ã¢ã«ãŠã³ãã®ããã¯ã¢ãŠãã¯ã·ã¹ãã 管çè ã«ãšã£ãŠé¢åã§ãããActive DirectoryïŒADïŒã§ã¯äžè¬çã§ãã調æ»ã«ãããšãã¢ã«ãŠã³ãã®ããã¯ã¢ãŠãã¯ITãµããŒãã«é»è©±ããæãäžè¬çãªçç±ã§ãã
ãŸããActive Directoryã¢ã«ãŠã³ãããããã¯ããäž»ãªçç±ïŒãŠãŒã¶ãŒããã¹ã¯ãŒããå¿ããå Žåãé€ãïŒã¯ãå€ãè³æ Œæ å ±ã§èªèšŒããããã€ã¹äžã§å®è¡äžã®ã¢ããªãŸãã¯ããã¯ã°ã©ãŠã³ããµãŒãã¹ã§ãããŠãŒã¶ãŒã¯ããå€ãã®ããã€ã¹ã䜿çšããå¿ èŠãããããããã®åé¡ã¯ããã«è€éã«ãªããŸãããã®åé¡ã解決ããã«ã¯ãsysadminã¯ãå€ãè³æ Œæ å ±ã§å®è¡ãããŠããã¢ããªã±ãŒã·ã§ã³ãèŠã€ããŠãããã忢ãããããŠãŒã¶ãŒã«è³æ Œæ å ±ã®æŽæ°ãäŸé Œããå¿ èŠããããŸãã
ActiveDirectoryãã¢ã«ãŠã³ãããã¯ãåŠçããæ¹æ³ã¯ææ°ã§ã¯ãããŸããã以åã¯ãã»ãšãã©ã®OfficeãŠãŒã¶ãŒã1ã€ã®ããã€ã¹ãããã°ã€ã³ãããšãè³æ Œæ å ±ãç°¡åã«è¿œè·¡ã§ããŸããããããä»ãç¶æ³ã¯å€ãããŸããã
ãã®èšäºã§ã¯ãActive Directoryã¢ã«ãŠã³ãã®ããã¯ãã©ã®ããã«çºçããããããããä¿®æ£ããæ¹æ³ãããã³ã¢ã«ãŠã³ãã®ããã¯è§£é€ã«è²»ããããæéãšãªãœãŒã¹ãåæžããããªã·ãŒãäœæããæ¹æ³ã«ã€ããŠè©³ãã説æããŸãã
æŠèŠïŒActiveDirectoryããããã¯ããæãäžè¬çãªçç±
ã»ãšãã©ã®ActiveDirectoryã¢ã«ãŠã³ãã®ããã¯ã¯ããŠãŒã¶ãŒããã¹ã¯ãŒããå¿ããããŸãã¯ãã¹ãŠã®ããã€ã¹ã§è³æ Œæ å ±ãæŽæ°ããªããšãã2ã€ã®çç±ã®ããããã§çºçããŸãã
æåã®ã±ãŒã¹ã§ã¯ããŠãŒã¶ãŒããã¹ã¯ãŒããå¿ããå Žåã管çè ã¯ãŠãŒã¶ãŒã®è³æ Œæ å ±ããªã»ãããããã匷åãªãã¹ã¯ãŒããäœæããããšãéèŠã§ããããšããŠãŒã¶ãŒã«éç¥ãããããã¹ã¯ãŒããããŒãžã£ãŒã䜿çšããŠèšæ¶ãããã¹ã¯ãŒãã®æ°ãæžããããã«ã¢ããã€ã¹ããå¿ èŠããããŸãã 2çªç®ã®ã±ãŒã¹ã§ã¯ãäžéšã®ããã€ã¹ãŸãã¯ãµãŒãã¹ãå€ãããŒã¿ã§ãã°ã€ã³ããããšãããšããã®åé¡ã«ã¯ããè€éãªè§£æ±ºçãå¿ èŠã«ãªããŸããããã¯ãŸãã«ãã®èšäºã§æ€èšããåé¡ã§ãã
