ä»æ¥éåžžã«äžè¬çãªã·ããªãªãæ³åããŠã¿ãŸãããã å€ãã®ããžãã¹ã¢ããªã±ãŒã·ã§ã³ãäŒæ¥ãããã¯ãŒã¯ã«å±éãããŠããŸãã ãããã®ã¢ããªã±ãŒã·ã§ã³ã¯ãHTTPSãä»ããå€éšã¢ã¯ã»ã¹çšã«å
¬éãããŠããŸãã äŒæ¥ãããã¯ãŒã¯ã®å€éšã«ããäŒç€Ÿã®ã¢ãã€ã«åŸæ¥å¡ã¯ãWindowsãiOSããŸãã¯Androidã§å®è¡ãããŠããå人ã®ã¿ãã¬ãããããããã®ã¢ããªã±ãŒã·ã§ã³ã«æ¥ç¶ããããšèããŠããŸãã ãããã®ããã€ã¹ã¯ããã¡ã€ã³ã«å«ããããšãã§ããªããããŠãŒã¶ãŒããããå®è¡ããŸããã ãã®ãããªããã€ã¹ããäŒæ¥ã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ã®ã»ãã¥ãªãã£ã匷åããæ¹æ³ã¯ïŒ Windows Server 2012 R2ã®ããã€ã¹ç»é²ãµãŒãã¹ïŒDRSïŒã圹ç«ã¡ãŸãã
ãã®èšäºã§ã¯ãDRSã®åºæ¬ååãšã¢ãŒããã¯ãã£ã«çŠç¹ãåœãŠãŸãã èšå®ã®è©³çŽ°ã¯ãã³ãŒã¹ã
ã³ãŒãã¬ãŒãããã€ã¹ ãã®4çªç®ã®ã¢ãžã¥ãŒã«ã«èšèŒãããŠããŸã
ã ãã€ããªããè³æ Œæ
å ±ã管çããæ¹æ³ ãã
äž»ãªåé¡ã¯äœã§ããïŒ
äŒæ¥ãããã¯ãŒã¯å
ã«ã¯ãå€éšããæ¥ç¶ããããã«å
¬éãããHTTPSã¢ã¯ã»ã¹ãåããWebã¢ããªã±ãŒã·ã§ã³ããããŸãã ã©ã®ãã©ãŠã¶ããã§ãä»»æã®ãã©ãããã©ãŒã ããæ¥ç¶ããããã©ãŠã¶ãšã¢ããªã±ãŒã·ã§ã³éã®ãã¹ãŠã®ãã©ãã£ãã¯ã¯æå·åãããŸãã ããããçŸä»£ã®ã¢ãã€ã«ããã€ã¹ãç¹ã«ã¿ãã¬ããã®ãã¹ãŠã®æãããªå©ç¹ã«ã¯ããã€ãã¹é¢ããããŸãã ã©ãã«ã§ãæã¡éã¶ã®ã«äŸ¿å©ãªãã®ã¯ãç°¡åã«çŽå€±ãããçãŸãããããå¯èœæ§ããããŸãã 奜å¥å¿ã®ããã€ã¹ã®æ°ãããææè
ãã¯ãæªæã®ããã«ããŸãã¯æªæãæã£ãŠããã©ãŠã¶å±¥æŽã§URLããåŠç¿ãããããšããããšãã§ããŸãã ãŸããå人çšããã€ã¹ã§äœ¿çšãããå¯èœæ§ãé«ãä¿åãããCookieã䜿çšãããšãçµç¹ã®ã¢ããªã±ãŒã·ã§ã³ãå«ãã¢ã¯ã»ã¹ãååŸããããšã¯é£ãããããŸããã
ãã¡ã€ã³ãããã¯ãŒã¯ã§ã¯ãã°ã«ãŒãããªã·ãŒã«ãããã®ãããªç¶æ³ãç°¡åã«åé¿ã§ããŸãã ãã¡ã€ã³ããã€ã¹ãžã®ãã°ã€ã³çšã®ãã¹ã¯ãŒãã§å§ãŸããã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ããéã®èªèšŒçšã®èšŒææžã§çµãããŸãã ãã¡ã€ã³ã«å«ããããšãã§ããªãããã€ã¹ã«ã€ããŠã¯ã©ãã§ããïŒ ã¢ãããŒãã¯ç°ãªãå ŽåããããŸãããã¹ã¯ãŒããŸãã¯PINã³ãŒãã®å¿
