çããããã«ã¡ã¯ãåœäºã§ãã
ADFSãã¬ãŒãã³ã°ããã¹ãå
šæå
¬éãã£ã¬ã³ãžã®9åç®ã¯Office 365ãšADFSã飿ºãããããã®å
·äœçãªæ¹æ³ã«ã€ããŠè§£èª¬ããŸãã
â â â
![ã¹ã©ã€ã55 ã¹ã©ã€ã55]()
Office 365 ã®åãµãŒãã¹ãžã®ã·ã³ã°ã«ãµã€ã³ãªã³ãå®çŸããå ŽåãADFS ãµãŒããŒãå©çšãã ID 飿ºã®ä»ãAzure AD ãã£ã¬ã¯ããªãš Active Directory ã®éã§ã®ããããžã§ãã³ã° (ID åæ) ãå¿
èŠã«ãªããŸããAzure AD ã§ã¯ Azure AD ãã£ã¬ã¯ããªãš Active Directory ã®éã§ã® ID åæã®ããã®ããŒã«ãšããŠãAzure Active Directory Connect (AAD Connect) ããŒã«ãç¡åã§æäŸããŠããããããå©çšããããšã«ãããID 飿ºã«å¿
èŠãªããããžã§ãã³ã°ã®éšåãå®çŸããŸãã
ãŸããå€éšãã Office 365 ã«ã¢ã¯ã»ã¹ããå ŽåããOutlook ã¢ããªã±ãŒã·ã§ã³ããã¡ãŒã«ããã¯ã¹ã«ã¢ã¯ã»ã¹ãããšãã¯ãWeb ã¢ããªã±ãŒã·ã§ã³ãããã·çµç±ã§ ADFS ãµãŒããŒã«ã¢ã¯ã»ã¹ããããŒã¯ã³ãååŸããå¿
èŠãããç¹ã«ã泚æããŠãã ããã
![ã¹ã©ã€ã56 ã¹ã©ã€ã56]()
ãã©ãŠã¶ãŒ ã¢ã¯ã»ã¹ã«ãã Office 365 ãžã®ã·ã³ã°ã«ãµã€ã³ãªã³ãå®çŸããã«ã¯ã以äžã®èšå®ãå¿
èŠã«ãªããŸãã
â Active Directory ã®èšå® : Office 365 ã«ç»é²ããããã¡ã€ã³åãæã€ã¡ãŒã«ã¢ãã¬ã¹ãŸã㯠UPN ã®ç»é²
Office 365 ã®ã·ã³ã°ã«ãµã€ã³ãªã³ãè¡ãããã«ã¯ãActive Directory ã®ãã¡ã€ã³åã Office 365 ã§äœ¿çšãããã¡ã€ã³åãšåãã§ãªããã°ãªããŸããããããç°ãªããã¡ã€ã³åã Active Directory ã«èšå®ããŠããå Žåãä»£æ¿ UPNãµãã£ãã¯ã¹ãèšå®ããããOffice 365 ã®ãã¡ã€ã³åãšåããã¡ã€ã³åã䜿çšããã¡ãŒã«ã¢ãã¬ã¹ããŠãŒã¶ãŒã«ç»é²ããããšã§å¯ŸåŠããŸã (ã¡ãŒã«ã¢ãã¬ã¹ã®ç»é²ã«ããã·ã³ã°ã« ãµã€ã³ãªã³ã®èšå®æ¹æ³ã«ã€ããŠã¯ãAlternate Login IDãã®é
ã§è§£èª¬ããŸã)ã
â¡ ADFS ãµãŒããŒã®èšå® : ADFS ãµãŒããŒãšããŠã®èšå®
ADFS ãµãŒããŒãã®ãã®ãå©çšããããã®èšå®ãè¡ããŸããå
·äœçã«ã¯ãADFS ãµãŒããŒã®ã€ã³ã¹ããŒã«ãèšŒææžã®å®è£
ãªã©ãå«ãŸããŸãã
⢠ADFS ãµãŒããŒã®èšå® : Azure AD ã®ç»é²
⣠ADFS ãµãŒããŒã®èšå® : ãã§ãã¬ãŒã·ã§ã³ ãã¡ã€ã³ã®ç»é²
ADFS ãµãŒããŒãå©çšãã Azure AD ã®ç»é²ãè¡ããŸããAzure AD ã®ç»é²ã«ã¯ãã§ãã¬ãŒã·ã§ã³ãã¡ã€ã³ã®ååãæå®ããŠè¡ãããããã§ãã¬ãŒã·ã§ã³ ãã¡ã€ã³ã®ç»é²ãè¡ãããšã§èªåçã« Azure AD ã¯ç»é²ããããã®çµæãADFS ãµãŒããŒã«èšŒææžå©çšè