ãã®ã¿ã€ãã®ã¢ã«ãŠã³ãããã¯ã¢ãŠãã®åºæ¬çãªä»çµã¿ã¯æ¬¡ã®ãšããã§ããããã©ã«ãã§ã¯ãActive Directoryã¯ããã°ã€ã³ã«3å倱æãããšããŠãŒã¶ãŒããããã¯ããŸããã»ãšãã©ã®å ŽåããŠãŒã¶ãŒãActive Directoryã¢ã«ãŠã³ãã®è³æ Œæ å ±ãæŽæ°ããããã«æ±ãããããšãæããã䜿çšããããã€ã¹ã§æŽæ°ããŸãããã®ãŠãŒã¶ãŒã®ä»ã®ããã€ã¹ã¯å€ãè³æ Œæ å ±ãä¿æã§ããããã°ã©ã ãŸãã¯ãµãŒãã¹ã¯ãããã䜿çšããŠActiveDirectoryãžã®ã¢ã¯ã»ã¹ãèªåçã«è©Šè¡ãç¶ããŸãããããã®ããã€ã¹ã®è³æ Œæ å ±ã¯ç¡å¹ã«ãªã£ãŠããããããã°ã€ã³ã§ããªããªããActive Directoryã¯ã¢ã«ãŠã³ããéåžžã«è¿ éã«ããã¯ããŠããã«ãŒããã©ãŒã¹æ»æã®ããã«èŠããããšãé²ããŸãã
ã»ãšãã©ã®å Žåãsysadminã¯ããããã®äžæ£ãªãã°ã€ã³è©Šè¡ã®åå ãç¹å®ãããããããããã¯ãããããŠãŒã¶ãŒã«è³æ Œæ å ±ã®æŽæ°ãäŸé ŒããããšãäœåãªããããŸãããŠãŒã¶ãŒãæ°åã®ç°ãªããœãŒã¹ãããã°ã€ã³ããå¿ èŠããã仿¥ã®ç°å¢ã§ã¯ãæ ¹æ¬çãªåå ãèŠã€ããããšã¯å°é£ãªäœæ¥ã«ãªãå¯èœæ§ãããããã®ãããªåé¡ã®é »åºŠãæžããããã®é©åãªãããã¯ããªã·ãŒãéçºããããšãã§ããŸããèšäºã®åŸåã§ãäž¡æ¹ã«å¯ŸåŠããæ¹æ³ã瀺ããŸãã
ActiveDirectoryã§ãããã¯ããäžè¬çãªçç±
ã¢ã«ãŠã³ãã®ããã¯ã¢ãŠãã®åé¡ã解決ããããã®è§£æ±ºçã«ã€ããŠèª¬æããåã«ãäžèšã®2ã€ã®æãäžè¬çãªã¢ã«ãŠã³ãã®ããã¯ã¢ãŠãã®çç±ä»¥å€ã«ããä»ã«ãå€ãã®çç±ãããããšã«æ³šæããŠãã ããã
Microsoftã«ã¯ãããããã³ã°ã®åé¡ããã©ãã«ã·ã¥ãŒãã£ã³ã°ããæ¹æ³ã«é¢ããTechNetã®èšäºå šäœãããããªã¹ãã«ã¯æ¬¡ã®ãã®ãå«ãŸããŠããŸãã
- ãã£ãã·ã¥ã«å€ãè³æ Œæ å ±ãããããã°ã©ã
- ãµãŒãã¹ã¢ã«ãŠã³ãã®ãã¹ã¯ãŒãã®å€æŽã
- 誀ã£ããã¹ã¯ãŒãå ¥åã®ãããå€ãäœãèšå®ããããŠããŸãã
- è€æ°ã®ã³ã³ãã¥ãŒã¿ãŒã§ã®ãŠãŒã¶ãŒãã°ãªã³ã
- ä¿åããããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã«ã¯å€ãè³æ Œæ å ±ãå«ãŸããŠããŸãã
- å€ãè³æ Œæ å ±ãæã€ã¹ã±ãžã¥ãŒã«ããããžã§ãã
