŒã䜿çšããããç¹å®ã®éšéã®ã³ã³ããã¹ãã¡ãã¥ãŒãããã°ã«ãŒãããªã·ãŒæŽæ°ãã³ãã³ãã䜿çšããŠãã¿ãŒã²ããã³ã³ãã¥ãŒã¿ãŒã®ã°ã«ãŒãããªã·ãŒèšå®ãæŽæ°ããå¿
èŠããããŸãã°ã«ãŒãããªã·ãŒç®¡çã¹ãããã€ã³èªäœ
- ã¿ãŒã²ããã³ã³ãã¥ãŒã¿ãŒã®Windowsãšã¯ã¹ãããŒã©ãŒã«ç§»åããåé¡ãããã¡ã€ã«ãéžæããŸãã ãã®åŸããã®ã³ã³ããã¹ãã¡ãã¥ãŒãåŒã³åºããŠããã¡ã€ã«ããããã£ãã€ã¢ãã°ããã¯ã¹ãéãå¿
èŠããããŸãã ããã§ã[ åé¡ ]ã¿ãã«ç§»åããå¿
èŠããããŸããæ¬¡ã®å³ã«ç€ºãããã«ãå
ã»ã©äœæããæåã®RPLãªããžã§ã¯ãã«å¯ŸããŠæ§æãããã®ãšåããªãœãŒã¹ããããã£ã䜿çšã§ããŸãã ããšãã°ãRegionãŸãã¯Departmentããããã£ã®å€ãæ§æã§ããŸãã

å³ 10.ãã¡ã€ã«åé¡
ãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒãšã³ã³ãã³ãããŒã¹ã®ãã¡ã€ã«åé¡
ã¹ãã¬ãŒãžãªãœãŒã¹ã«å¯ŸããèŠæ±ãå¢ãç¶ããç¶æ³ã§ã¯ãçµç¹ãããŒã¿ã«ãŸããŸãäŸåããããã«ãªãã«ã€ããŠãIT管çè
ã¯ããŸããŸã倧ããè€éãªã¹ãã¬ãŒãžã€ã³ãã©ã¹ãã©ã¯ãã£ãç£èŠããªãããä¿æããããŒã¿ã远跡ããå¿
èŠããããŸãã åãã¡ã€ã«ãå埩åŠçããå¿
èŠããããã¡ã€ã«ãæåã§åé¡ããå Žåãšã¯ç°ãªããã³ã³ãã³ãããŒã¹ã®ãã¡ã€ã«å顿¹æ³ã䜿çšãããšããã®ããã»ã¹ã®ã»ãšãã©ãèªååã§ããŸãã ãã®ã¿ã€ãã®ããŒã¿ç®¡çã«é¢é£ããã³ã¹ããšãªã¹ã¯ãåæžããããã«ã管çè
ããã¡ã€ã«ãåé¡ãããã®åé¡ã«åºã¥ããŠããªã·ãŒãé©çšã§ããç¹å®ã®ãã©ãããã©ãŒã ããã¡ã€ã«åé¡ã€ã³ãã©ã¹ãã©ã¯ãã£ã§äœ¿çšãããŸãã ãã®æ¹æ³ã䜿çšãããšãããŒã¿ç®¡çèŠä»¶ã¯ãªããžããªã®æ§é ã«åœ±é¿ãäžãããçµç¹ã¯å€åããçµæžç°å¢ããã³èŠå¶ç°å¢ã«å®¹æã«é©å¿ã§ããŸãã 管çè
ã¯ããã¡ã€ã«ã®åé¡ã«åºã¥ããŠãã€ã§ãç¹å¥ãªãã¡ã€ã«ç®¡çããªã·ãŒãèšå®ããããžãã¹ã®èŠä»¶ã«åŸã£ãŠäŒæ¥ããŒã¿ç®¡çèŠä»¶ã®ã¿ãèªåçã«é©çšã§ããŸãã ããã«ãããªã·ãŒãç°¡åã«å€æŽãããã¡ã€ã«ç®¡çã«åé¡ãµããŒãããŒã«ã䜿çšã§ããŸãã ãã®æ®µéã§ã
ãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒãªã©ã®ããŒã«ã䜿çšããå¿
èŠããã
ãŸã ã ãããäœã§ããããåºãèŠãŠã¿ãŸãããã
ãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒ
çŸåšããªãœãŒã¹ç®¡çã¯ãããŒã¿ã®ããªã¥ãŒã ãšå¯çšæ§ã®ç®¡çã ãã§ãªããäŒæ¥ããªã·ãŒã®å®è£
