æ¬é£èŒã§ã¯ãMicrosoft AzureãæäŸããIaaSïŒInfrastructure as a ServiceïŒäžã«Active Directoryãã¡ã€ã³ãµãŒãã¹ãæ§ç¯ããªãããAzure ã®ç¹åŸŽãäœ¿ãæ¹ãIaaSäžã«Active DirectoryïŒãã€ã¯ããœãããéçºãããã£ã¬ã¯ããªã»ãµãŒãã¹ãã¡ã€ã³ïŒãæ§ç¯ããéã®ãã€ã³ãã解説ããã
æçµçã«ã¯ãAzure Active DirectoryãšIaaSäžã®Active Directoryãã¡ã€ã³ã«ãããã€ããªãããªActive Directoryãæ§æããã¯ã©ãŠãäžã®ã¢ããªã±ãŒã·ã§ã³ã«å¯ŸããŠIaaSäžã®Active Directoryãã¡ã€ã³ã§èªèšŒãè¡ããããã«ãããåŸåã¯ããªããã€ã¬ãã«ã®äœæ¥ã«ãªããããã²ãã£ã¬ã³ãžããŠããã ãããã
ååãšãªãä»åã¯ãAzure IaaSäžã®ä»®æ³ãã·ã³ãã»ããã¢ãããããšãããŸã§ç޹ä»ããããªã³ãã¬ãã¹ïŒäŒæ¥ãªã©ãæ å ±ã·ã¹ãã ãèªç€Ÿèšåã§éçšããããšïŒã®ç°å¢ã§ããã°ããµãŒããç«ã¡äžããã«ã¯ããŒããŠã§ã¢ã調éããŠçŸèª¿ããDVDã¡ãã£ã¢ãããµãŒãã®ã€ã³ã¹ããŒã«ãè¡ããšããããã»ã¹ãå¿ é ã ãããåãã®ãšãããIaaSã¯ãã®ãããªé¢åãªäœæ¥ã¯å¿ èŠãªãã
ä»ååããŠIaaSãšåŒã°ããç°å¢ã䜿çšããå Žåã¯ãäžåºŠè©ŠããŠã¿ãŠããã ããããæ¬çªç°å¢ã«IaaSãå©çšãããã©ããã¯å¥ãšããŠãæ€èšŒç°å¢ãçšæã§ããªãå Žåãªã©ã«ã䟿å©ãªã¯ãã ã
ããããæ§ç¯ããã·ã¹ãã ç°å¢ã詳ãã解説ããåç»ãçšæããã®ã§ãæ¬çš¿ãšåãããŠåç §ããã ãããããªããæ¬çš¿ã§æ²èŒããŠããåç»ã¯ãã¹ãŠãã€ã¯ããœããã®ãµã€ãå ã«çœ®ãããŠããã®ã§ãå®å¿ããŠã¢ã¯ã»ã¹ããã ãããã
Azure Active Directory PremiumãšWindows Server Active Directory on IaaSã«ããHybrid IdPã®æ§ç¯
[ã¹ããã1]Microsoft Azureã¢ã«ãŠã³ããæºåãã
Microsoft Azureã¯è©äŸ¡çãæäŸãããŠããã®ã§ãã¢ã«ãŠã³ããæã£ãŠããªãå Žåã¯è©äŸ¡çã䜿ã£ãŠãã©ã€ããã ããããè©äŸ¡çãç³ã蟌ãã«ã¯ãã€ã¯ããœããã¢ã«ãŠã³ããå¿ èŠãšãªãã
ç»é²ã«ããã£ãŠã¯ã¯ã¬ãžããã«ãŒãã®çªå·ãå¿ èŠã«ãªãããè©äŸ¡çããåŸé課éãã©ã³ã«å€æŽããªãéãã課éãããããšã¯ãªããã€ãŸããè©äŸ¡çã®æéãåããŠããŸã£ãå Žåããã®ãŸãŸã«ããŠããã°èª²éã®å¿é ã¯ãªããšããããã ã