é 䜿çšãèšå®ããŠããã€ã¹ãå
¥åããããã¿ãã¬ããã§èšŒææžãçæããŠã€ã³ã¹ããŒã«ãããã§ããŸãã ãã©ãããã©ãŒã ãç°ãªãå Žåã®ã¿ããããã®æé ã¯ç°ãªããããããITã¹ã¿ãããæåã§è¡ãå¿
èŠããããæ°ããããã€ã¹ããšã«é©åãªäžé£ã®ã¢ã¯ã·ã§ã³ãçæãããŸãã ãããŠãç§ã¯ãããã€ã¹ã®ææè
ããã®ãããªã¿ã¹ã¯ã«å¯ŸåŠã§ããããã«ããããšèããŠããŸãã
1ã€ã®è§£æ±ºçã¯ãWindows Server 2012 R2ã®DRSã䜿çšããããšã§ãã
äž»ãªã¢ã€ãã¢ã¯äœã§ããïŒ
ãµãŒãã¹ã®ååã瀺ãããã«ãDRSã¯ããã€ã¹ç»é²æé ãå®è£
ããŠããŸãã ç»é²ããã»ã¹äžã«ãDRSã¯X.509蚌ææžãçæããŸããããã¯ããã€ã¹ã«ããŠã³ããŒããããããã€ã¹ãšç»é²ãå®äºãããŠãŒã¶ãŒã®äž¡æ¹ã«é¢ããæ
å ±ãå«ãActive Directoryã«æ°ãããªããžã§ã¯ããäœæããŸãã
ãŠãŒã¶ãŒãç»é²æžã¿ããã€ã¹ããã¢ããªã±ãŒã·ã§ã³ã«æ¥ç¶ãããã³ã«ããŠãŒã¶ãŒã¯èªèšŒããïŒãã¹ã¯ãŒããå
¥åããããCookieã䜿çšãããŸãïŒã蚌ææžãæ€èšŒãããŸãã ãããŠãäž¡æ¹ã®ãã§ãã¯ã«æåããå Žåã®ã¿ããŠãŒã¶ãŒã¯ã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããŸãã å®éã2èŠçŽ èªèšŒãæ±ã£ãŠããŸãã
ãã ããããã€ãã®ç¹ã«æ³šæããããšãéèŠã§ãã
- ç»é²æé ã¯å¯èœãªéãç°¡åã§ãITã¹ãã·ã£ãªã¹ãã«ããããã€ã¹ã®äºåèšå®ã¯å¿
èŠãããŸããã
- DRSã¯ããŸããŸãªãã©ãããã©ãŒã ããµããŒãããŠããŸãã
- Windows 8.1以é
- iOS 6以é
- Android-Samsung KNOX
- Windows 7 ProïŒãã¡ã€ã³ã«å«ãŸããïŒ
- DRSã¯PKIå±éãå¿
èŠãšããŸãã
ã©ã®ããã«èŠããŸããïŒ
Windows Server 2012 R2ã§ã¯ãDRSã¯ADFSãšãšãã«ã€ã³ã¹ããŒã«ãããŸãã ADFSã¯ãäžèšã®å³ãããããããã«ãèªèšŒããã»ã¹ã§éèŠãªåœ¹å²ãæãããŸãã ã¢ããªã±ãŒã·ã§ã³ã«ç»é²ãµãŒãã¹ã䜿çšããã«ã¯ãADFSãä»ããŠèªèšŒ
ãæ§æ
ããå¿
èŠããããŸãã ã»ãã¥ãªãã£äžã®çç±ãããADFSãåãããµãŒããŒã¯éåžžäŒæ¥ãããã¯ãŒã¯å
ã«ãããããã€ã³ã¿ãŒãããããèŠæ±ãåä¿¡ããŠââADFSã«ãªãã€ã¬ã¯ãããå¢çãŸãŒã³ã«ã¯ãããã·ã³ã³ããŒãã³ããå¿