ä¿¡é Œ (RP) ãèªåçã«èšå®ãããŸããAzure AD ã®ç»é²èšå®ã¯ PowerShell ã³ãã³ãã¬ãããéããŠè¡ããŸãã
†Office 365 ã®èšå® : ãã£ã¬ã¯ããªåæã®ã¢ã¯ãã£ãå
Office 365 ã§ã·ã³ã°ã«ãµã€ã³ãªã³ãè¡ãå ŽåãActive Directory ã«ç»é²ããããŠãŒã¶ãŒã Azure AD ã«ãããããåæãããŠããå¿
èŠããããŸããåæã®èšå®ã«å
ç«ã¡ãOffice 365 ã§ã¯åæãèš±å¯ããèšå®ãè¡ã£ãŠãããŸãã
⥠Active Directory ã®èšå® : ãã£ã¬ã¯ããªåæããŒã«ã«ããåæ
Active Directory å
ã®ãŠãŒã¶ãŒãã°ã«ãŒãã®æ
å ±ãåæããŸããåæã¯ Active Directory ãã Azure AD ãã£ã¬ã¯ããªã«åããŠäžæ¹åã«è¡ãããŸãã
⊠åæãããŠãŒã¶ãŒã®ã¢ã¯ãã£ãå
Active Directory ãšã®éã§åæãããŠãŒã¶ãŒã¯ãåæå®äºæç¹ã§ã¯ãŸã å©çšå¯èœãªç¶æ
ã§ã¯ãããŸãããã¢ã¯ãã£ãåã®æäœãéããŠãŠãŒã¶ãŒã¢ã«ãŠã³ãã¯åã㊠Office 365 ã§å©çšå¯èœãªç¶æ
ãšãªããŸãã
瀟å€ãã Office 365 ã«ã¢ã¯ã»ã¹ããå Žåãæ¬¡ã®èšå®ã远å ã§å¿
èŠã«ãªããŸãã
â§ WAP ã®ã€ã³ã¹ããŒã«ã»åæèšå®
瀟å€ãã ADFS ãµãŒããŒã«ã¢ã¯ã»ã¹ããããŒã¯ã³ãçºè¡ããã«ã¯ãWAP ãçµç±ããå¿
èŠããããŸãããã®ãããäºåã« WAP ãã€ã³ã¹ããŒã«ããåæèšå®ãæžãŸããŠãããŸãã
âš DNS ã¬ã³ãŒãã®ç»é²
WAP ã«ã¢ã¯ã»ã¹ããããã® URL ã¯ç€Ÿå
ãã ADFS ãµãŒããŒã«ã¢ã¯ã»ã¹ãããšãã® URL ãšåãã§ãªããã°ãªããªããŸãããããã§ãADFS ãµãŒããŒãšåã URL ã«å¯Ÿãã IPã¢ãã¬ã¹ã WAP ã® IPã¢ãã¬ã¹ãšãªãããã«å€éš DNS ãµãŒããŒã«ã¬ã³ãŒããç»é²ããŸãã
äžæ¹ã瀟å
ãã ADFS ãµãŒããŒãçµç±ããŠãOffice 365 ã«ã¢ã¯ã»ã¹ããå ŽåãADFS ãµãŒããŒãã®ãã®ã® DNS ã¬ã³ãŒãã®ã»ããå©çšãããµãŒãã¹ã«åããã DNS ã¬ã³ãŒããç»é²ããå¿
èŠããããŸãã
Outlook ã¢ããªã±ãŒã·ã§ã³ãã Office 365 ã«ã¢ã¯ã»ã¹ããå Žåã瀟å€ããã®ã¢ã¯ã»ã¹æ¹æ³ã®èšå®ã«å ããŠã次ã®èšå®ã远å ã§å¿
èŠã«ãªããŸãã
â© å
¬çèªèšŒå±ããçºè¡ãããèšŒææž
ã¢ã¯ãã£ã ãããã¡ã€ã«ã§ã¯ãOffice 365 ãã WAP ã« SSL éä¿¡ãããããOffice 365ã§å©çšå¯èœãªèšŒææžãã€ãŸãå
¬çèªèšŒå±ããçºè¡ãããèšŒææžã WAP ã«å®è£
ããªããã°ãªããŸãããSkype for Business ãã Office 365 ã«ã¢ã¯ã»ã¹ããå Žåãã·ã³ã°ã«ãµã€ã³ãªã³ã®å©çšã®æç¡ã«ãããããªããå¿
èŠãª DNS ã¬ã³ãŒããç»é²ããå¿
èŠããããŸãã
次ã®ããŒãžããåã
ã®é
ç®ã«ã€ããŠãå
·äœçãªèšå®ã確èªããŸãã
Azure Active Directory Connect ã«ãã Office 365 SSO ç°å¢ã®æ§ç¯