- å€ãè³æ Œæ å ±ãæã€ãã©ã€ããå²ãåœãŠãã
- ActiveDirectoryã®èª€ã£ãè€è£œã
- äžæãããã¿ãŒããã«ãµãŒããŒã»ãã·ã§ã³ã
- å€ããµãŒãã¹ã¢ã«ãŠã³ãã®ãã°ã€ã³ã
Active Directoryã®åºæ¬ãããçè§£ããŠããã°ãActiveDirectoryããããã³ã°ã®åé¡ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ãç°¡åã«ãªããŸããActiveDirectoryããã¹ã¿ãŒããã®ã«åœ¹ç«ã€å€ãã®ãã¥ãŒããªã¢ã«ãäœæããŸãããæé«ã®ActiveDirectoryãã¥ãŒããªã¢ã«ã®ã¬ã€ãããå§ããããšããå§ãããŸããå¿ ãçè§£ãããã®Active Directoryã®ãŠãŒã¶ãŒãšã³ã³ãã¥ãŒã¿ã®éã®å·®ããéã®Active DirectoryãµãŒãã¹ã®äœæ¥ãããã³ADãšLDAPãšã®éãã
ãããã®ãããã¯ãçè§£ãããšãã¢ã«ãŠã³ãã®ãããã¯ãã©ã®ããã«æ©èœããããããçè§£ã§ããããã«ãªããŸãã
ã¢ã«ãŠã³ãã®ãããã¯ã®åé¡ã解決ãã
Active Directoryã¢ã«ãŠã³ãã®ããã¯ã¢ãŠãã«ã¯å€ãã®æœåšçãªåå ããããããã·ã¹ãã 管çè ã¯ãã®åé¡ã解決ããããã«å€å€§ãªåŽåãè²»ãããªããã°ãªããªãããšããããããŸããã·ã¹ãã 管çè ã¯ããã¡ã€ã³ãã©ã¬ã¹ãå ã®ããã¯ãæå¹ãªãŠãŒã¶ãŒã®æ°ã远跡ããããã«ã·ã¹ãã ãæ§æããŠããŠãŒã¶ãŒã®åŒã³åºããæ®ºå°ããåã«ããã¯ã¢ãŠãã®åé¡ããã©ãã«ã·ã¥ãŒãã£ã³ã°ã§ããããã«ããå¿ èŠããããŸãã
æåã®ã¹ããã
ãããã¯ãããã¢ã«ãŠã³ããæåã«ç¹å®ãããšããæåã®æãéèŠãªã¿ã¹ã¯ã¯ããããã¯ããµã€ããŒæ»æã«ãã£ãŠåŒãèµ·ããããŠãããã©ããã倿ããããšã§ãã
調æ»ããã®ã«ååãªæ å ±ãããããšã確èªããã«ã¯ãããã€ãã®éèŠãªæé ãå®è¡ããå¿ èŠããããŸãã
- ææ°ã®ãµãŒãã¹ããã¯ãšããããã£ãã¯ã¹ããã¡ã€ã³ã³ã³ãããŒã©ãŒãšã¯ã©ã€ã¢ã³ãã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ãããŠããããšã確èªããŸãã
- ããŒã¿åéçšã«ã³ã³ãã¥ãŒã¿ãŒãæ§æããŸãã
- ãã¡ã€ã³ã¬ãã«ã§ã®ç£æ»ãæå¹ã«ããŸãã
- Netlogonãã®ã³ã°ãæå¹ã«ããŸãã
- Kerberosãã®ã³ã°ãæå¹ã«ããŸãã