èŠã§ãã Webã¢ããªã±ãŒã·ã§ã³ãããã·ïŒWAPïŒã¯ãWindows Server 2012 R2ã®æ°ãããµãŒãã¹ã§ãããããã·ã®åœ¹å²ãæããããšãã§ããŸãã 次ã«ãADFSã¯ãŠãŒã¶ãŒèªèšŒãå®è¡ããããã€ã¹ç»é²ãæ§æãããŠããå Žåã¯èšŒææžã®æ€èšŒãå®è¡ããŸãã èªèšŒã«æåããå ŽåãADFSã¯èŠæ±ãããã¢ããªã±ãŒã·ã§ã³ã®ã¢ã¯ã»ã¹ããŒã¯ã³ãçæãããŠãŒã¶ãŒããã€ã¹äžã®ãã©ãŠã¶ãŒã«ããŒã¯ã³ãè¿ããŸãã ãã®åŸããŠãŒã¶ãŒã¯ã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããŸãã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã®èŠä»¶ã«ã€ããŠèª¬æããå ŽåãDRSã䜿çšããã«ã¯ãADã¹ããŒããæ¡åŒµããWindows Server 2012 R2ãšADFSããŒã«ãææ ŒããããµãŒããŒãå°ãªããšã1ã€æã€å¿
èŠããããŸãã
ããã€ã¹ç»é²ããã»ã¹ã次ã®å³ã«ç€ºããŸãã
Windows 8.1ãæèŒããã¿ãã¬ããã®ææè
ã®èŠ³ç¹ãããã®ããã»ã¹ãã©ã®ããã«èŠãããããããŠèå°è£ã§äœãèµ·ããããèŠãŠã¿ãŸãããã ç§ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã¯ãããã€ã¹ãäŒæ¥ãããã¯ãŒã¯ã®å€éšã«ããå Žåã«ã®ã¿ããã€ã¹ã®ç»é²ãå¿
èŠã«ãªãããã«ADFSãæ§æãããŠããŸãã ããšãã°ãã¿ãã¬ãããäŒæ¥ã®Wi-Fiã«æ¥ç¶ãããŠããå ŽåããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã«ããèªèšŒã§ååã§ãã ãããŠãã¡ããããŠãŒã¶ãŒãäŒæ¥ãããã¯ãŒã¯äžã®ãã¡ã€ã³ã³ã³ãã¥ãŒã¿ãŒããã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ããå ŽåããŠãŒã¶ãŒã«ã¯äœãå¿
èŠãããŸããã å®å
šãªã·ã³ã°ã«ãµã€ã³ãªã³ããããŸãã ãã®ãããªæ¡ä»¶ä»ãã¢ã¯ã»ã¹æ¡ä»¶ãæ§æããæ©èœã¯ãç¹å®ã®ã¢ããªã±ãŒã·ã§ã³ã«å¯ŸããŠãåé¡ã®ã·ããªãªã§ADFSã䜿çšãããã1ã€ã®é倧ãªå©ç¹ã§ãã æ¡ä»¶ä»ãã¢ã¯ã»ã¹ããªã·ãŒã®å®çŸ©æ¹æ³ã¯ãã³ãŒã¹ã
äŒæ¥ããã€ã¹ ãã®4çªç®ã®ã¢ãžã¥ãŒã«ã«èšèŒãããŠããŸã
ã ãã€ããªããè³æ Œæ
å ±ã管çããæ¹æ³ ãã
ãã®ãããäŒç€Ÿã®åŸæ¥å¡ã¯äŒç€Ÿã®å€ã«ããŠããã¡ã€ã³ã«å«ãŸããŠããªãã¿ãã¬ããã®ãã©ãŠã¶ãŒã§ãSharePointã®äŒæ¥ããŒã¿ã«ã®URLããã€ã€ã«ããŸãã WAPãä»ããèŠæ±ã¯ADFSã«ãã£ãŠãªãã€ã¬ã¯ãããããã®ãããªç»åã衚瀺ãããŸãã
