ä»åãåã åãšååã«ç¶ãããAzure AD ãšãªã³ãã¬ãã¹ Active Directory ãšã®ãã§ãã¬ãŒã·ã§ã³ããæ§æããäœæ¥ã«ã€ããŠèª¬æãããã
2åã«ãããããAzure AD ã®æºåãã管çè IDã®äœæããã¢ã€ãã³ãã£ãã£ãã§ãã¬ãŒã·ã§ã³ãæ§æããããã®æºåãããã§ãã¬ãŒã·ã§ã³ã®æ§æããã¢ã€ãã³ãã£ãã£ãã§ãã¬ãŒã·ã§ã³ã®æ§æããŸã§è¡ã£ãã以äžãç¶ãã®äœæ¥ã解説ããã
ãŠãŒã¶ãŒIDã®åæãèšå®ãã
ãã§ãã¬ãŒã·ã§ã³ã®èšå®ãå®äºãããã«ã¯ããŠãŒã¶ãŒIDã®åæã®èšå®ãè¡ããªããã°ãªããªãã
ãŸã㯠Azure ã®æ§ããŒã¿ã«ïŒhttp://manage.windowsazure.com/ïŒã«æ¥ç¶ããŠããã ãããã å·ŠåŽã®ã¡ãã¥ãŒããŒãäžã«ã¹ã¯ããŒã«ãããšã以äžã®ãããªããŒã¯ãèŠã€ãããããã Azure AD ã®ç®¡çããŒã¿ã«ã ã
ä»åäœæãããã£ã¬ã¯ããªãã¯ãªãã¯ããããäžã®ã¿ãããããã£ã¬ã¯ããªçµ±åããã¯ãªãã¯ãããããã£ã¬ã¯ããªçµ±åç»é¢ãéããããããã£ã¬ã¯ããªåæãæ¬ã®ãã¢ã¯ãã£ãåæžã¿ããã¯ãªãã¯ããŠãåæãæå¹åããããã®éãå¿ ãç»é¢äžã®ãä¿åããã¯ãªãã¯ããŠä¿åããããšãå¿ããªãããã
次ã«ãåæããŒã«ãDS1ã«ã€ã³ã¹ããŒã«ãããAzure Portal ã® Virtual Machines ãã DS1ã«æ¥ç¶ããããæ¬çªéçšã§ã¯ãåæããŒã«ã¯ç¬ç«ãããµãŒããŒã«ã€ã³ã¹ããŒã«ããŠããã ãããããä»åã¯Azureãžã®èª²éãæããããã«DS1ã«åå± ãããããšã«ããã
DS1äžã§ãã©ãŠã¶ãèµ·åãã以äžã®URLãã Azure AD Connect ãããŠã³ããŒãããŠãã€ã³ã¹ããŒã«ãããã
https://www.microsoft.com/en-us/download/details.aspx?id=47594
ã€ã³ã¹ããŒã«ãå®è¡ãããã°ãããããšAzure AD Connect ã®ã»ããã¢ãããŠã£ã¶ãŒããèµ·åããããã©ã€ã»ã³ã¹æ¡é ããã³ãã©ã€ãã·ãŒã«é¢ãã声æã«åæãããããã§ãã¯ããŠãç¶è¡ããã¯ãªãã¯ãããã
ãç°¡åèšå®ãç»é¢ã衚瀺ãããããä»åã¯ãã§ãã¬ãŒã·ã§ã³æ§æãæåã§èšå®æžã¿ãªã®ã§åæã«é¢ããã»ããã¢ããã ããè¡ãããããã«ã¹ã¿ãã€ãºããã¯ãªãã¯ããã
ãå¿ é ã³ã³ããŒãã³ãã®ã€ã³ã¹ããŒã«ãç»é¢ã®ããªãã·ã§ã³æ§æãã§ã¯äœãéžæããå¿ èŠã¯ãªããäœãéžæããã«ãã€ã³ã¹ããŒã«ããã¯ãªãã¯ããã
å¿ é ã³ã³ããŒãã³ãã®ã€ã³ã¹ããŒã«ãå®äºãããšããŠãŒã¶ãŒ ãµã€ã³ã€ã³ãç»é¢ã衚瀺ããããããã§ã¯å¿ ããæ§æããªãã§ãã ããããéžæããŠã次ãžããã¯ãªãã¯ããã
