æšä»ãªã¢ãŒãã¯ãŒã¯ã®å¢å ã«äŒŽã£ãŠãã¯ã©ãŠãäžã®ããŸããŸãªé£æºã¢ããªã±ãŒã·ã§ã³ã®å©çšãå¢å ããŠããŸããäŸãã°ããªã³ã©ã€ã³äŒè°ãããããã«ããã€ã¯ããœããã®ã¯ã©ãŠãIDåºç€ãAzure Active Directoryãã«ãMicrosoft TeamsããZoomãWebExãšãã£ãã¯ã©ãŠãäžã®ã¢ããªã飿ºããããšãã£ãå ·åã§ãã
ããããã¯ã©ãŠãäžã®ã¢ããªãšã®é£æºã¯ãå¹çã®è¯ããªã¢ãŒãã¯ãŒã¯ã®åŒ·ã峿¹ãšãªã£ãŠããäžæ¹ãç¹ã«äŒæ¥çµç¹ã§ã¯ããŠãŒã¶ãŒãå©çšããã¢ããªã«å¯Ÿããã»ãã¥ãªãã£ãªã¹ã¯ãžã®å¯Ÿå¿ãè¿«ãããŠããŸãããã€ã¯ããœããã宿œãã調æ»ã§ã¯ãCOVID-19 ãã³ãããã¯ã®ç¶æ³äžã§ã®ITç°å¢ã®ã»ãã¥ãªãã£èª²é¡ãšããŠæãå€ãæããããã®ã¯ãçµç¹ã®ããŒã¿ãã¢ããªãžã®ãªã¢ãŒãã¢ã¯ã»ã¹ã«ãããã»ãã¥ãªãã£ç¢ºä¿ã§ãããç¹ã«ããªã¢ãŒãã¢ã¯ã»ã¹ãžã®è åšãšããŠã¯ããã£ãã·ã³ã°ãæå€§ã®æžå¿µãšããŠæããããŠãããCOVID-19 ãã³ãããã¯ã®ç¶æ³äžã§90ïŒ ã®çµç¹ãããã£ãã·ã³ã°ã«ãã圱é¿ãåããããšåçãã28ïŒ ã¯ããã£ãã·ã³ã°ã«ããæ»æãæåããçè·¡ããã£ãããšåçããŠããŸãã
äŒæ¥ãŠãŒã¶ãŒã«å¯Ÿãããã£ãã·ã³ã°ãšèšãã°ã粟巧ãªåœã®ãã°ã€ã³ç»é¢ãªã©ã衚瀺ããŠãŠãŒã¶ãŒåãšãã¹ã¯ãŒããå ¥åãããããšãã£ããã®ãã€ã¡ãŒãžããæ¹ãå€ããããããŸãããå®éãOffice 365ã®ç²Ÿå·§ãªåœãã°ã€ã³ç»é¢ã衚瀺ãããŠãŒã¶ãŒåãšãã¹ã¯ãŒããã ãŸãåãã±ãŒã¹ãå ±åãããŠããŸãããã ããæšä»ã§ã¯ãã®ãããªãã£ãã·ã³ã°ææ³ã ãã§ãªããå©çšãå¢å ããŠããã¯ã©ãŠãã¢ããªã®å©çšã«çµ¡ãããã£ãã·ã³ã°ææ³ãå ±åãããŠããã®ã§ãã
åæãä¿ãã¿ã€ãã®ãã£ãã·ã³ã°ã®æ¡å€§
Azure ADã§ã¯ãOAuth 2.0ãããã³ã«ãå©çšãããŠããŸããããã«ããããŠãŒã¶ãŒã«ä»£ãã£ãŠã飿ºãèš±å¯ããŠããä»»æã®ã¢ããªããŠãŒã¶ãŒã®æ å ±ãããŒã¿ããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšãå¯èœã§ããã¢ããªã飿ºããŠãŠãŒã¶ãŒã®ããŒã¿ã«ã¢ã¯ã»ã¹ããããã«ã¯ãå¿ èŠãªã¢ã¯ã»ã¹æš©ãä»äžããå¿ èŠãããããŠãŒã¶ãŒã«ã¢ã¯ã»ã¹æš©ã®ä»äžã«åæããããæ±ããããã³ããã衚瀺ãããŸãã