ã芧ã®ãšãããADFSèªèšŒããŒãžã®èŠçŽ ãšãšã©ãŒã¡ãã»ãŒãžããŒãžïŒç»åãããŽãã¡ãã»ãŒãžããã¹ãïŒãæ§æãããŠããŸãã ãŠãŒã¶ãŒã¯ãã¡ã€ã³ã¢ã«ãŠã³ãã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããæå®ãããã°ã€ã³ã¯ãŠãŒã¶ãŒããªã³ã·ãã«åïŒUPNïŒã®åœ¢åŒã§å
¥åãããŸãã ããã€ã¹ã¯ãŸã ç»é²ãããŠããªããããã¢ã¯ã»ã¹ã¯æåŠãããŸãã
ãšã©ãŒã¡ãã»ãŒãžã®ããã¹ãã§ãã¿ãã¬ãããç»é²ããããã«ãŠãŒã¶ãŒãå®è¡ããå¿
èŠãããã¢ã¯ã·ã§ã³ã瀺ããŸããã ãããã®ã¢ã¯ã·ã§ã³ã¯ãã©ãããã©ãŒã ããšã«ç°ãªããŸãã ãããã£ãŠãiOSã®å Žåã¯ã
httpsïŒ// <adfs server name> / enrollmentserver / otaprofileã®URLã«ç§»åããã ã
ã§ã ã Windows 8.1ã®å Žåãç»é²ã¯OSã€ã³ã¿ãŒãã§ãŒã¹ã§æäŸãããŸãïŒ
PCèšå®->ãããã¯ãŒã¯->ã¯ãŒã¯ãã¬ãŒã¹ ã
Workplace joinãšåŒã°ããŸãã
[
åå ]ãã¿ã³ãã¯ãªãã¯ãããšãæ¢ã«ããªãã¿ã®ADFSèªèšŒãŠã£ã³ããŠã衚瀺ãããŸãã
Windows 8.1ã¯ã©ã®ããã«ADFSãæ€åºããŸããïŒ ãŠãŒã¶ãŒãå
¥åããUPNãããæ¥å°ŸèŸïŒãã®å Žåã¯
contosomsspb.com ãå®çŸ©æžã¿ã®ååïŒãååŸããã
enterpriseregistrationãããã«ãããã³ã°ãããOSãIPã§è§£æ±ºããããšããŠããFQDNã§ãã
enterpriseregistration.contosomsspb.comã«ãªããŸãã ãããã£ãŠããã®ãããªDRSãã£ã¹ã«ããªã¡ã«ããºã ãæ©èœãããã«ã¯ãçµç¹Aã¬ã³ãŒãã®ãããªãã¯DNSãã¡ã€ã³ã«ãååã
enterpriseregistrationã§ãããã¯ã¹ã³ã³ããŒãã³ãïŒWAPãµãŒããŒãªã©ïŒã®IPã¢ãã¬ã¹ãç»é²ããå¿
èŠããããŸãã
ãã¹ã¯ãŒããæ£ããå
¥åããããšãããã€ã¹ãç»é²ãããåã®ãŠã£ã³ããŠã«æ»ããŸããããã§ã
Workplaceåå æäœãå®äºããããšãããããŸãã
èå°è£ã§äœãèµ·ãã£ãŠããŸããïŒ ã¿ãã¬ããèªäœã§ã
蚌ææžã¹ãããã€ã³ã䜿çšããŠãæ°ãã蚌ææžã®åºçŸãæ€åºã§ããŸãã
ã¢ããªã±ãŒã·ã§ã³ã«æ¥ç¶ãããšãã«ã2çªç®ã®èªèšŒèŠçŽ ãšããŠäœ¿çšãããã®ã¯åœŒã§ãã
Active Directoryã§ã¯ã察å¿ãã蚌ææžãªããžã§ã¯ãã¯æ°ãã