ãã€ã¯ããœããã§ã¯ã2015 幎 6 æã« Azure Active Directory Connect (AAD Connect) ãšåŒã°ããããŒã«ãæ°ããæäŸããŸãããAAD Connect 㯠Office 365ã®ã·ã³ã°ã«ãµã€ã³ãªã³ç°å¢ãæ§ç¯ããããã«å¿
èŠãªèšå®ãèªåçã«è¡ããã®ã§ããæ¬ããŒãžã§è§£èª¬ããæé ã®ãã¡ãâ¡,â¢,â£,â¥,â§ã®æé ããŠã£ã¶ãŒããéããŠå®è¡ããããšãã§ããŸãã
![ã¹ã©ã€ã57 ã¹ã©ã€ã57]()
Azure AD ã§ã¯ãæ¢å®ã§ç»é²ãããã¡ã€ã³å (.onmicrosoft.com ã®åœ¢åŒã®ãã¡ã€ã³å) ãšã¯å¥ã«ãªãªãžãã«ã®ãã¡ã€ã³åãèšå®ã§ããŸããAzure AD ã§ãã¡ã€ã³åãèšå®ãããšãAzure AD ã®ãŠãŒã¶ãŒåãããŠãŒã¶ãŒåïŒ ãã¡ã€ã³åãã®åœ¢åŒã§èšå®ã§ãããããçµç¹ã§æ®æ®µäœ¿çšããŠããã¡ãŒã«ã¢ãã¬ã¹ãšãŠãŒã¶ãŒãµã€ã³ã€ã³åãåãã«ã§ããã¡ãªããããããŸãã
Azure AD ã§æ°ãããã¡ã€ã³åãç»é²ããå ŽåãOffice 365 管çã»ã³ã¿ãŒãŸã㯠Azure 管çããŒã¿ã«ç»é¢ããèšå®ã§ããŸãããã¡ã€ã³ç»é²ã¯ã€ã³ã¿ãŒãããã«ããããã¡ã€ã³åãææããŠããçµç¹ã ããç»é²ã§ããããããã¡ã€ã³ç»é²ãè¡ãéã«ãDNS ãµãŒããŒãžã® TXT ã¬ã³ãŒãã®ç»é²ãæ±ããããŸãããã®ãããAzure AD ã®ç®¡çè
ã¯ãèªèº«ã®ãã¡ã€ã³ã® DNS ãµãŒããŒãžã®ã¢ã¯ã»ã¹ãã§ããããšããã㊠DNS ãµãŒããŒãžã®ã¬ã³ãŒãç»é²ã®æ¹æ³ãäºåã«ç¢ºèªããŠãã ããã
Office 365 管çè
ã¢ã«ãŠã³ãã®ã¢ãã¬ã¹
ã·ã³ã°ã«ãµã€ã³ãªã³ã®èšå®ã¯ãã¡ã€ã³ã®åäœã§è¡ããŸãããã®ãããæ°ããäœæãããã¡ã€ã³åãã·ã³ã°ã«ãµã€ã³ãªã³ã§ããããã«æ§æãããšããã®ãã¡ã€ã³åãæã€ãŠãŒã¶ãŒã¯ã·ã³ã°ã«ãµã€ã³ãªã³ã匷å¶ãããŸããOffice 365 ã®å¥çŽæã«äœæããã管çè
ã¢ã«ãŠã³ã (å
šäœç®¡çè
) ã¯ã·ã³ã°ã«ãµã€ã³ãªã³ ãŠãŒã¶ãŒãšããŠæ§æã§ããŸãããADFS ãµãŒããŒãªã©ã®ã·ã³ã°ã«ãµã€ã³ãªã³ç°å¢ã«ãã©ãã«ãçºçãããšãå
šäœç®¡çè
ããµã€ã³ã€ã³ã§ããªããªããŸãããã®ãããæåã®å
šäœç®¡çè
ã¢ã«ãŠã³ãã®ã¢ãã¬ã¹ã«ã¯ããªãªãžãã«ã®ãã¡ã€ã³åãèšå®ãããæ¢å®ã§èšå®ããã onmicrosoft.com ãã¡ã€ã³ãå©çšããããšããå§ãããŸãã
![ã¹ã©ã€ã58 ã¹ã©ã€ã58]()
Active Directory ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ããå©çšã㊠Office 365 ã®ãµã€ã³ã€ã³ãè¡ãå ŽåãActive Directory ãŠãŒã¶ãŒã®ãŠãŒã¶ãŒ ããªã³ã·ãã«å (UPN) ãšãOffice 365 ã«ç»é²ããããŠãŒã¶ãŒå (ã¡ãŒã«ã¢ãã¬ã¹) ã¯åäžã®ãã®ã§ãªããã°ãªããŸãããUPN 㯠Active Directory ãã¡ã€ã³åã«åºã¥ããŠæ±ºå®ãããããããã¡ã€ã³åã« .local ã®ãããªã€ã³ã¿ãŒãããã§ã¯å©çšã§ããªãååãèšå®ããŠãããšãUPN ãš Office 365 ã®ãŠãŒã¶ãŒåã¯åäžã«ã¯ãªããŸããã