ãšãæ¢åã®ã¹ãã¬ãŒãžã®äœ¿ç𿹿³ã«é¢ããååãªçè§£ããæ§æãããŠããŸãã ãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒã¯ãWindows Server 2012/2012 R2ãµãŒããŒãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®åœ¹å²ã®1ã€ã§ããããããã¯ãŒã¯ã¹ãã¬ãŒãžã®äžéšãç£èŠããã³å¶åŸ¡ããã®ã«åœ¹ç«ã¡ãŸãã ãã®ãããªãããŒãžã£ã«ã¯ããããã¯ãŒã¯ã¹ãã¬ãŒãžã®æé·ã倿ããããã«äœ¿çšã§ããã¬ããŒããããããã¯ãŒã¯ã¹ãã¬ãŒãžã«é¢é£ããå¯èœæ§ã®ããä»ã®ææšãå«ãŸããŠããŸãã ãã¡ãããã¬ããŒãã¯ãã¹ã±ãžã¥ãŒã«ã«åŸã£ãŠããŸãã¯ãªã³ããã³ãã§èªåçã«çæã§ããŸãã ã€ãŸãã
ãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒã¯ã
管çè
ããµãŒããŒã«æ ŒçŽãããŠããããŒã¿ã®éãšçš®é¡ãåŠçãããã®ããŒã¿ãå¶åŸ¡ããã³ç®¡çã§ããããã«ããããŒã«ã®ã»ããã§ãã ãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒã䜿çšããŠã管çè
ã¯ããªã¥ãŒã ã®ã¯ã©ãŒã¿ãèšå®ãããã¡ã€ã«ãšãã©ã«ããŒãã¢ã¯ãã£ãã«ããã¯ããå
æ¬çãªã¹ãã¬ãŒãžã¬ããŒããäœæã§ããŸãã ãã®åŒ·åãªããŒã«ã»ããã«ããã管çè
ã¯å©çšå¯èœãªã¹ãã¬ãŒãžãªãœãŒã¹ã广çã«å¶åŸ¡ã§ããã ãã§ãªããçµç¹ã®ããªã·ãŒã®å€æŽãèšç»ããã³å®è£
ããããšãã§ããŸãã
ãã®èšäºã®åŸåã§ã¯ãFSRMã䜿çšããŠãã¡ã€ã«ãåé¡ããæ¹æ³ã«ã€ããŠã®ã¿åŠç¿ããŸããããã®ãããã¯ã«èå³ãããå Žåã¯ãã¯ã©ãŒã¿ãããžã¡ã³ããã¯ã©ãŒã¿ãã³ãã¬ãŒããããã¯ããã®ãµã€ã¯ã«ãšã¯ç¬ç«ããå¥ã®èšäºã®ãã£ã«ã¿ãŒäŸå€ãå«ããã¡ã€ã«ã°ã«ãŒããªã©ã®ãããã¯ãæ€èšã§ããŸãããã¡ã€ã«ããã¯ãã«ã¹ã¿ã ãã¡ã€ã«ç®¡çã¿ã¹ã¯ãå«ããã¡ã€ã«æå¹æéã¿ã¹ã¯ãããã³ããŸããŸãªã¬ããŒãæ©èœãšã¬ããŒãçæããã»ã¹ã
仿¥ã¯ããã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒèªäœã®ã€ã³ã¹ããŒã«ãšãã¡ã€ã«åé¡ã®æäœã«ã€ããŠã®ã¿èª¬æããŸãã
ãã®ããŒã«ã®ã€ã³ã¹ããŒã«ã¯éåžžã«ç°¡åã§ãã
FSRMãããŒãžã£ãŒãã€ã³ã¹ããŒã«ããã«ã¯ããµãŒããŒãããŒãžã£ãŒãéãå¿
èŠããããŸãããã®ã³ã³ãœãŒã«ãã圹å²ãšã³ã³ããŒãã³ãã®è¿œå ãŠã£ã¶ãŒããéããã€ã³ã¹ããŒã«ã®çš®é¡ãéžæãããšãã«ã圹å²ãšã³ã³ããŒãã³ããã€ã³ã¹ããŒã«ãããªãã·ã§ã³ã§åæ¢ãã衚瀺ããããµãŒããŒããŒã«ããã¿ãŒã²ãããµãŒããŒãéžæããŠããããã®ãµãŒããŒã®åœ¹å²ãéžæããããŒãžã§ãŠã£ã¶ãŒããæ¬¡ã®å³ã«ç€ºãããã«ãã®åœ¹å²ãéžæããããã¡ã€ã«ãšã¹ãã¬ãŒãžãµãŒã㹠»ïŒãã¡ã€ã«ããã³ã¹ãã¬ãŒãžã»ãµãŒãã¹ãïŒããããŠã°ã«ãŒãã§ãããå±éããããã¡ã€ã«ãµãŒãã¹ãããã³iSCSIãµãŒã㹠»ïŒãã¡ã€ã«ãµãŒãã¹ãšiSCSIãªãã·ã§ã³ã®ãã§ãã¯ããã¯ã¹ïŒãCommã® ã·ã§ãŒã«ãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ »ïŒãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ïŒæ¬¡ã«ããŠã£ã¶ãŒãã®æç€ºã«åŸãã ãã§ãã