RegisteredDevicesã³ã³ãããŒã«ãããŸãã ãªããžã§ã¯ãã®ååã¯CN蚌ææžãšäžèŽããŸãã ãã®ãªããžã§ã¯ãã®å±æ§ã¯ãããšãã°ADSI Editã䜿çšããŠè¡šç€ºã§ããŸãã
å±æ§ã®äžã«ã¯ãããã€ã¹åãOSã¿ã€ããšããŒãžã§ã³ãç»é²ãå®äºãããŠãŒã¶ãŒã®SIDãç»é²æ¥æãªã©ããããŸãã
ããŒã¿ã«ãžã®æ¥ç¶ãåè©Šè¡ããåã³ADFSããŒãžã«ã¢ã¯ã»ã¹ããŠãå床ADã¢ã«ãŠã³ãã®è³æ Œæ
å ±ãå
¥åããŸãã ããããä»ã§ã¯ããã¹ã¯ãŒãã®ç¢ºèªã«å ããŠã蚌ææžã®ç¢ºèªãšã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹ãæ£åžžã«å®äºããŠããŸãã
ããã«ãæåã®æ¥ç¶ã«æåãããšããŠãŒã¶ãŒã¯ãã®ã¢ããªã±ãŒã·ã§ã³ã®SSOãåãåããŸãã 圌ã¯ãã©ãŠã¶ãéãããã·ã³ãåèµ·åãããã©ãŠã¶ãå床éããURLãå
¥åããŠãè¿œå ã®è³ªåãªãã§ã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããŸãã å®éãCookieã¯æåã®èªèšŒèŠçŽ ãæäŸãã蚌ææžã¯2çªç®ã®èªèšŒèŠçŽ ãæäŸããŸãã åœç¶ãæ°žä¹
ã§ã¯ãªãããŠãŒã¶ãŒã¯ãã¹ã¯ãŒããå
¥åããŠèªåã®ä¿¡byæ§ã確èªããå¿
èŠããããŸãã ãããããã®çšèªã¯ITãå¶åŸ¡ããŸãã
ã»ãã¥ãªãã£ã«é¢ããè¿œå ã®èæ
®äºé
ã¿ãã¬ããã®çŽå€±/çé£ã®ç¶æ³ã«æ»ããŸãããã ããã€ã¹ãæ¢ã«ç»é²ãããŠããå Žåãã¢ããªã±ãŒã·ã§ã³ã«SSOãå®è£
ãããããã€ã¹ã¯ééã£ãæã«èœã¡ãŸããã æåã®é²è¡ç·ã¯ãããã€ã¹ã«å
¥ãããã®ãã¹ã¯ãŒããŸãã¯PINã³ãŒãã§ãã éãã¡ã€ã³ããã€ã¹ã®å ŽåãMicrosoft IntuneãŸãã¯å¥ã®MDMãœãªã¥ãŒã·ã§ã³ãªã©ã䜿çšããŠã匷å¶ããã¯ãæå¹ã«ã§ããŸãã ãããè¡ãããŠããªãå Žåã¯ïŒ æ»æè
ã«è¿œå ã®åãæãäžããããšãããããŸã-圌ã¯ãã©ãŠã¶ãéããŠURLãå
¥åããã ãã§ãã æããã«ããã®ãããªç¶æ³ã§ã¯ãææè
ã¯ITãµãŒãã¹ã«ã§ããã ãæ©ãéç¥ããå¿
èŠããããŸãã ITã¯äœãããŸããïŒ ããã€ãã®ãªãã·ã§ã³ãèŠãŠã¿ãŸãããã
ããã€ã¹ç»é²ãµãŒãã¹ããŸã£ãã䜿çšãããŠããªãå Žåã- å
¬éãããã¢ããªã±ãŒã·ã§ã³ãžã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã¢ã¯ã»ã¹ãå¶éã§ããŸãã ããããé·è·é¢æ