ãã®åé¡ã解決ããããã«ãActive Directory ã§ã¯ä»£æ¿ UPNãµãã£ãã¯ã¹ãå©çšããŸããä»£æ¿ UPN ãµãã£ãã¯ã¹ãå©çšãããšãæ¬æ¥ã®ãã¡ã€ã³åã®ä»£ãããšãªããã¡ã€ã³åãèšå®ã§ãããããOffice 365 ãšåäžã®ååãèšå®ã§ããããã«ãªããŸãã
äŸãã°ãexample.local ãã¡ã€ã³ã« yamada ãŠãŒã¶ãŒãååšããå Žåããã®ãŠãŒã¶ãŒã® UPN 㯠yamada@example.local ãšãªããŸããããããOffice 365 ã§ example.com ãã¡ã€ã³ãå©çšããå Žåãyamada ãŠãŒã¶ãŒã®ãŠãŒã¶ãŒå㯠yamada@example.com ãšãªããActive Directory ã® UPN ãšã¯ç°ãªããã®ã«ãªããŸããããã§ãä»£æ¿ UPN ãµãã£ãã¯ã¹ã§ example.com ãèšå®ããŠãããšãyamada ãŠãŒã¶ãŒã® UPN ã yamada@example.local ãã yamada@example.com ã«å€æŽã§ããããã«ãªããŸãããã®çµæãyamada ãŠãŒã¶ãŒã®ãŠãŒã¶ãŒå㯠Active Directory ãš Office 365 ã§åäžã®ååãšãªããŸãã
çããããã«ã¡ã¯ãåœäºã§ãã以åãåœããã°ã§Alternate Login ID(代æ¿ID/代æ¿ãã°ã€ã³ID)ãšããæ¹æ³ãå©çšããŠãOffice365(Azure AD)ã®ã·ã³ã°ã«ãµã€ã³ãªã³(SSO)ãæ§æããæ¹æ³ã玹ä»ããŸããã代æ¿IDã䜿ããšãã£ã¬ã¯ããªåæãSSOã«UPNã䜿ããªããªãã®ã§ãkunii@... AAD Connectã«ãã代æ¿IDèšå® - Always on the clock |
ãµã€ã³ã€ã³ã¢ã«ãŠã³ããš SMTP ã¢ãã¬ã¹
Office 365 ã§ã¯ã管çããŒã¿ã«ãããŠãŒã¶ãŒãäœæããå ŽåãäœæãããŠãŒã¶ãŒå (ãµã€ã³ã€ã³ ã¢ã«ãŠã³ã) ããã®ãŸãŸ Exchange Online ã®SMTP ã¢ãã¬ã¹ã«ãªããŸããããã£ã¬ã¯ããªåæã«ãã£ãŠäœæããããŠãŒã¶ãŒã®å Žåãonmicrosoft.com ãã¡ã€ã³ã®ã¢ãã¬ã¹ããã©ã€ã㪠SMTP ã¢ãã¬ã¹ãšãªãããã£ã¬ã¯ããªåæã«ãã£ãŠäœæãããŠãŒã¶ãŒã®ã¢ãã¬ã¹ã¯ãã©ã€ã㪠SMTP ã¢ãã¬ã¹ã«ã¯ãªããŸããããã®ãããåæãŠãŒã¶ãŒã®ã¢ãã¬ã¹ããã©ã€ã㪠SMTP ã¢ãã¬ã¹ã«æç€ºçã«æå®ããå Žåãã¡ãŒã«ã¢ãã¬ã¹ (mail) 屿§ã« UPNãšåãã¢ãã¬ã¹ãèšå®ããããproxyaddresses 屿§ã«ãSMTP:<UPN>ã(SMTP ã¯å€§æå)ãšå
¥åããèšå®ããŸãã
Â
![ã¹ã©ã€ã59 ã¹ã©ã€ã59]()
åã®ããŒãžã§ã解説ããããã«ãOffice 365 ã§ã·ã³ã°ã« ãµã€ã³ãªã³ãå®è¡ãããšãã«ã¯ããªã³ãã¬ãã¹ã«ADFS ãµãŒããŒãé
眮ããå¿
èŠããããŸããOffice 365 ã«ããã ADFS ãµãŒããŒã¯ãCP ãšããŠã®ã¿åäœããããã飿ºããŠåäœããèšŒææžå©çšè