ã¢ã«ãŠã³ãã®ååŸãé£ããå Žåã¯ãå®éã®æäœæé ã確èªã§ããåç»ãçšæããã®ã§ãæ¬çš¿ãšåãããŠåç §ããã ãããã
Azure Active DirectoryãšAD on IaaSã«ãããã€ããªãã IdPã®æ§ææé
[ã¹ããã2]ä»®æ³ãããã¯ãŒã¯ãäœæãã
Azure IaaS äžã«ä»®æ³ãã·ã³ãé 眮ããéããã®ä»®æ³ãã·ã³ãå€éšããã®ã¢ã¯ã»ã¹å°çšã®ãµãŒãã§ããã°ãå¿ ãããä»®æ³ãããã¯ãŒã¯ã¯å¿ èŠã§ã¯ãªããä»®æ³ãããã¯ãŒã¯ãå¿ èŠã«ãªãã®ã¯ãä»ã®ãµãŒããšã€ã³ã¿ãŒããããçµç±ããªãããŒã«ã«ãããã¯ãŒã¯ã䜿çšããŠéä¿¡ããå Žåãããªã³ãã¬ãã¹ã®ãããã¯ãŒã¯ãšé£æºããå Žåã ã
ä»åã®æ§æã§ã¯ã3å°ã®ãµãŒããå±éãããããã¯ãµãŒãéã§ããŒã«ã«ãªéä¿¡ãè¡ãå¿ èŠãããããä»®æ³ãããã¯ãŒã¯ãäœæããªããã°ãªããªãã
ä»åã¯ã·ã³ãã«ã«1ã€ã®ä»®æ³ãããã¯ãŒã¯ã®ã¿ãäœæãããã以äžã®å³ã®ããã«Azureã®ä»®æ³ãããã¯ãŒã¯ã¯æè»ã«æ§æããããšãã§ãããæ§æãã¿ãŒã³ã¯3çš®é¡çšæãããŠããã
- Point to SiteïŒã¯ã©ã€ã¢ã³ãããçŽæ¥Azure VNET(ä»®æ³ãããã¯ãŒã¯)ã«æ¥ç¶
- Site to SiteïŒAzure VNETãšãªã³ãã¬ãã¹ã®ãããã¯ãŒã¯ãæ¥ç¶
- Azure VNET鿥ç¶ïŒç°ãªãAzure VNETéãæ¥ç¶
äžèšã®æ§æãã¿ãŒã³ã¯è€æ°ãçµã¿åãããŠäœ¿çšããããšãå¯èœã ã
ããã§ã¯ãå ·äœçãªäœæ¥æé ã玹ä»ãããã
(1)portal.azure.com ã«ã¢ã¯ã»ã¹ããAzure ã¢ã«ãŠã³ãã§ãµã€ã³ã€ã³ãã
(2)ãªãœãŒã¹ ãããŒãžã£ãŒé äžã«ä»®æ³ãããã¯ãŒã¯ãäœæ
[æ°èŠ] - [ãããã¯ãŒãã³ã°] - [ä»®æ³ãããã¯ãŒã¯] ãéžæãããããã€ã¢ãã«ããããªãœãŒã¹ ãããŒãžã£ãŒããéžæããŠãäœæããã¯ãªãã¯ããããã®ã»ãã®éžæè¢ãšããŠã¯ãã¯ã©ã·ãã¯ããçšæãããŠããããæ°ãã«äœæããç°å¢ã§ã¯ãå§ãããªãã
ãªãœãŒã¹ ãããŒãžã£ãŒãšã¯ããããã¯ãŒã¯ãã¹ãã¬ãŒãžãä»®æ³ãã·ã³ãªã©ã®ãªãœãŒã¹ã1ã€ã«ãŸãšããŠç®¡çããããã®æ©èœã ããªãœãŒã¹ ãããŒãžã£ãŒã䜿ãããšã§ãAzureäžã®ãªãœãŒã¹ã®ç®¡çäœæ¥ãåŸæ¥ãšæ¯èŒããŠå€§å¹ ã«è»œæžã§ããããªãœãŒã¹ã¯ãã³ãã¬ãŒãåããããšãå¯èœã§ãä»åŸåãæ§æã®ãµãŒã矀ãå±éããéã¯ããã³ãã¬ãŒããèªã¿èŸŒãŸããã°ããã®ãŸãŸåäžç°å¢ãæ§ç¯ããããšãã§ãããå ·äœçã«åŸããã广ã«ã€ããŠã¯ãæé ã远ããªãã解説ããŠããã