ãŠãŒã¶ãŒã¯è¡šç€ºãããããã³ããã確èªããæ±ããããŠããã¢ã¯ã»ã¹æš©ã確èªããäžã§ãåæããããã¯ãªãã¯ããããšã«ãªããŸããããããªããããã確èªãããã«ã¯ãªãã¯ããŠããŸãã±ãŒã¹ã¯å°ãªããããŸãããããã«ããã£ãã·ã³ã°è©æ¬ºãè¡ãæ»æè ã¯ããŸããŸãªæå£ã§ãŠãŒã¶ãŒãã ãŸãããšããããã§ããŸããæ£èŠã®ã¢ããªã«èŠããããäžæ£ãªåœã¢ããªãçšæããã¡ãŒã«ãªã©ãéããŠããã®åœã¢ããªãžã¢ã¯ã»ã¹èš±å¯ãè¡ãåæç»é¢ã衚瀺ãããªã³ã¯ãéãããšã§ãåœã¢ããªã«ã¢ã¯ã»ã¹æš©ãäžããããèªå°ããã®ã§ãã
äžæ£ãªã¢ããªãžåæãäžããæäœã¯ããŠãŒã¶ãŒãæ£èŠã®ãã°ã€ã³èªèšŒãè¡ã£ãåŸã«ãŠãŒã¶ãŒèªèº«ãè¡ãæäœã§ãããããäžæ£ãªãã°ã€ã³èªèšŒã鲿¢ããå€èŠçŽ èªèšŒ(MFA)ã§ã¯ããã®ãåæãã£ãã·ã³ã°ããé²ãããšã¯ã§ããŸããããŸããäžæ£ãªã¢ããªãžæš©éãäžããããšã«åæããŠããŸã£ãåŸã¯ããŠãŒã¶ãŒã®ã¢ã«ãŠã³ãã䜿çšããªããŠããäžæ£ãªã¢ããªã¯ãŠãŒã¶ãŒã®ããŒã¿ãžã¢ã¯ã»ã¹ããããšãã§ããããã«ãªããŸãããã®ããããŠãŒã¶ãŒã®ãã¹ã¯ãŒãã®ãªã»ãããè¡ãã ãã§ã¯ãäžæ£ãªã¢ããªã±ãŒã·ã§ã³ããã®ã¢ã¯ã»ã¹ã鮿ããããšã¯ã§ããŸãããã¢ããªã®é£æºãè§£é€ãããããã¯ãè¡ã察åŠãå¿ èŠã§ãã
管çè ã宿œã§ãã察ç
ä»å玹ä»ããŠãããåæãã£ãã·ã³ã°ãã«éãããæšä»ã®ãã£ãã·ã³ã°ã¯å®ã«å·§åŠã§ããã£ãã·ã³ã°ã¡ãŒã«ïŒãµã€ããé²èЧãããŠãŒã¶ãŒãããã£ãã·ã³ã°ãã©ãããèŠåããããšã¯å°é£ã§ãããããã¡ãããŠãŒã¶ãŒã«ãäžæ£ãªã¢ããªãžã®åæãæ±ãããã£ãã·ã³ã°ç»é¢ãªã©ãåšç¥ããããšã¯éèŠã§ããããã£ãã·ã³ã°ã«ãããªã¹ã¯ãæå°åããã«ã¯ãOffice 365 ATPãªã©ã®ã»ãã¥ãªãã£ã³ã³ãããŒã«ãçšããçµç¹çãªå¯ŸçãéèŠã«ãªããŸãïŒãã®èŸºãã«ã€ããŠã¯ãæ¬é£èŒã®ç¬¬21åã§è§£èª¬ããŠããã®ã§ããã¡ããåèã«ããŠãã ããïŒã
äžè¿°ãããããªäžæ£ãªã¢ããªãžã®åæãä¿ããã£ãã·ã³ã°ææ³ã«å¯ŸããŠçµç¹çã«å¯Ÿçããå Žåã¯ãçµç¹å ã®ãŠãŒã¶ãŒãã©ã®ãããªã¢ããªãå©çšããŠããããå¯èŠåããçµç¹å ã®ã¢ããªã®å¶åŸ¡ãè¡ãããšãæå¹ã§ãã