å³ 11.ãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒã®ã€ã³ã¹ããŒã«ã³ã³ãã³ãããŒã¹ã®ãã¡ã€ã«åé¡ããã»ã¹
FSRMã«ã¯ãåé¡ã管çããããã«äœ¿çšã§ãã2ã€ã®äž»èŠãªæŠå¿µãã€ãŸããåé¡ããããã£ãšåé¡ã«ãŒã«ããããŸããåé¡ããããã£ã¯ãæå®ããããã©ã«ããŒãŸãã¯ããªã¥ãŒã å
ã®ãã¡ã€ã«ã«å€ãå²ãåœãŠãããã«äœ¿çšãããŸããããŒãºã«å¿ããŠãé©åãªããããã£ã¿ã€ããéžæã§ããŸããå®éããããã®åé¡ããããã£ã¯ããªãœãŒã¹ããããã£ããŒãã§äœæããããªãœãŒã¹ããããã£ã§ããActive Directory Central Administration ConsoleããªãœãŒã¹ããããã£ãªã¹ãã«è¿œå ãããŸããããããã£ãŠãéžæã§ããããããã£ã«ã¯å€ãã®çš®é¡ããããŸããããã«ããã®ã³ã³ãœãŒã«ãããçµç¹ã®ããŒãºã«åºã¥ããŠç¬èªã®ããŒã«ã«ããããã£ã¿ã€ããäœæã§ããŸããåã®èšäºã§èª¬æãããªãœãŒã¹ããããã£å€ã®ã¿ã€ãã®å Žåãšåæ§ã«ãYes / NoãDate-timeãNumericãOrdered listãStringãMultiple selectionãMultiple linesãªã©ã®åé¡ããããã£ã®ã¿ã€ããåºå¥ã§ããŸãããããããã¹ãŠã®ã¿ã€ãã®èª¬æã¯åã®èšäºã«èšèŒãããŠããã®ã§ããããã«ã€ããŠè©³ãã説æããæå³ã¯ãããŸãããæ¬¡ã®å³ã«ç€ºãããã«ãFSRMãããŒãžã£ãŒã®[ åé¡ãããã㣠]ããŒãã§ã以åã«äœ¿çšãããã¹ãŠã®ãªãœãŒã¹ããããã£ãããã«èŠã€ããããšãã§ããŸããããšãã°ãäœæããRegionããããã£ã¯æ¬¡ã®ãšããã§ãã
å³ 12. FSRMãããŒãžã£ãŒã®åé¡ããããã£ããŒãïŒåé¡ã«ãŒã«ã¯ããã¡ã€ã«ã«åé¡ããããã£ãå²ãåœãŠãŸããäœæããååé¡ã«ãŒã«ã«ã¯ãã©ã®ãã¡ã€ã«ãç¹å®ã®ã«ãŒã«ã«é©çšããã©ã®åé¡ããããã£ããããã«å²ãåœãŠãããæ±ºå®ããç¹å®ã®æ
å ±ãå«ããå¿
èŠããããŸããåã«ãŒã«ã«ã¯ãäžæã®åé¡ããããã£ãå«ããããšãã§ãããã¡ããããã®ãããªããããã£ã®å€ã決å®ã§ããŸããåé¡ã«ãŒã«ã¯ããªã³ããã³ããŸãã¯ã¹ã±ãžã¥ãŒã«ã®2ã€ã®æ¹æ³ã§å®è¡ã§ããŸãããããã®å Žåã§ããåé¡ã®éå§ãéžæãããšããã®åé¡ã§ã¯ãç¶æ
ããªã³ã«ããŠæ§æãããã¹ãŠã®ã«ãŒã«ã䜿çšãããŸããåé¡ã¹ã±ãžã¥ãŒã«ãèšå®ãããšããã¡ã€ã«åé¡ã«ãŒã«ã«åŸãæéééãæå®ã§ãããµãŒããŒãã¡ã€ã«ã宿çã«åé¡ãããŸãŸã«ããŠãåžžã«åé¡ãèªèã§ããããã«ããŸããæ¬¡ã«ããã®ãããªã«ãŒã«ãäœæããæ¹æ³ãæ£ç¢ºã«ç¢ºèªããŸãããããã£ãŠãæåã®åé¡ã«ãŒã«ãäœæããã«ã¯ãæ¬¡ã®æé ã«åŸãå¿
èŠããããŸãã- FSRM « » ( Classification Rules ), , « » ( Create Classification Rule ), :

å³ 13.