ä¿¡é Œ (RP) ãå¥éæå®ããªããã°ãªããŸãããOffice 365 ã®ããã®èšŒææžå©çšè
ä¿¡é Œã®èšå®ã¯ããWindows PowerShell çš Windows Azure Active Directory ã¢ãžã¥ãŒã«ããšããããŒã«ã䜿ã£ãŠè¡ãå¿
èŠããããŸãã
Windows PowerShell çš Windows Azure Active Directory ã¢ãžã¥ãŒã«ã¯ãOffice 365 ã®ãµã€ãããããŠã³ããŒãããããšãã§ããŸããã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ãããšãã¯ãåãã Office 365 ã®ãµã€ãããããŠã³ããŒãã»ã€ã³ã¹ããŒã«å¯èœãªãã£ã¬ã¯ããªåæããŒã«ããããã¯ãã€ã¯ããœãã Web ãµã€ãããããŠã³ããŒãã»ã€ã³ã¹ããŒã«å¯èœãª ãMicrosoft Online Services ãµã€ã³ã€ã³ ã¢ã·ã¹ã¿ã³ããããŒã«ãã€ã³ã¹ããŒã«ããŠããå¿
èŠããããŸãã
Windows PowerShell çš Windows Azure Active Directory ã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããã³ã³ãã¥ãŒã¿ãŒã«ã¯ããã¹ã¯ãããã«ã·ã§ãŒãã«ãããäœæãããã®ã§ããã®ã·ã§ãŒãã«ãããã Windows PowerShell ãå®è¡ããŸããæ¬¡ã®ã³ãã³ãã¬ãããå®è¡ããããšã§ãèªåçã«èšŒææžå©çšè
ä¿¡é Œã®èšå®ãæœãããŸãã
â Azure AD ãžã®æ¥ç¶ã®ããã®ã³ãã³ãã¬ãã
$Cred = Get-Credential
Connect-MsolService -Credential $cred
â ã·ã³ã°ã«ãµã€ã³ãªã³ã®ããã«äœ¿çšãã ADFS ãµãŒããŒã®æå®
Set-ADFSContext -Computer <ADFSãµãŒããŒå>
â ã·ã³ã°ã«ãµã€ã³ãªã³ã®ããã«äœ¿çšãããã¡ã€ã³åã®æå®
Convert-MsolDomainToFederated -DomainName <ãã¡ã€ã³å>
Convert-MsolDomainToFederated ã³ãã³ãã¬ãããå®è¡ãããšãOffice 365 ã§äœ¿çšãããã¡ã€ã³åã®ãã¡ãã·ã³ã°ã«ãµã€ã³ãªã³ã«äœ¿çšãããã¡ã€ã³åãå®çŸ©ããããšãã§ããŸãããªããConvert-MsolDomainToFederated ã³ãã³ãã¬ããã§å®çŸ©å¯èœãªãã¡ã€ã³åã¯äºåã« Azure AD ã«ç»é²ããããã¡ã€ã³ã ãã§ãããã¡ã€ã³ææè
ã®ç¢ºèªãå®äºãããšãOffice 365 ã®ç®¡çè
ã³ã³ãœãŒã«ã«è¡šç€ºããããã¡ã€ã³åäžèЧã§ãã®æšç¢ºèªã§ããŸãã
è€æ°ã® Active Directory ãã¡ã€ã³ããã§ãã¬ãŒã·ã§ã³ ãã¡ã€ã³ãšããŠå©çšãã
ãã§ãã¬ãŒã·ã§ã³ ãã¡ã€ã³ã®ç»é²ã¯ Convert-MsolDomainToFederated ã³ãã³ãã¬ãããå©çšããŠè¡ãããšããããŸã§ã§åŠç¿ããŸããããã®ãšããè€æ°ã® Active Directory ãã¡ã€ã³ã§ãè€æ°ã®ä»£æ¿ UPN ãµãã£ãã¯ã¹ãå©çšããŠåæãè¡ããè€æ°ã®ãã§ãã¬ãŒã·ã§ã³ ãã¡ã€ã³ãšã㊠ID 飿ºãè¡ãå Žåãããããã®ã³ãã³ãã¬ããã®å®è¡æã«ã-supportmultipledomain ãªãã·ã§ã³ãä»ããŠå®è¡ããŸãã