ãAzure ADã«æ¥ç¶ãç»é¢ã§ã¯ãAzure ADã«å¯ŸããŠç®¡çæš©éãæã€ãŠãŒã¶ãŒIDãæå®ãããäžã®æŒç¿ã§ç»é²ãã admin@mynavidomain.onmicrosoft.com ãæå®ããã°ããã
ããã£ã¬ã¯ããªã®æ¥ç¶ãç»é¢ã§ã¯ããªã³ãã¬ãã¹ADãã¡ã€ã³ã«å¯Ÿããç®¡çæš©éãæã£ããŠãŒã¶ãŒãæå®ããåæå¯Ÿè±¡ãšãªãADãã¡ã€ã³ãæå®ãããCloudAdmin@mynavi.mydns.jp ãšãã¹ã¯ãŒããæå®ãããããã£ã¬ã¯ããªã®è¿œå ããã¯ãªãã¯ãããã
以äžã®ããã«ãæ§ææžã¿ãã£ã¬ã¯ããªãšããŠADãã¡ã€ã³ã远å ãããããæ¬¡ãžããã¯ãªãã¯ãããã
ããã¡ã€ã³ãšOUã®ãã£ã«ã¿ãªã³ã°ãç»é¢ã§ã¯åæå¯Ÿè±¡ãšããOUãæå®ããããšãã§ãããä»åã¯å šãŠã®OUã察象ãšããã®ã§ããã¹ãŠã®ãã¡ã€ã³ãšOUã®åæããéžæãããç¶æ ã§ã次ãžããã¯ãªãã¯ããã
ãäžæã®ãŠãŒã¶ãŒèå¥ãç»é¢ã§ã¯ãAzure ADãšãªã³ãã¬ãã¹ADã®ãŠãŒã¶ãŒããããããéã®å±æ§ãã«ã¹ã¿ãã€ãºããããšãã§ãããä»åã¯äœãããå¿ èŠã¯ãªãã®ã§ããã®ãŸãŸã次ãžããã¯ãªãã¯ããã
ããŠãŒã¶ãŒããã³ããã€ã¹ã®ãã£ã«ã¿ãªã³ã°ãç»é¢ã§ã¯ãåæå¯Ÿè±¡ãšãããŠãŒã¶ãŒãããã€ã¹ã¢ã«ãŠã³ããã°ã«ãŒãåäœã§æå®ããããšãã§ãããä»åã¯äœãããå¿ èŠã¯ãªãã®ã§ããã®ãŸãŸã次ãžããã¯ãªãã¯ããã
ããªãã·ã§ã³æ©èœãç»é¢ã§ã¯äœãéžæããå¿ èŠã¯ãªãããã®ãŸãŸã次ãžããã¯ãªãã¯ãããã
ãæ§æã®æºåå®äºãç»é¢ã衚瀺ãããããæ§æãå®äºããããåæåŠçãéå§ããŠãã ããããããã§ãã¯ãããç¶æ ã§ãã€ã³ã¹ããŒã«ããã¯ãªãã¯ãããã
æ§æãå®äºãããšããã£ããããã¯ã°ã©ãŠã³ãã§åæãéå§ãããã
ãªããæ¢å®ã§ã¯ãªã³ãã¬ãã¹ã®ç®¡çè ïŒãã®æŒç¿ã§ã¯ CloudAdminïŒã¯åæãããªããããã§ããªã³ãã¬ãã¹ADã«äžè¬ãŠãŒã¶ãŒãäœæãããã
DS1ã§ãµãŒããŒãããŒãžã£ãŒãèµ·åãããããŒã«ãã¡ãã¥ãŒãããActive Directory ãŠãŒã¶ãŒãšã³ã³ãã¥ãŒã¿ãŒããèµ·åãããããUsersããå³ã¯ãªãã¯ããŠãæ°èŠäœæã-[ãŠãŒã¶ãŒ]ãéžæããã
ãæ°ãããªããžã§ã¯ã - ãŠãŒã¶ãŒãç»é¢ã§ãå§åããã«ããŒã ãé©åœã«å ¥åãããŠãŒã¶ãŒãã°ãªã³åã« user01 ãæå®ããããæ¬¡ãžããã¯ãªãã¯ããã
次ã®ããŒãžã§ãã¹ã¯ãŒããæå®ããããã¹ã¯ãŒããç¡æéã«ãããããã§ãã¯ããããæ¬¡ãžããå®äºããã¯ãªãã¯ããã