- ã€ãã³ããã°ãã¡ã€ã«ãšNetlogonãã°ãã¡ã€ã«ããããŒã¿ãåæããŸããããã¯ãããã¯ãçºçããå Žæãšçç±ãå€å¥ããã®ã«åœ¹ç«ã¡ãŸãã
- ã¢ã«ãŠã³ãããã¯ãçæããŠããã³ã³ãã¥ãŒã¿ãŒã®ã€ãã³ããã°ãåæããŠãåå ãç¹å®ããŸãã
ãããã®ãã°ã確èªããåŸãæ°çŸïŒãŸãã¯æ°åïŒã®ãã°ã€ã³è©Šè¡ã®å€±æã衚瀺ãããå Žåã¯ãã·ã¹ãã ã«å¯Ÿãããã«ãŒããã©ãŒã¹æ»æãçºçããŠããå¯èœæ§ããããããããã«å¯ŸåŠããå¿ èŠããããŸããéå¡ã®åå ãéåžžã®çç±ã§ããããšã倿ããå Žåã¯ããããã©ã®ããã«çºçãããã調ã¹ãå¿ èŠããããŸãã
ããããã³ã°ããªã·ãŒã§èæ ®ãã¹ãèŠçŽ
è€æ°ã®çš®é¡ã®ActiveDirectoryã¢ã«ãŠã³ãã®ããã¯ã¢ãŠããåžžã«çºçããå Žåã¯ãããã¯ã¢ãŠãããªã·ãŒã確èªããããšã§ãããä¿®æ£ã§ããŸãã
å€ãã®ç®¡çè ã¯ããã¹ãŠã§ã¯ãªãã«ããŠããã»ãšãã©ã®ã¢ã«ãŠã³ãããã¯ã¢ãŠãã¯ãããã¹ããŒããªActiveDirectoryã¢ã«ãŠã³ãããã¯ã¢ãŠãããªã·ãŒãå®è£ ããããšã§å¯ŸåŠã§ãããšèšãã§ãããããã®ã¢ãããŒãã®æ¯æè ã¯ã管çè ããã¡ã€ã³ã®ããã©ã«ãã®GPOã«ç§»åããé©åãªãããã¯èšå®ãããé©åãªãã®ã«å€æŽããããšããå§ãããŸãã
ã¢ã«ãŠã³ãããã¯ã¢ãŠããããå€ãã©ã¡ãŒã¿ãŒããããã³ã°ãããã«ãŒã«ãããã«ãŒããã©ãŒã¹æ»æã«ãã£ãŠã®ã¿ããªã¬ãŒãããããã«ã3ãããã¯ããã«å€§ããæ°ïŒãããã20ãŸãã¯30ïŒã«å€æŽããå¿ èŠããããŸãïŒãã®å Žåãæ°çŸåã®è©Šè¡ããããŸãïŒã
ã¢ã«ãŠã³ãã®ããã¯ã¢ãŠãæéïŒã¢ã«ãŠã³ãã®èªåããã¯è§£é€ãå®äºãããŸã§ã®åŸ æ©æéïŒã¯ã10åïŒããšãã°ã12æéã§ã¯ãªãïŒããŸãã¯ããã©ã«ãå€ã®ãŒãïŒæ°žç¶çãªããã¯ã¢ãŠããæå³ããïŒã«èšå®ããå¿ èŠããããŸãã ..ã
æåŸã«ãããªãããŒãªãã¢ã«ãŠã³ãããã¯ã¢ãŠãããªã·ãŒã®ãªã»ããåŸãèšå®ã¯ããã©ã«ãã§1åã«èšå®ãããŠããŸãããã®ã¢ãããŒãã®è©³çްã«ã€ããŠã¯ããã¡ããã芧ãã ããã