- « » ( Create Classification Rule ) , . :
- «» (General) . , , , , , . :
- ( Rule name ) . . , «First rule» ;
- (Enabled) . , , . , .
- (Description) . , , . , , , « , ».
:

å³ 14. «»
- «» (Scope) . , . , « » « » ( Add Remove ). . , , , , , , .
« » ( Set Folder Management Properties ), . , , , , , , , . , , , , , . , , F:\Photo :

å³ 15. «»
- «» (Classification) . . :
- « » ( Choose a method to assign a property to files ). , , Windows Server 2012/2012 R2. :
- Windows PowerShell ( Windows PowerShell classifier ). Windows PowerShell, , , . , Windows PowerShell . , , . , , ;
- (Folder classifier) . , . , , , , , Los Angeles Region ;
- (Content classifier) . , , , . , , . , , «» ( Configure ). , ;
- «» « » ( Choose a property to assign to files ). , . « Region »;
- « » ( Specify a value ). , , , . « Los Angeles », , , Windows PpowerShell, , ;
- « » ( Configure ) « » ( Classification Parameters ). , , . :
- (RegularExpression) . , . , , , . .NET. , , , . , «\d\d\d» . , , http://msdn.microsoft.com/en-us/library/ae5bf541.aspx , . , \d :. , , : 111-22-3333. , \d , 111 \d{3} 111, , : \d{3}-\d{2}-\d{4} . ;
- (StringCaseSensitive) . . , Top Secret! , ;
- (String) . , , . , Top Secret .
. , , , , «» «», .
( Minimum Maximum Occurrences ) . , . , 1.
:

å³ 16.
- « » ( Evaluation Type ). « » ( Re-evaluate existing property values ), . , ? , , , . , , - , . , :
- ( Overwrite the existing value ). , , , , . , , . , , , , , . â « » « », , .
- (Aggregate the values) . , , , . , , . , , , , , . .
, , , :

å³ 17. « »
- «» FSRM « » ( Run Classification With All Rules Now ) . « » , « » ( Wait for classification to complete ), :

å³ 18.