![ã¹ã©ã€ã60 ã¹ã©ã€ã60]()
Office 365 ã§ã¯ãADFS ãµãŒããŒã§çºè¡ãããããŒã¯ã³ãããšã«ãAzure AD ã«ç»é²ãããŠãããŠãŒã¶ãŒãšã®ãããã³ã°ãè¡ããŸãããã®ãããActive Directory ãŠãŒã¶ãŒã®æ
å ±ã¯ Azure AD ã«ã³ã㌠(åæ) ãããå¿
èŠããããŸãããŠãŒã¶ãŒæ
å ±ã®åæã«ã¯ãOffice 365ã®ãµã€ãããããŠã³ããŒãã»ã€ã³ã¹ããŒã«å¯èœãªãã£ã¬ã¯ããªåæããŒã«ãå©çšããŸãã
ãã£ã¬ã¯ããªåæããŒã«ã¯ã64 ãããçã®ã»ããã¢ããããã°ã©ã ã ããæäŸãããŠããããã¡ã€ã³ã³ã³ãããŒã©ãŒãå«ããä»»æã® 64 ãããçWindows Server OS ã«ã€ã³ã¹ããŒã«ããããšãã§ããŸãããã£ã¬ã¯ããªåæããŒã«ãã€ã³ã¹ããŒã«ãããšãååèµ·åæã« Active Directory ã®ãã¡ã€ã³ç®¡çè
ãš Azure AD ã®ç®¡çè
ã¢ã«ãŠã³ãã®è³æ Œæ
å ±ã®æç€ºãæ±ããããŸããå
¥åããè³æ Œæ
å ±ã¯ãã£ã¬ã¯ããªåæããŒã«ã®äžã§ä¿åããã2 åç®ä»¥éã®ãã£ã¬ã¯ããªåæã®ããã«äœ¿ãããŸãã
ãã£ã¬ã¯ããªåæããŒã«ãå®è¡ãããšãActive Directory ãã¡ã€ã³ã«ä¿åãããŠãããŠãŒã¶ãŒæ
å ±ã Azure AD ã«åæãããŸããåæã¯ (çŸæç¹ã§ã¯) Active Directory ãã Azure AD ã«å¯ŸããŠäžæ¹åã«è¡ãããããããã£ã¬ã¯ããªåæããŒã«ã§åæããããŠãŒã¶ãŒã®æ
å ±ã¯ Office 365 ãã倿Žããããšãã§ããŸããã
ãŸãããã£ã¬ã¯ããªåæããŒã«ã§ã¯ã¢ã«ãŠã³ãã®åæãè¡ããŸãããAzure AD ã«åæããããŠãŒã¶ãŒã«å¯Ÿãã Office 365ã®ã©ã€ã»ã³ã¹ã®é¢é£ä»ãã¯è¡ããŸããããã®ããããã£ã¬ã¯ããªåæã®å®äºåŸãå¿
èŠã«å¿ããŠåæãŠãŒã¶ãŒãžã®ã©ã€ã»ã³ã¹å²ãåœãŠã Office 365 管çããŒã¿ã«ãªã©ããè¡ã£ãŠãã ããã
SQL Server ãå©çšããŠãã£ã¬ã¯ããªåæããŒã«ãã€ã³ã¹ããŒã«
ãã£ã¬ã¯ããªåæããŒã«ã¯ããŒã¿ããŒã¹ãšã㊠SQL Server Express ãå©çšããŸããSQL Server Express ã®æå€§ããŒã¿ããŒã¹ ãµã€ãºã¯ 2GB ã§ããããã£ã¬ã¯ããªåæããŒã«ã§æ±ã ID ã®æ°ãšã㊠50000 ã¢ã«ãŠã³ããäžéãšãããŠããŸãããã®ããã50000 ã¢ã«ãŠã³ããè¶
ããŠåæãè¡ãå¿
èŠãããå ŽåãSQL Server Express ã§ã¯ãªããSQL Server ãå©çšããŠåæãè¡ãããã«ã€ã³ã¹ããŒã«ããå¿
èŠããããŸããAAD Connect ããã€ã³ã¹ããŒã«ããéã«æ¢åã® SQL Server ãå©çšããŠãã£ã¬ã¯ããªåæããŒã«ãã€ã³ã¹ããŒã«ããããã«éžæã§ããŸãã
![ã¹ã©ã€ã61 ã¹ã©ã€ã61]()
