ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã§ãŠãŒã¶ãŒãèªèšŒããããšããæ¹åŒã¯å€ãã®èªèšŒåºç€ã§å©çšããããAzure Active Directory(Azure AD)ãã§ã第äžã®èªèšŒãšããŠæ¢å®ïŒå©çšãããŠããŸããæšä»ã¯ã匷åºãªãã¹ã¯ãŒããå©çšããã ãã§ã¯é²ãããšã®ã§ããªãäžæ£ãã°ãªã³ã«ã€ãªããè åšãé²ãããã«ãäºèŠçŽ èªèšŒãAzure Multi-Factor Authenticationããªã©ã®è¿œå ã®ä¿è·çãæå¹ã«ããããšãæšå¥šããŠããŸãã
远å ã®ä¿è·çãæå¹ã«ããŠããå Žåã§ãããã¡ããã第äžã®èªèšŒãšããŠå©çšãããŠãããã¹ã¯ãŒãã«ã¯ååãªåŒ·åºŠã®ãããã®ãå©çšããããšãéèŠã§ããå€ãã®æ¿åºã忥çãåçµç¹ã®ããªã·ãŒïŒã¬ã€ãã³ã¹ã§ã¯ããã¹ã¯ãŒããè€éã«ããããšããåããã¹ã¯ãŒãã䜿ãåããªãããšãªã©ãæšå¥šãããŠããŸãããããã®äŒæ¥ã§ããããããã¬ã€ãã³ã¹ã«åŸã£ãŠãçµç¹å ã®ãã¹ã¯ãŒãããªã·ãŒãã«ãŒã«ãèšå®ããŠããããšã§ãããã
ãªã³ãã¬ãã¹ã®Active Directory(AD)ã§ãããã¹ã¯ãŒãã®é·ããè€éããªã©ãããŸããŸãªèšå®ã管çè ãè¡ãããšãã§ããããããã¹ã¯ãŒãããªã·ãŒã®æ©èœãåãã£ãŠããŸãããããããªããããè€æ°ã®ãµãŒãã¹ã§äœ¿ãåããããªãããšãã£ããããªãåŸæ¥ã®ãã¹ã¯ãŒãã«ãŒã«ã§ã¯é²ããªãè匱ãªãã¹ã¯ãŒãã䜿çšãããããšãå€ã ãããŸãã
Azure ADã§ã¯ãããã«é²åãããã¹ã¯ãŒãããªã·ãŒæ©èœãæäŸãããããŸã§ã®ããªã·ãŒã§ã¯é²ãããšãé£ããã£ãè匱ãªãã¹ã¯ãŒãã®å©çšã鲿¢ããŠããŸããå ããŠããã®Azure ADã®ãã¹ã¯ãŒãããªã·ãŒã¯ãªã³ãã¬ãã¹ADã«ãé©çšãããããšãã§ããã®ã§ãã
Azure ADã®ãã¹ã¯ãŒãããªã·ãŒ
ãŸãåºæ¬çãªä»çµã¿ãšããŠãAzure ADã§ã¯ããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã«é¢ããŠã䜿çšã§ããæåãè€éããé·ããæå¹æéãªã©ãå®ããæ¢å®ã®ããªã·ãŒãå®ããããŠãããå šãŠã®ãŠãŒã¶ãŒã«é©çšãããŠããŸãã
现ããèšå®ãã§ããªãïŒ
åºæ¬çãªAzure ADã®ããªã·ãŒãèŠãŠããAzure ADã§ã¯ãããŸã现ããèšå®ãã§ããªãããšæããæ¹ããããããããŸããã
ãããªãã§ããå®ã¯Azure ADã§ã¯ããªã³ãã¬ãã¹ADã®ãã¹ã¯ãŒãããªã·ãŒã®ãããªããããããã¹ã¯ãŒãã®è€éããæ§æããããã®è©³çްãªèšå®ãæäŸããŠããŸããâ»ã
ãªã³ãã¬ãã¹ADã§ã¯ãè€éãªããªã·ãŒãADã®ç®¡çè ãããããèšå®ããŠããŸãããããããAzure ADã§ã¯ãADã®ç®¡çè ã«ä»£ãã£ãŠãAzure ADããã¹ã¯ãŒããèªåçã«åæïŒè©äŸ¡ããä»çµã¿ãå°å ¥ããŠããŸãããã®ããã管çè ã现ããèšå®ãããå¿ èŠããªãã®ã§ãã