äœäººãã®Varonisãšã³ãžãã¢ããå°éå®¶ã®ã¢ããã€ã¹ãåããåŸãããã©ã«ãã®ActiveDirectoryããããã³ã°èšå®ã倿Žããããšã圹ç«ã€ããšãåŠã³ãŸããããã ããæåã«åŸæ¥å¡ã®ãã¹ã¯ãŒãã®å šäœçãªåŒ·åºŠã確èªããå¿ èŠããããããããã«ã¯æ³šæããå¿ èŠããããŸãããã¹ã¯ãŒãããªã·ãŒã匷åãªå Žåã¯ããã¢ã«ãŠã³ãããã¯ã¢ãŠãã®ãããå€ããå¢ããããšãçã«ããªã£ãŠããå¯èœæ§ããããŸããããããªããšãæ©èœããªãå¯èœæ§ããããŸããããã«ããã®ãããå€ã¯åžžã«ãŒãã§ãªããã°ãªããªããšããè¯ãè°è«ããããŸãããã®çµæããŠãŒã¶ãŒã¯ã¢ã«ãŠã³ãã®ãããã¯ãè§£é€ããããã«ãµããŒãã«é£çµ¡ããå¿ èŠããããŸãã
æçµçã«ãæ¡çšããã¢ãããŒãã¯ãç°å¢ãšæ¥åžžçã«çºçããé害ç©ã®æ°ã«ãã£ãŠç°ãªããŸãããããã¯ãŒã¯ã«äŸµå ¥ããããšããŠããäŸµå ¥è ãæãŸããããšãã§ããäžæ¹ã§ãã¢ã«ãŠã³ãã®ãªã»ããã®è©Šè¡åæ°ãå¶åŸ¡ããããã¯ã¢ãŠãããªã·ãŒã®å®è£ ã«åªããå¿ èŠããããŸãã
ActiveDirectoryã¢ã«ãŠã³ãããã¯ãåŠçããããã®3ã€ã®ããŒã«
Active Directoryã¢ã«ãŠã³ãã®ããã¯ã¢ãŠãã¯éåžžã«äžè¬çã§ããããããã¯ãŒã¯ç®¡çè ã«ãšã£ãŠã¯ãã©ã¹ãã¬ãŒã·ã§ã³ã®åå ãšãªããããåé¡ã«å¯ŸåŠããããã«ããã€ãã®ããŒã«ãç¹å¥ã«èšèšãããŠããŸãããã€ã¯ããœãããæäŸãããã®ãããã°ããµãŒãããŒãã£ãæäŸãããã®ããããŸãããããæé«ã®ãã®ã®ãªã¹ãã§ãïŒ
ã¢ã«ãŠã³ãããã¯ã¢ãŠãã¹ããŒã¿ã¹ãœãããŠã§ã¢
ããã¯ãMicrosoftãActiveDirectoryã¢ã«ãŠã³ãã®ããã¯ã¢ãŠãã管çããããã«æäŸããããŒã«ã®æšæºã»ããã§ããããã¯ãããã€ãã®åå¥ã®ã³ã³ããŒãã³ãã§æ§æãããŠããŸãã
ãããã¯ããããããããã¯ãŒã¯ã®ããŸããŸãªåŽé¢ãæ¢çŽ¢ããã®ã«åœ¹ç«ã¡ãŸãã
- EventCombMT.exeã¯ããã¡ã€ã³ã³ã³ãããŒã©ãŒã®ã€ãã³ããã°ããã€ãã³ããåéããŠãã£ã«ã¿ãªã³ã°ããŸãããã®ããŒã«ã«ã¯ãã¢ã«ãŠã³ãããã¯ã®æ€çŽ¢æ©èœãçµã¿èŸŒãŸããŠããŸããç¹å®ã®ã¢ã«ãŠã³ãããã¯ã«é¢é£ä»ããããã€ãã³ãIDãããšã¯ã¹ããŒãå¯èœãªå¥ã®ããã¹ããã¡ã€ã«ã«åéããŸãã
- LockoutStatus.exe , . , .
- Netlogon Netlogon NT LAN Manager (NTLM). Netlogon â . Netlogon NLParse.exe, .
- Acctinfo ADUC ( Active Directory), lastLogon ( ) Password Expires ( ). , ADUC, « ». , .