- ãã©ãŠã¶ã§åé¡ã¬ããŒããéãããã¡ã€ã«ã§å®è¡ããããã¹ãŠã®æäœã衚瀺ãããŸãã以åã«å¿
èŠãªããã¹ããå«ããã¡ã€ã«ã1ã€äœæããŠãããããã¬ããŒãã«ã¯1ã€ã®ãã¡ã€ã«ã®ã¿ãåé¡ãããããšã瀺ãããŠããŸãã

å³ 19.ãã¡ã€ã«åé¡ã¬ããŒã
ãšããã§ãèªååé¡ã®ã¹ã±ãžã¥ãŒã«ãèšå®ããããšã«ãããåé¡ãå®å
šã«èªååã§ããŸãã ãããããã®å¥ã®æéã«ã€ããŠã®è©³çްã
ããã§ãå®è¡å
容ãšãã¡ã€ã«ãé©åã«åé¡ããããã©ããã確èªããå¿
èŠããããŸãããããè¡ãã«ã¯ãWindowsãšã¯ã¹ãããŒã©ãŒã«ç§»åããããã§FïŒ\ Photoãã©ã«ããŒãéãå¿
èŠããããŸãããã®ãã©ã«ãã«ã¯ã以åã«äœæãããããã¹ããã¡ã€ã«ããããŸãããã®åŸããã®ãããªãã¡ã€ã«ã®ããããã£ãã€ã¢ãã°ããã¯ã¹ãéãã[ åé¡ ]ã¿ãã«ç§»åããå¿
èŠããããŸããæ¬¡ã®å³ã«ç€ºãããã«ãçªå·111-22-3333ããã¡ã€ã«ã«è¡šç€ºãããããããã¡ã€ã«ã¯Regionããããã£ãšLos Angeleså€ã§åé¡ãããŸãããã€ãŸããæäœå
šäœãæ£åžžã«çµäºããŸããã
å³ 20.åé¡çµæãããã«
ãã®ãããæ¬¡ã®4çªç®ã®èšäºã§ã¯ãåçã¢ã¯ã»ã¹å¶åŸ¡ãªã©ã®çŽ æŽãããæè¡ã«ã€ããŠèª¬æããŸãããã®éããªãœãŒã¹ããããã£ã®ãªã¹ãã®æ§æèŠçŽ ãšç®¡çæ¹æ³ã«ã€ããŠèª¬æããŸããã Active DirectoryãµãŒããŒã®å
šäœç®¡çã³ã³ãœãŒã«ãšWindows PowerShellãªã©ã®åªããããŒã«ã䜿çšããŠããªãœãŒã¹ããããã£ã®åäžã®ãªã¹ããäœæããã³æ§æããããã§è€æ°ã®ãªãœãŒã¹ããããã£ã远å ããŸããããã®èšäºã®ç¬¬2éšã§ã¯ããã¡ã€ã«ã®åé¡ãªã©ãçµç¹ã«åçã¢ã¯ã»ã¹å¶åŸ¡ãå®è£
ããããã»ã¹ã®ãã®ãããªéèŠãªã³ã³ããŒãã³ããæ±ããŸããããã¡ã€ã«ã®åé¡ã®å®çŸ©ãšç®çã«ç²Ÿéããåé¡ã®ããããã£ãšã«ãŒã«ã«ã€ããŠãåŠã³ãŸãããå®éã«ã¯ããã¡ã€ã«ãæåã§åé¡ããæ¹æ³ãšãã³ã³ãã³ãã«åºã¥ããèªåã¢ãŒãã§åé¡ããæ¹æ³ãããã³ãã¡ã€ã«ãµãŒããŒãªãœãŒã¹ãããŒãžã£ãŒããããç°¡åã«FSRMãªã©ã®ããŒã«ã䜿çšããŠåé¡ããæ¹æ³ã«ã€ããŠèª¬æããŸãããåœç¶ãFSRMãã£ã¹ãããã£èªäœã«é¢ããå®å
šã«å
æ¬çãªæ
å ±ãæäŸããŸãïŒã€ãŸããã¯ã©ãŒã¿ãšã¯ã©ãŒã¿ãã³ãã¬ãŒãããã¡ã€ã«ãšãã¡ã€ã«ã°ã«ãŒãã®ããã¯ãèšäºã®äžéšããã¡ã€ã«ç®¡çã¿ã¹ã¯ãšã¬ããŒãã«å
ãŠããªã©ïŒãããã³ãã¡ã€ã«åé¡ïŒããã§ã¯ãç¬èªã®ããŒã«ã«æ§æããããã£ãåé¡ã¹ã±ãžã¥ãŒã«ããã©ã«ããŒç®¡çããããã£ã®ããŸããŸãªäœ¿çšäŸã®è©³çްãªçæãããã³Windows PowerShellåé¡åããã©ã«ããŒåé¡åãããã³pã®äœ¿çšäŸã瀺ããŸãã 1ã€ã®èšäºã§ã®æ£èŠè¡šçŸã®äœ¿çšã®ããŸããŸãªäŸïŒã¯ãåã«äžå¯èœã§ãããããã£ãŠãèšåããããããã¯ã®ããããã«èå³ãããå Žåã¯ããã®äžé£ã®èšäºãšã¯ç¡é¢ä¿ã«1ã€ä»¥äžã®æ°ããèšäºããéãããŸãããã®ã·ãªãŒãºã®æ¬¡åã®èšäºã§ã¯ãåŒãç¶ãåçã¢ã¯ã»ã¹å¶åŸ¡ã«ç²Ÿéããéäžã«ãŒã«ãšéäžã¢ã¯ã»ã¹ããªã·ãŒã®äœæã«ã€ããŠåŠç¿ããŸãã