(3)ãä»®æ³ãããã¯ãŒã¯ãã®èšå®
ãä»®æ³ãããã¯ãŒã¯ã®äœæãç»é¢ã衚瀺ããããã以äžã®æ å ±ãå ¥åããã以äžãå ¥åé ç®ã«ã€ããŠç°¡åã«ç޹ä»ããã
ãååãã¯ãèå¥ã§ããååã§ããã°äœã§ãããããã ããã¯ã©ãŠãäžã®ãªãœãŒã¹ã¯ç®ã§èŠããªããã®ã§ãããèå¥åã«ãã£ãŠå€æããå¿ èŠããããããé©åœã«ä»äžããã®ã§ã¯ãªããäžç®ã§ã©ã®ãããã¯ãŒã¯ãªã®ããèå¥ã§ããããã«ããããããã§ã¯ãMy-VNETããšããã
ãã¢ãã¬ã¹ç©ºéãã¯ãã®åã®ãšããããã®ãããã¯ãŒã¯å šäœã§äœ¿çšããã¢ãã¬ã¹ç©ºéãæå³ããããã§å®çŸ©ããã¢ãã¬ã¹ç©ºéããããµãããããåãåºãããšã«ãªããããã§ã¯èŠå®å€ã§ããã10.0.0.0/16ããæå®ããã
ããµãããããã¯ãµãŒããé 眮ãããµããããã䜿çšããã¢ãã¬ã¹ç©ºéãæå®ãããããã§æå®ããã¢ãã¬ã¹ã¯ãå ã«æå®ãããã¢ãã¬ã¹ç©ºéãã«å«ãŸããŠããå¿ èŠããããGUIäžã§ã¯1ã€ããäœæã§ããªãããããšããã¢ãã¬ã¹ç©ºéãèš±ãéãç¡å¶éã«äœæã§ãããè€æ°ã®ãµãããããäœæããå Žåããã®éã®ã«ãŒãã£ã³ã°ã¯èªåçã«èšå®ããããããã§ã¯ãMy-subnet1ããšæå®ããã
ããã§1ã€æ³šæç¹ãããããµããããäžã®ä»®æ³ãã·ã³ã«ã¯ãèŠå®ã®DHCPïŒDynamic Host Configuration ProtocolïŒãµãŒãã«ããIPã¢ãã¬ã¹ãé çªïŒèŠå®ã§ã¯èµ·åããé ïŒã«å²ãåœãŠããããã€ãŸããããã§èšå®ãããµããããã®ã¢ãã¬ã¹ç©ºéãšã¯ãDHCPãµãŒããžã®ã¢ãã¬ã¹ããŒã«ã®ç»é²ã§ãããã®ã ã詳ããã¯åŸè¿°ããããä»®æ³ãã·ã³ã«éçã«IPã¢ãã¬ã¹ãå²ãåœãŠãããšã¯ã§ããªããä»®ã«ãä»®æ³ãã·ã³å ã§éçãªIPã¢ãã¬ã¹ãèšå®ããŠããããã¯èªåçã«DHCPèšå®ã«çœ®ãæãã£ãŠããŸããã§ã¯ãã¢ãã¬ã¹ãåºå®ã§ããªãã®ããšãããšããã§ã¯ãªããDHCPããå²ãåœãŠãããIPã¢ãã¬ã¹ãåºå®åïŒäºçŽïŒããããšãå¯èœã ãæé ã¯åŸè¿°ããã
ããµãã¹ã¯ãªãã·ã§ã³ãã¯ãè€æ°ã®Azureãµãã¹ã¯ãªãã·ã§ã³ãæã£ãŠããå Žåã«ä»®æ³ãããã¯ãŒã¯ãäœæãããµãã¹ã¯ãªãã·ã§ã³ãæå®ãããAzureäžã«ãªãœãŒã¹ãäœæãããšããµãã¹ã¯ãªãã·ã§ã³ã«å¯ŸããŠèª²éããããããè€æ°ã®ãµãã¹ã¯ãªãã·ã§ã³ãæã£ãŠããå Žåã¯æ³šæããªããã°ãªããªãã