é©åãªãã¹ã¯ãŒãããªã·ãŒãä¿ã€ããã«ã¯ãç¶ç¶çã«ãã¹ã¯ãŒãã«é¢ããè åšãåæããŠèšå®ã®èŠçŽããå³ãå¿ èŠããããããã管çè ã®å€§ããªè² æ ã«ãªã£ãŠããŸããããã®ãããçµæçã«ãçµç¹ã§å©çšããŠãããã¹ã¯ãŒãããªã·ãŒãå€ããŸãŸãšãªããè匱ãªãã¹ã¯ãŒãã®å©çšããŠãŒã¶ãŒã«èš±ããŠããŸãããããã¯éã«ãå¿ èŠä»¥äžã«å³ãããããã¹ã¯ãŒãããªã·ãŒã§ãŠãŒã¶ãŒã®å©äŸ¿æ§ãæãªãããã±ãŒã¹ããã£ãã®ã§ãã
Azure ADã§ã¯ããã€ã¯ããœãããåéããŠããè åšã®æ å ±ãå ã«ãAzure ADãèªåçã«ãå©çšãããã¹ã¯ãŒãã®åæïŒè©äŸ¡ããããšã§ã管çè ã®è² æ ãæå°éã«ããªãããææ°ã®ä¿è·ãåããããããèšèšãããŠããŸãã
â»ãAzure AD B2Cã§ã¯ãè€éæ§ããªã·ãŒãªã©ãã«ã¹ã¿ãã€ãºããããšãå¯èœã§ãã詳现ã¯Azureã®ããã¥ã¡ã³ããAzure Active Directory B2Cã§ãã¹ã¯ãŒãã®è€éãã®èŠä»¶ãæ§æããããåç §ããŠãã ããã
å®éã®è åšã«å³ããŠãã¹ã¯ãŒããè©äŸ¡
Azure ADã§ã¯ãå®éã®è åšã®æ å ±ã«åºã¥ããŠããŠãŒã¶ãŒãèšå®ããããšãããã¹ã¯ãŒããè©äŸ¡ããé©åãªãã¹ã¯ãŒãã®ã¿èšå®ãèš±å¯ããŠããŸãããããé©åãªã¬ãã«ãæºãããŠããªããšè©äŸ¡ããããã¹ã¯ãŒããèšå®ãããå ŽåããŠãŒã¶ãŒã«åèãä¿ããŸãã
ãã¹ã¯ãŒããè©äŸ¡ããéã¯ããã€ã¯ããœãããåéããŠããè åšã€ã³ããªãžã§ã³ã¹ããèšå®ãããã°ããŒãã«çŠæ¢ãã¹ã¯ãŒããªã¹ãããšåŒã°ãããªã¹ããåºã«è©äŸ¡ãè¡ãããŸãããŠãŒã¶ãŒãèšå®ããããšãããã¹ã¯ãŒããããã®ãã°ããŒãã«çŠæ¢ãã¹ã¯ãŒã ãªã¹ããã«ç §ãããŠãã§ãã¯ããäžèŽããããã¯é¡äŒŒãããã®ãããå Žåããã¹ã¯ãŒãã®èšå®ã¯ãšã©ãŒã«ãªããŸãã
ãã®ãã°ããŒãã«çŠæ¢ãã¹ã¯ãŒããªã¹ããã®è©³çްã¯ã»ãã¥ãªãã£äžã®çç±ããå ¬éãããŠããŸããããäŸãã°ãå®éã®ãã¹ã¯ãŒãã¹ãã¬ãŒæ»æã«çŸåšããå©çšãããŠãããã¹ã¯ãŒããªã©ãä»ãŸãã«çŸå®ã«çºçããŠããæ»æã®ãã¬ã¡ããªããŒã¿ã«åºã¥ããŠãæ§æãããŠããŸãã
ç¬èªã®çŠæ¢ãªã¹ãã远å ããããšãå¯èœ
詳现ãªãã¹ã¯ãŒããè©äŸ¡ããã¢ã«ãŽãªãºã ãšã°ããŒãã«çŠæ¢ãã¹ã¯ãŒããªã¹ãã¯ããã€ã¯ããœãããç¶ç¶çã«è¡ã£ãŠããè åšåæãšèª¿æ»ã«åºã¥ããŠãéæã¢ããããŒããããŠããŸããããããäŒæ¥çµç¹ã«ãã£ãŠã¯ãã»ãã¥ãªãã£ã匷åãããããç¬èªã«çŠæ¢ããçšèªã远å ããããšããèŠæããããŸãããã€ã¯ããœããã管çããŠãããã°ããŒãã«çŠæ¢ãªã¹ããã¯ç·šéããããšãã§ããŸããããåçµç¹ã§å©çšãããã«ã¹ã¿ã ã®çŠæ¢ãã¹ã¯ãŒããã远å ã§èšå®ããç¹å®ã®çšèªãçŠæ¢ããããšãå¯èœã§ãã