è¡äžã«å¥ã®ããã€ã¹ïŒã¡ã€ã³ã©ããããããã»ã«ã³ãã¿ãã¬ãããªã©ïŒããã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ããå¿
èŠãããå Žåã¯ã©ãã§ããããã
- ãŠãŒã¶ãŒã®ãã¹ã¯ãŒãããªã»ããã§ããŸãã ãããããããä»ã®ãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ã«ã©ã®ããã«åœ±é¿ãããã¯å¿
ãããæããã§ã¯ãããŸããã
äž¡æ¹ã®ãœãªã¥ãŒã·ã§ã³ãããã³æäŸå¯èœãªä»ã®ãªãã·ã§ã³ã¯éåžžã«é©çšå¯èœã§ãããçæ³çã§ã¯ãããŸããã
ããã€ã¹ãç»é²ãããŠããå Žåã管çè
ãADã§å€±ãããããã€ã¹ã«é¢é£ä»ãããããªããžã§ã¯ããèŠã€ããŠããªããžã§ã¯ããåé€ããããmsDS-IsEnabledå±æ§ã®ããããã£ã«å€FALSEãèšå®ããã ãã§ååã§ãã
ãã®åŸãã¢ããªã±ãŒã·ã§ã³ã«æ¥ç¶ãããšãããã€ã¹èšŒææžã¯æ€èšŒã«åæ ŒããããŠãŒã¶ãŒã¯ãšã©ãŒã¡ãã»ãŒãžãåãåããŸãã ãããã£ãŠãç¹å®ã®ããã€ã¹ãžã®ã¢ã¯ã»ã¹ããããã¯ããŸãã
ãŠãŒã¶ãŒã®ãã¹ã¯ãŒããå±éºã«ãããããæ»æè
ã«ç¥ãããããã«ãªã£ãå Žåã¯ã©ãã§ããããïŒ åœŒã®åç»é²ã劚ãããã®ã¯äœããããŸããã ãã®ã·ããªãªã«å¯ŸåŠãã1ã€ã®æ¹æ³ã¯ãMicrosoft Azure Multifactor AuthenticationïŒMFAïŒãµãŒãã¹ã䜿çšããŠããã€ã¹ãç»é²ããããšã§ãã ãã®å ŽåããŠãŒã¶ãŒã¯ããã€ã¹ãç»é²ãããšãã«ããã¹ã¯ãŒãã®å
¥åã«å ããŠè¿œå ã®ãã§ãã¯ã«åæ Œããå¿
èŠããããŸã-æºåž¯é»è©±ãžã®çä¿¡ã«å¿çããããåä¿¡ããSMSã³ãŒããå
¥åããããåã³ãªã³ã©ã€ã³ã¹ãã¢ã«ããç¹å¥ãªã¢ããªã±ãŒã·ã§ã³ïŒMulti-Fator AuthïŒã䜿çšããŸããã€ã¯ããœãããã°ãŒã°ã«ãã¢ããã«ã
ããããããã¯å¥ã®è°è«ã®ãããã¯ã§ãã
ãã®ãããWindows Server 2012 R2ã§å°å
¥ãããããã€ã¹ç»é²ãµãŒãã¹ã¯ãADãã¡ã€ã³ã«å«ãŸããŠããããããŸããŸãªOSãå®è¡ããŠããå人ã®ã¢ãã€ã«ããã€ã¹ããäŒæ¥ã¢ããªã±ãŒã·ã§ã³ã«ãªã¢ãŒãã§æ¥ç¶ããéã®ã»ãã¥ãªãã£ã¬ãã«ãè¿œå ããã®ã«åœ¹ç«ã¡ãŸãã
ADFSãšDRSã®ã€ã³ã¹ããŒã«ãšæ§æã®è©³çŽ°ã«ã€ããŠã¯ãããšãã°
ãã¡ããã芧ãã ãã ã
iOSããã€ã¹ã®æ§ææ©èœãæ¡ä»¶ä»ãã¢ã¯ã»ã¹ããªã·ãŒã®äœæãWAPã®å±éãªã©ïŒ
https://technet.microsoft.com/en-us/library/dn280939.aspx