ããã§ãã¹ããŠãŒã¶ãŒãäœæã§ããã®ã§ããã®ãŠãŒã¶ãŒãåæãããã åæã®ã¿ã€ãã³ã°ã¯æ¢å®ã§ã¯30åã«1åã ããä»ããåæããå Žåã«ã¯ PowerShell ããè¡ããPowerShell ã³ã³ãœãŒã«ã管çè æš©éã§èµ·åãã以äžã®ã³ãã³ããå®è¡ããŠã¿ããã
Start-ADSyncSyncCycle
äžèšãå®è¡ããããæ§ããŒã¿ã«ã® Azure AD ã®ç®¡çã³ã³ãœãŒã«ãéããããŠãŒã¶ãŒãäžèЧãåç §ããŠã¿ããšã以äžã®ããã«äœæãããŠãŒã¶ãŒãåæãããŠããã®ããããã ããã
user01 ã®ãœãŒã¹ããããŒã«ã«Active Directoryããšè¡šç€ºãããŠããã®ãããããã€ãŸãããªã³ãã¬ãã¹ADããåæãããŠãããŠãŒã¶ãŒã§ãããšããããšã ã
ããã§ãã¹ãŠã®èšå®ãå®äºããã
ãããããŠãã©ãŠã¶ãã以äžã®URLã«ã¢ã¯ã»ã¹ããŠã¿ããç¹°ãè¿ãã«ãªãããAzureããŒã¿ã«ã§äœ¿çšããŠãããã©ãŠã¶ãšã¯å¥ã®ãã©ãŠã¶ã䜿çšããããInPrivateã¢ãŒãã䜿çšãããã ä»åºŠã¯ããŠãŒã¶ãŒIDãšããŠå ã»ã©äœæãã user01@mynavi.mydns.jp ã䜿çšããã ã©ãã ããïŒä»åºŠã¯æ£ãããã°ãªã³ã§ããã¯ãã ã
以äžã§ãæ¬é£èŒã®æŒç¿ã¯å®äºã ã
å幎以äžã®é£èŒãšãªã£ãããéäž Azure ã®ä»æ§ãå€ãã£ãããæ°æ©èœã远å ãããããªã©ã®åœ±é¿ã§ãé£èŒãäžæããŠããŸã£ãããšããã£ããå®ã¯ãAzure AD ã®ç®¡çããŒã¿ã«ãæ°ãã管çç»é¢ã«ç§»è¡ãããããšãæåŸ ããŠããã®ã ããæ®å¿µãªããé£èŒæéäžã«ã¯ç§»è¡ãããããšã¯ãªãã£ãã
ã¯ã©ãŠãã¯é²åãæ©ãããã®é£èŒã§è§£èª¬ããæé ãåŸã ã«å€ããã®ãšãªã£ãŠããã¯ãã ãããããããã§åŸããã§ãã¬ãŒã·ã§ã³ã®åºç€ç¥èã¯æé ãæ°ãããªã£ãŠãçããããšãã§ãããããããæ¬çªç°å¢ãèšèšããæ¹ã¯ããã²ãšããã®é£èŒã§åŸããã§ãã¬ãŒã·ã§ã³ã®ç¥èãæŽ»çšããéäžç®¡çãããå®å šãªèªèšŒåºç€ãèšèšããŠããã ãããã
ç·šéåå:ãŠããŸã³
å®çŽ é äž
æ¥æ¬ãã€ã¯ããœãã ãã¯ãã«ã« ãšãã³ãžã§ãªã¹ã
äž»ã«ã€ã³ãã©ç³»ãã¯ãããžãŒã®æ¥æ¬åžå Žãžã®èšŽæ±ãæ åœãè¿å¹Žã¯ãããªãã¯ã¯ã©ãŠãäžã®ã¢ã€ãã³ãã£ãã£ã»ãããã€ããŒã§ããAzure Active DirectoryãæŽ»çšããã»ãã¥ãªãã£åºç€ã®ãã¶ã€ã³ãå®è£ æ¹æ³ãªã©ãã¡ã€ã³ã®ãã£ãŒã«ãã§ããã
Technetã§å人ããã°ãããŸããŸãªæè¡æ å ±ãçºä¿¡ããŠããã



