ãã©ãŠã¶ãŒãã Office 365 ãµã€ãã«ã¢ã¯ã»ã¹ããã·ã³ã°ã« ãµã€ã³ãªã³ãè¡ãå ŽåãActive Directory ã«ãããèªèšŒçµæ (Kerberos ãã±ãã) ãããšã« (ã€ãŸã Windows çµ±åèªèšŒãå©çšããŠ) ãŠãŒã¶ãŒã®ããŒã¯ã³ãçºè¡ããŸãããã®ãããKerberos ãã±ããããã©ãŠã¶ãŒã®æäœã«ãã£ãŠèªåçã« Office 365 ãµã€ãã«éä¿¡ããèªèšŒãè¡ããããã«ããå¿
èŠããããŸãã
Kerberos ãã±ãããå©çšããŠãèªåçã«ãµã€ã³ã€ã³ãè¡ããããã«ããã«ã¯ãInternet Explorer ã® [ããŒã«ã« ã€ã³ãã©ããã] ãã ADFS ãµãŒããŒã®ãšã³ããã€ã³ã URL (https://<ãã§ãã¬ãŒã·ã§ã³ ãµãŒãã¹å>/adfs/ls/) ãç»é²ããå¿
èŠããããŸãã
ãµã€ã³ã€ã³ãŠãŒã¶ãŒãšã¯ç°ãªããŠãŒã¶ãŒã§ Office 365 ã«ãµã€ã³ã€ã³ãã
ãã©ãã«ã·ã¥ãŒãã£ã³ã°ãªã©ã®ç®çã§ Windows ã«ãµã€ã³ã€ã³ãããŠãŒã¶ãŒãšã¯ç°ãªããŠãŒã¶ãŒã§ Office 365 ã«ãµã€ã³ã€ã³ããå Žåããã©ãŠã¶ãŒã®ããŒã«ã«ã€ã³ãã©ãããã®èšå®ãè¡ããªãã§ãã ãããããŒã«ã«ã€ã³ãã©ãããã®èšå®ãè¡ããªãå ŽåãOffice 365ã«ãµã€ã³ã€ã³ããã¿ã€ãã³ã°ã§èªèšŒãã€ã¢ãã°ã衚瀺ãããã®ã§ãããã§çŸåšãµã€ã³ã€ã³ããŠãããŠãŒã¶ãŒãšã¯ç°ãªããŠãŒã¶ãŒã§ãµã€ã³ã€ã³ããããšãã§ããŸãã
Internet Explorer 以å€ã®ãã©ãŠã¶ãŒãã Office 365 ã«ãµã€ã³ã€ã³ãã
Internet Explorer 以å€ã®ãã©ãŠã¶ãŒãå©çšããŠãµã€ã³ã€ã³ããå Žåãããããã ADFS ãµãŒããŒã§ã·ã³ã°ã«ãµã€ã³ãªã³ãèš±å¯ãããããèšå®ããå¿
èŠããããŸããADFSãµãŒããŒã§ã® SSO èš±å¯èšå®ã¯ããã©ãŠã¶ãŒçš®é¡ãšããŒãžã§ã³ã®åäœã§è¡ãå¿
èŠããããPowerShell ã®ä»¥äžã®ã³ãã³ãã¬ãããå®è¡ããç»é²ããŸãã
â Firefox ã Google Chrome (Mozilla/5.0) ã SSO çšãã©ãŠã¶ãŒãšããŠç»é²
$old=(Get-AdfsProperties).WIASupportedUserAgents
$new=$old+âMozilla/5.0â³
Set-ADFSProperties -WIASupportedUserAgents $new
![ã¹ã©ã€ã62 ã¹ã©ã€ã62]()
å€åºå
ãã Office 365 ã«ã¢ã¯ã»ã¹ããå Žåã Outlook ã¢ããªã±ãŒã·ã§ã³ãã Office 365ã«ã¢ã¯ã»ã¹ããå ŽåãADFS ãµãŒããŒã®ä»£ããã« WAP ã«ã¢ã¯ã»ã¹ããŠã·ã³ã°ã«ãµã€ã³ãªã³ ããã»ã¹ãéå§ããŸãããã®ããããããã®ã¢ã¯ã»ã¹æ¹æ³ããµããŒãããå Žåã«ã¯ãäºåã« WAP ãã€ã³ã¹ããŒã«ããŠããå¿
èŠããããŸãã
WAP çµç±ã§ã®ããŒã¯ã³çºè¡ããã»ã¹ã¯ãADFS ãµãŒããŒã«ã¢ã¯ã»ã¹ãããšããšåãèšŒææžãå©çšããå¿
èŠããããŸãããã®ãããWAP ãã€ã³ã¹ããŒã«ããåã« ADFSãµãŒããŒã«å®è£
ãã SSL èšŒææžãšåãèšŒææžã WAP ã«å®è£
ããŠãã ããã
ãªããWAP ã§ã¯å€éšã«å