æ¢å®ã®èšå®ã§ã¯ãAzure ADã®å šãŠã®ãŠãŒã¶ãŒã¯ãMicrosoft IDãã©ãããã©ãŒã ãæŽ»çšããã¢ããªã«å¯ŸããŠãã¢ã¯ã»ã¹èš±å¯ãäžããããšãã§ããããã«ãªã£ãŠããŸãããã®æ¢å®ã®èšå®ã§ã¯ããŠãŒã¶ãŒèªèº«ãå¿ èŠãšãã䟿å©ãªã¢ããªã±ãŒã·ã§ã³ãç°¡åã«å ¥æããŠå©çšã§ãããšããã¡ãªãããããäžæ¹ãå©çšããã¢ããªã®æ£åœæ§ããŠãŒã¶ãŒèªèº«ãæ éã«ç¢ºèªãããŸãé©åã«ç®¡çïŒç£èŠããäžã§å©çšãç¶ç¶ããŠããå¿ èŠãããããšããããšã«æ³šæããªããŠã¯ãããŸããã
ãã®ããšãããç¹ã«äŒæ¥çµç¹ã«ãããŠã¯ãæ»æã®å¯Ÿè±¡ãšãªãé åãæžãããŠãªã¹ã¯ã軜æžããããã«ããŠãŒã¶ãŒã«ããã¢ããªãžã®ã¢ã¯ã»ã¹èš±å¯ããçµç¹ã®ããªã·ãŒã«ãã£ãŠå¶éããäžæ£ãªã¢ããªã®å©çšãç£èŠãè¿ éã«å¯ŸåŠã§ããäœå¶ãæŽããããšãæšå¥šããŠããŸãã
Azure ADã§ã¯çŸåšãã¢ããªã®åæããªã·ãŒ(ãã¬ãã¥ãŒ)ã§ãŠãŒã¶ãŒã®åæãå¶éããæ©èœãæäŸããŠããŸãããã®æ©èœãå©çšããããšã§ããŠãŒã¶ãŒãã©ã®ãããªã¢ããªã«ã¢ã¯ã»ã¹èš±å¯ãäžããããããã³ã³ãããŒã«ããããšãã§ããŸããäŸãã°ããæ€èšŒãããçºè¡å ã®ã¢ããªã®ã¿ãããããã¯ãéžæããã¢ã¯ã»ã¹èš±å¯ã®ã¿ãã«å¶éãããšãã£ãå ·åã§ãããŠãŒã¶ãŒãå¿ èŠãšããã¢ããªãå¶éãããŠããå Žåã¯ã管çè ã®åæèŠæ±ã¯ãŒã¯ãããŒã䜿ã£ãŠãçµç¹ã®ç®¡çè ã«èš±å¯ãæ±ããããã«ããããšãã§ããŸãã
ãŸãããã§ã«ãŠãŒã¶ãŒã«ãã£ãŠèš±å¯ãããŠããã¢ããªãçµç¹ã®ç®¡çè ãèŠçŽããç£èŠããããšãã§ããŸãããããäžæ£ãªã¢ããªããã§ã«ãŠãŒã¶ãŒã«ãã£ãŠèš±å¯ïŒå©çšãããŠããå Žåã¯ã管çè ãäžæ³ãªåæã®ä»äžãæ€åºããŠä¿®åŸ©ããããšãå¯èœã§ãã
ãŠãŒã¶ãŒèªèº«ãã¢ã¯ã»ã¹èš±å¯ã«åæããã¢ããªã確èªãããå Žåã¯ãããŒã¿ã«ã§èªã確èªããããšãã§ããŸããã¢ã¯ã»ã¹å¯èœãªå šãŠã®ã¢ããªã衚瀺ãããããããã«é¢ãã詳现ã衚瀺ããã (ã¢ã¯ã»ã¹ã®ç¯å²ãå«ã)ãçãããããŸãã¯äžæ³ãªã¢ããªã«å¯ŸããŠæš©éãåãæ¶ãããšãå¯èœã§ãããŠãŒã¶ãŒæè²ãè¡ãéã«ã¯ãäžæ£ãªã¢ããªãžã®æ³šæãä¿ããšãšãã«ãèªã確èªããææ³ãåšç¥ããŠããããšãã被害ç¯å²ã®æå°åã«åœ¹ç«ã¡ãŸãã
Microsoft Cloud App Securityã§å¹çè¯ã管ç
å¿ èŠãªã©ã€ã»ã³ã¹ãæã£ãŠããå Žåã¯ããMicrosoft Cloud App Securityããå©çšããããšã§ãããã«å¹çè¯ãã¯ã©ãŠãäžã§å©çšããŠããã¢ããªã管çããè¿ éãªå¯Ÿå¿ãè¡ããŸãã