ãŸãããµãã¹ã¯ãªãã·ã§ã³ãè¶ ããŠãªãœãŒã¹ãäœæããããšã¯ã§ããªããã€ãŸããä»®æ³ãããã¯ãŒã¯ãäœæãããµãã¹ã¯ãªãã·ã§ã³ãšã¯ç°ãªããµãã¹ã¯ãªãã·ã§ã³ã«ä»®æ³ãã·ã³ãé 眮ããããšã¯ã§ããªãã®ã§æ³šæãããããç»é¢ã«ã¯çè ã䜿çšããŠãããµãã¹ã¯ãªãã·ã§ã³ã衚瀺ãããŠãããããèªè ã®ãµãã¹ã¯ãªãã·ã§ã³åãšã¯ç°ãªãå¯èœæ§ãããã
ããªãœãŒã¹ ã°ã«ãŒããã¯ãäœæããä»®æ³ãããã¯ãŒã¯ãæå±ãããªãœãŒã¹ ã°ã«ãŒããæå®ãããåããŠAzureã䜿çšããå Žåã¯ãªãœãŒã¹ ã°ã«ãŒããååšããªãããããæ°èŠäœæããã¯ãªãã¯ããŠããªãœãŒã¹ ã°ã«ãŒãã®ååãæå®ãããããã§ã¯ãæ°èŠã«ãMy-RGããäœæããããã«æå®ããŠããã
ãå Žæãã¯ãAzureã®ããŒã¿ã»ã³ã¿ãŒã®ãã±ãŒã·ã§ã³ãæå³ããŠãããAzureäžçååœã«ããŒã¿ã»ã³ã¿ãŒãæã£ãŠãããã©ããéžæããŠãæ§ããªããæ¥æ¬åœå ã«ã¯ãè¥¿æ¥æ¬ããšãæ±æ¥æ¬ãã®2ã«æã«ããŒã¿ã»ã³ã¿ãŒãçšæãããŠããããã ããããããäœæããä»®æ³ãã·ã³ããæ±æ¥æ¬ãã«é 眮ãããå Žåã¯ãä»®æ³ãããã¯ãŒã¯ããæ±æ¥æ¬ãã«ããªããã°ãªããªããä»åã¯ãæ±æ¥æ¬ããéžæããã
以äžã®é ç®ã®å ¥åãå®äºããããäœæããã¯ãªãã¯ããã30ç§çšåºŠã§ä»®æ³ãããã¯ãŒã¯ãäœæãããã
(4)DNS ãµãŒããŒã®èšå®
次ã«ãä»®æ³ãããã¯ãŒã¯ã§äœ¿çšããDNS ãµãŒããŒãæå®ãããæ¢å®ã§ã¯ãAzureãçšæããŠããDNSã䜿çšããããActive Directoryãã¡ã€ã³ãæ§ç¯ããã«ã¯ãã«ã¹ã¿ã DNSãã䜿çšããå¿ èŠãããããçŸæç¹ã§ã¯Azure DNSã®ãŸãŸã§ããã
以äžã§ãã¹ããã2ãŸã§ã®äœæ¥ãçµäºãšãªãããŸã ãã¹ãããã¯ç¶ãã®ã ãããããã«ã€ããŠã¯æ¬¡åã«èª¬æãããã
ç·šéåå:ãŠããŸã³
å®çŽ é äž
æ¥æ¬ãã€ã¯ããœãã ãã¯ãã«ã« ãšãã³ãžã§ãªã¹ã
äž»ã«ã€ã³ãã©ç³»ãã¯ãããžãŒã®æ¥æ¬åžå Žãžã®èšŽæ±ãæ åœãè¿å¹Žã¯ãããªãã¯ã¯ã©ãŠãäžã®ã¢ã€ãã³ãã£ãã£ã»ãããã€ããŒã§ããAzure Active DirectoryãæŽ»çšããã»ãã¥ãªãã£åºç€ã®ãã¶ã€ã³ãå®è£ æ¹æ³ãªã©ãã¡ã€ã³ã®ãã£ãŒã«ãã§ããã
Technetã§å人ããã°ãããŸããŸãªæè¡æ å ±ãçºä¿¡ããŠããã