¬éããèšŒææžå©çšè
ä¿¡é Œãæç€ºçã«æå®ããå¿
èŠããããŸãããAzure AD ã®èšŒææžå©çšè
ä¿¡é Œãå
¬éããå Žåããã®èšå®ã¯äžèŠã§ããWAPã®ã€ã³ã¹ããŒã«ãå®äºããã°ãèªåçã« ADFS ãµãŒããŒãžã®ããŒã¯ã³ã®çºè¡èŠæ±ã¯è»¢éãããããã«åäœããŸãã
![ã¹ã©ã€ã63 ã¹ã©ã€ã63]()
Office 365 ã§ã¯ããã©ãŠã¶ãŒããã¢ã¯ã»ã¹ããå ŽåãOutlook ããã¢ã¯ã»ã¹ããå ŽåãSkype for Businessããã¢ã¯ã»ã¹ããå Žåãšãæ§ã
ãªã·ã³ã°ã« ãµã€ã³ãªã³æ¹æ³ããããŸãããã®ãããã©ã®ãããªã¢ããªã±ãŒã·ã§ã³ããã¢ã¯ã»ã¹ãè¡ããã«ãã£ãŠãå¿
èŠãšãªã DNS ã¬ã³ãŒããç°ãªããŸããããã§ã¯ãããããã®ã±ãŒã¹ã«ãããŠå¿
èŠãª DNS ã¬ã³ãŒãã«ã€ããŠç¢ºèªããŸãã
â 瀟å
ãããã©ãŠã¶ãŒã§ã¢ã¯ã»ã¹ããå Žå
ADFS ãµãŒããŒã«ã¢ã¯ã»ã¹ããããã®ã¬ã³ãŒã (A ã¬ã³ãŒã) ã瀟å
DNS ãµãŒããŒã«äœãããŠããã°ãã·ã³ã°ã«ãµã€ã³ãªã³ãå®çŸããŸãããªããNLB ãªã©ã«ãã£ãŠ ADFS ãµãŒããŒãè€æ°å°ç«ãŠãŠéçšããŠãããšãã«ã¯ãè² è·åæ£çš IP ã¢ãã¬ã¹ã Aã¬ã³ãŒãã«ç»é²ããŠãã ããã
â 瀟å
ãã Skype for Business (SfB) ã§ã¢ã¯ã»ã¹ããå Žå
瀟å
ãããªããã¯ã©ã€ã¢ã³ã ãããã¡ã€ã«ã§ã¢ã¯ã»ã¹ããå Žåãåºæ¬çã«ããã·ããããã¡ã€ã«ãšåãã§ãããã ããSfB Online é¢é£ã®ã¬ã³ãŒãã¯ç€Ÿå
ã® DNS ãµãŒããŒã§åå解決ããããã瀟å
ã® DNS ãµãŒããŒã« SfB Online é¢é£ã®ã¬ã³ãŒããäžç·ã«ç»é²ããŠãã ããã
â 瀟å€ããSkype for Business ãŸãã¯ãã©ãŠã¶ãŒã§ã¢ã¯ã»ã¹ããå Žå
瀟å€ããã¢ã¯ã»ã¹ããå ŽåãWAP ã®ã¢ãã¬ã¹ãå€éš DNS ãµãŒããŒã« A ã¬ã³ãŒããšããŠç»é²ããŸãããŸããSfB ãå©çšããŠããå Žå㯠SfB Online é¢é£ã¬ã³ãŒããå€éš DNS ãµãŒããŒã«ç»é²ããŠãã ããã
â Outlook ã§ã¢ã¯ã»ã¹ããå Žå
Outlook ããã·ã³ã°ã«ãµã€ã³ãªã³ãå®è¡ããå ŽåãWAP ã®ã¢ãã¬ã¹ã瀟å
DNS ãµãŒããŒãšå€éš DNS ãµãŒããŒã« ãããã A ã¬ã³ãŒããšããŠç»é²ããŸãããŸããExchange Online é¢é£ã¬ã³ãŒãããããããã® DNS ãµãŒããŒã«ç»é²ããŠãã ããã
ç·šéåŸèš
Advent Calendar颚ã«12æ25æ¥ãŸã§ãã£ãããšå
¬éããŠããããšæã£ãã®ã§ãããåéãå€ãããŠããããŸã§ã¯å¹Žå
ã«å
¬éãçµãããªãããã§ãããã®ããã仿¥ã¯å°ãããªã¥ãŒã ãå¢ãããŠã¿ãŸãããèªã¿ã«ãããªã©ã®æèŠãããã°ãåå²ããŠå
¬éããŸãã®ã§ããæèŠãªã©ãå¯ããã ããã
The post ADFSãã¬ãŒãã³ã°ããã¹ãå
šæå
¬éãã£ã¬ã³ãž(9) â Office365飿ºç°å¢ã®æ§ç¯ã¹ããã first appeared on Always on the clock.