ãOAuth ã¢ã㪠ããªã·ãŒããæ§æããããšã§ããããã现ãããäžæ£ãªã¢ããªãå¶éããããæ€åºãããããããšãå¯èœã§ããäŸãã°ããŸãããããOAuthã¢ããªåãçºè¡å åãå©çšããŠãããçãããæåãè¡ãã¢ããªãªã©ã现ããæ¡ä»¶ãèšå®ããŠçµç¹å ã§å©çšãããŠããã¢ããªãåæã§ããŸãã
ãŸããæ¡ä»¶ã«ãã£ãŠèªåçãªéç¥ã察åŠãè¡ãããšãå¯èœã§ããäŸãã°ããäžè¬çã§ã¯ãªãã¢ããªãé«ãã¢ã¯ã»ã¹èš±å¯ãèŠæ±ããå Žåã«èªåçã«èš±å¯ã倱å¹ãããããã¢ã¯ã»ã¹èš±å¯ãæ¿èªãããŠãŒã¶ãŒãAdministratorsã°ã«ãŒãã®ã¡ã³ããŒã§ããå Žåã«éç¥ãåãåãããé«ãã¢ã¯ã»ã¹èš±å¯ã¬ãã«ãå¿ èŠãšããçµç¹å ã§50人ãè¶ ãããŠãŒã¶ãŒã«ãã£ãŠæ¿èªãããã¢ããªãããå Žåãèªåçã«ã¢ã©ãŒããåãåãããšãã£ãèšå®ã«ãã£ãŠãçµç¹ã«ãšã£ãŠãªã¹ã¯ã®é«ãã¢ããªã«ãè¿ éãã€å¹çè¯ã察åŠãããããšãã§ããéçšé¢ã®è² è·ãæäœéã«ããããšãã§ããŸãã
|
|
|
|
Cloud App Security ããŒã¿ã«ã«ãããçµç¹ã®ã¢ããªã®åæ |
Cloud App Security ã§ã®ã¢ããªã®ããªã·ãŒã®èšå® |
çµç¹ã®ã¢ããªã®é©åãªç®¡çãšè¿ éãªå¯Ÿå¿ãïŒ
ãã£ãã·ã³ã°ãšèšããšãããŠãŒã¶ãŒåãšãã¹ã¯ãŒããå ¥ããããç»é¢ã«æ³šæããšããã€ã¡ãŒãžã匷ããããããŸãããããããªããããã£ãã·ã³ã°è©æ¬ºãè¡ãæ»æè ã¯ããŠãŒã¶ãŒãã ãŸããææ³ããITå©çšç°å¢ã®å€åã«åãããŠæ¬¡ã ã«ä»æããŠããŸããå€åœ©ãªãã£ãã·ã³ã°ã®ææ³ã«å¹çè¯ã察å¿ããããã«ã¯ãæ»æã®å¯Ÿè±¡ãšãªãé åãæžãããçµç¹å ã®ãŠãŒã¶ãŒã®IDãã¢ããªã®ç®¡çãé©åã«è¡ãããšã倧äºã§ãã
Azureã§ã¯ãããŸããŸãªãªã¹ã¯ã«è¿ éãã€å¹çè¯ã察å¿ã§ããã»ãã¥ãªãã£ã³ã³ãããŒã«ãçšæãããŠãããå°ãªãéçšè² è·ã§å€§ããªå¹æãåŸãããšãã§ããŸããäŒæ¥ãçããã£ãã·ã³ã°ã®ææ³ã«ã泚æããæ£ããã¢ããªã管çããå®å šã«ã¢ããªãå©çšããŠãããŸãããã
èè 玹ä»
|
|
å£å
ç±æ¢šéŠ
ãã€ã¯ããœããæ ªåŒäŒç€Ÿ ã»ãã¥ãªã㣠ã¬ã¹ãã³ã¹ ããŒã ã»ãã¥ãªã㣠ããã°ã©ã ãããŒãžã£ãŒ
ãã€ã¯ããœããæ ªåŒäŒç€Ÿã«å ¥ç€Ÿä»¥æ¥ãActive Directory, Network, èšŒææžããã³æå·åãå°éãšããWindows ãšã³ãžãã¢ãçµãŠçŸè·ãã»ãã¥ãªãã£ã®æèåäžæŽ»åãã€ã³ã·ãã³ã察å¿ã«åŸäºãCRYPTRECå§å¡ã