å®ã¯ãã«ã¹ã¿ã ã®çŠæ¢ãã¹ã¯ãŒãã§èšå®å¯èœãªçšèªã¯ãæå€§1,000åãŸã§ã«å¶éãããŠããããã以äžã®åæ°ãèšå®ããããã«ã¯èšèšãããŠããŸãããããã¯ãäžè¬çã«ãã¹ã¯ãŒãã«å©çšããã¹ãã§ã¯ãªããšèããããçšèªã¯ãã°ããŒãã«çŠæ¢ãªã¹ãã«èšå®ãããŠããã®ã§ãã«ã¹ã¿ã ã®çŠæ¢ãã¹ã¯ãŒããªã¹ãã«è¿œå ããå¿ èŠããªãããã§ããã«ã¹ã¿ã ã®çŠæ¢ãã¹ã¯ãŒããªã¹ãã«ã¯ãçµç¹ãå©çšããŠãããã©ã³ãåã補ååãäŒç€Ÿã®æåšå°ãçµç¹å ã§å©çšãããç¹å®ã®çšèªãç¥èªãªã©ãçµç¹åºæã®çšèªã远å ããŸãã
åã«çŠæ¢ãªã¹ããšæ¯èŒããã®ã§ã¯ãªã
ãŠãŒã¶ãŒãèšå®ã詊ã¿ããã¹ã¯ãŒããè©äŸ¡ããéãåã«ããããã®ãã¹ã¯ãŒãã®çŠæ¢ãªã¹ãã«äžèŽããçšèªããããã©ãããæ¯èŒããããã§ã¯ãããŸããã
ãªã¹ãã«æå®ãããŠããçšèªãåºã«ãããŸããŸãªããªãšãŒã·ã§ã³ãçµã¿åããã§ããŠãŒã¶ãŒãèšå®ã詊ã¿ããã¹ã¯ãŒãã®å šäœçãªåŒ·åºŠãè©äŸ¡ãããŸããããšãããŠãŒã¶ãŒãæ°ãã«èšå®ããããšãããã¹ã¯ãŒãããçŠæ¢ãªã¹ãã®çšèªã«å®å šã«äžèŽãããã®ã§ã¯ãªããŠããå®éã®è©äŸ¡ã®æ®µéã§è匱ã ãšå€æããããã®ã¯èªåçã«ãããã¯ãããã®ã§ãã äŸãã°ãContoso瀟ãã瀟åã§ãããContosoãã®å©çšãçŠæ¢ããããã«ãContosoãçŠæ¢ãªã¹ãã«è¿œå ãããšããŸãããŠãŒã¶ãŒãæ°ãã«ãã¹ã¯ãŒããèšå®ããããšãããšãAzure ADã¯ãçŠæ¢ãªã¹ãã«ããçšèªãšæåãçµã¿åããããContoso!1ãããã»ãã®çšèªãšçµã¿åããããContoso!Tokyoããšãã£ãçšèªãå°ã倿Žããã ãã®ãC@ntosoããªã©ãè匱ãªããªãšãŒã·ã§ã³ã ãšå€æããå šãŠèªåçã«ãããã¯ããŸãã
Azure ADã®ç®¡çè ããèŠãã°ãã«ã¹ã¿ã ã®çŠæ¢ãã¹ã¯ãŒããªã¹ãã«åºæ¬çšèªã®ã¿ã远å ããŠããã°ãAzure ADåŽã§åæããŠèªåçã«è匱ãªçµã¿åããããããã¯ããŠãããããšããããã§ããAzure ADã®ç®¡çè ããçŠæ¢ãããçšèªãå©çšããè匱ãªçµã¿åãããèããŠèšå®ããå¿ èŠããªãããã管çã®æéãå€§å¹ ã«åæžãããŸãã
|
|
|
ãã¹ã¯ãŒã倿޿ã«è匱ãªãã¹ã¯ãŒããèšå®ããããšãããšè¡šç€ºããããšã©ãŒ |
*ã*ã*
ãã®ããã«Azure ADã§ã¯ãåŸæ¥ã®ãã¹ã¯ãŒãããªã·ãŒãããé«åºŠã§ã管çè ã®æéãå€§å¹ ã«è»œæžãããæ¹æ³ã§ãè匱ãªãã¹ã¯ãŒããæé€ã§ããä»çµã¿ãå®çŸãããŠããŸãããããŠããã®Azure ADã®ãã¹ã¯ãŒãããªã·ãŒã¯ãAzure ADã®ãŠãŒã¶ãŒã ãã§ã¯ãªãããªã³ãã¬ãã¹ADã®ãŠãŒã¶ãŒã«ãé©çšãããããšãã§ããŸãããã®è©³çްã«ã€ããŠã¯æ¬¡åïŒ
èè 玹ä»
|
|
å£å
ç±æ¢šéŠ
ãã€ã¯ããœããæ ªåŒäŒç€Ÿ ã»ãã¥ãªã㣠ã¬ã¹ãã³ã¹ ããŒã ã»ãã¥ãªã㣠ããã°ã©ã ãããŒãžã£ãŒ
ãã€ã¯ããœããæ ªåŒäŒç€Ÿã«å ¥ç€Ÿä»¥æ¥ãActive Directory, Network, èšŒææžããã³æå·åãå°éãšããWindows ãšã³ãžãã¢ãçµãŠçŸè·ãã»ãã¥ãªãã£ã®æèåäžæŽ»åãã€ã³ã·ãã³ã察å¿ã«åŸäºãCRYPTRECå§å¡ã