ADLockouts
ããã¯ãActiveDirectoryã®ãããã¯ãåŒãèµ·ãããç¡å¹ãªãã¹ã¯ãŒãã®è©Šè¡ã®åå ã远跡ããããšããåçŽãªããã°ã©ã ã§ãã
ãã®ããŒã«ã¯å°èŠæš¡ãªãããã¯ãŒã¯ã«ã¯æé©ã§ãããå€§èŠæš¡ãªç°å¢ã§ã¯ããã»ã©å¹æçã§ã¯ãããŸãããã¢ããªã±ãŒã·ã§ã³ã¯ãåãã¡ã€ã³ãšãã¡ã€ã³ã³ã³ãããŒã©ãŒã§ãã°ã€ã³ã®å€±æãæ€çŽ¢ããé¢é£ãããã¹ãŠã®ã€ãã³ããåæããŸãããã®ç®çã¯ãéå¡ã®çç±ãç¹å®ããããšã§ãããã®åŸãããã°ã©ã ã¯åãã·ã³ãåæãããããããããã©ã€ããå€ããªã¢ãŒãã»ãã·ã§ã³ãã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ãªã©ã倿°ã®ãªããžã§ã¯ãã®ã¢ã«ãŠã³ãããã¯ã®äžè¬çãªã±ãŒã¹ããã¹ãŠè¡šç€ºããŸãã
ãã¯ãŒã·ã§ã«
ãã¡ãããActive Directoryã¢ã«ãŠã³ããããã¯ã¢ãŠããããŠããçç±ã調æ»ããããã®æãçŽæ¥çãªã¢ãããŒããåããPowerShellã䜿çšããããšãã§ããŸãããã®ããã»ã¹ã¯ãäžèšã®ããŒã«ãããå°ãæéãããããè€éã«ãªãå¯èœæ§ããããŸãããã·ã¹ãã ã§æ£ç¢ºã«äœãèµ·ãã£ãŠãããã«ã€ããŠã®ããè©³çŽ°ãªæ å ±ãæäŸããŸãã
PowerShellã䜿çšãããšãã¢ã«ãŠã³ãåºæã®ã€ãã³ãã®ã€ãã³ããã°ãç°¡åã«ãã£ã«ã¿ãªã³ã°ããŠãã¢ã«ãŠã³ãã®ããã¯ã¢ãŠãã®åå ãç¹å®ã§ããŸãã
- ããã¯ãGet-EventLogã³ãã³ãã¬ãããšæ¬¡ã®ã³ãã³ãã䜿çšããŠå®è¡ã§ããŸãã
Get-EventLog -LogName Security | ?{{$_.message -like "*locked*USERNAME*"}} | fl -property *
- Get-UserLockoutStatus . , , , , .
ãããã¯ãŒã¯ç®¡çè ã®å ŽåãActiveDirectoryã¢ã«ãŠã³ãããããã¯ããã®ãã©ãã»ã©é¢åãªããšãã説æããå¿ èŠã¯ãããããªãã§ãããããã®ããšã念é ã«çœ®ããŠãã¢ã«ãŠã³ãã®ããã¯ã¢ãŠããActive Directoryã®äžå¯æ¬ ãªæ©èœãšããŠæ±ãããµããŒããªã¯ãšã¹ããåãåããšããã«ãŠãŒã¶ãŒã¢ã«ãŠã³ãã®ããã¯ãèªåçã«è§£é€ããããšããèªæã«é§ãããŸãã
ãã ããããã¯ééã£ãã¢ãããŒãã§ããã¢ã«ãŠã³ãã®ããã¯ã¢ãŠãã®æ ¹æ¬çãªåå ãæéããããŠèª¿æ»ããããšã§ãã¢ã«ãŠã³ãã®ããã¯ã¢ãŠããé »ç¹ã«çºçããã®ãé²ãããšãã§ããŸããããã«ãããããã³ã°ããªã·ãŒã倿ŽãããšããŠãŒã¶ãŒãšã©ãŒãããããã³ã°ãåŒãèµ·ãããŠããå Žåãããããã¯ãŒã¯ã«å¯Ÿãããµã€ããŒç¯çœªæ»æãç¹å®ããããã®å¹æçãªæ¹æ³ã«ãªããŸãã
æçµçã«ãActive Directoryãçè§£ããããšã§ãã¢ã«ãŠã³ãã®ããã¯ã¢ãŠããã©ãã ã广çã«é²æ¢ããã³ç®¡çã§ããããæ±ºãŸããŸãããããã®åé¡ã®åå ã远跡ã§ããªãããšã«ãã°ãã°äžæºãæããå Žåã¯ãåœç€ŸãæäŸãããªãœãŒã¹ã䜿çšã§ããŸããç¹ã«ãActive Directoryã®ãŠãŒã¶ãŒãšã³ã³ãã¥ãŒã¿ãŒã«é¢ããã¬ã€ããšæ©å¯ããŒã¿ã®ã©ãã«ä»ãã«é¢ããã¬ã€ãã確èªããŠããµã€ããŒæ»æãããããã¯ãŒã¯ãããé©åã«ä¿è·ããŠãã ããã