title | date | tags | toc | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
ã管çè
ã®æ¿èªãå¿
èŠãã®ã¡ãã»ãŒãžã衚瀺ãããå Žåã®å¯ŸåŠæ³ |
2020-05-22 |
|
|
ããã«ã¡ã¯ãAzure Identity ããŒã ã®åŽå±±ã§ãã
ä»åã¯ãAzure AD ã®åæã®ãã¬ãŒã ã¯ãŒã¯ã«ã€ããŠè§£èª¬ããŸãã
æ©éã§ãããçããã¯ã¢ããªã±ãŒã·ã§ã³ãå©çšããããšæã£ãéã«ã以äžã®ããã«ã"管çè ã®æ¿èªãå¿ èŠ" ãšè¡šç€ºãããŠããŸã£ãããšã¯ç¡ãã§ããããã
ãããã¯ã以äžã®ãããªåæç»é¢ãèŠãããšã¯ãªãã§ããããã
å€ãã¯ã¢ããªã±ãŒã·ã§ã³ãå©çšããéã«è¡šç€ºãããç»é¢ã§ãããçããã¯ãã®ç»é¢ã®æå³ããåããã§ããããã
ãã®ç»é¢ã¯ãAzure AD ã®åæã®ãã¬ãŒã ã¯ãŒã¯ãšåŒã°ããä»çµã¿ã§ããŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããå®å šã«æš©éãå§ä»»ããããã®ä»çµã¿ã§ãã
ä»åã¯ããã®åæã®ãã¬ãŒã ã¯ãŒã¯ã«ã€ããŠãã©ã®ãããªæ©èœã§ããã"管çè ã®æ¿èªãå¿ èŠ" ãšè¡šç€ºããããšãã«ã¯ãã©ã®ããã«å¯ŸåŠããã°ããã®ãã次ã®é çªã§è§£èª¬ããŸãã
- äœã®ããã®æ©èœãªã®ã
- ã¢ããªã±ãŒã·ã§ã³ã«åæãè¡ãããšã§äœãèµ·ããã®ã
- ã©ã®ãããªåæã®çš®é¡ãããã®ã
- 管çè ã®åæãå¿ èŠãšè¡šç€ºãããéã®å¯ŸåŠæ³
- 管çè ã«ããåæã®ä»äžæé
- ã¢ããªã±ãŒã·ã§ã³ã«åææžã¿ã®æš©éã確èªãã
- ã¢ããªã±ãŒã·ã§ã³ã«ä»äžããæš©éãåãæ¶ã
ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã®æ¹æ³ãšãåæã®æé ã ã確èªãããæ¹ã¯ã管çè ã®æ¿èªãå¿ èŠãšè¡šç€ºãããéã®å¯ŸåŠæ³ ã®é ç®ã確èªãã ããã
Microsoft ã®ãµãŒãã¹ãå§ããã¯ã©ãŠã ãµãŒãã¹ãæ®åããçŸä»£ã§ã¯ãçããã¯æ¥ã ã®æ¥åã«å€ãã®ãµãŒãã¹ãå©çšããŠãããã®ãšåããŸãã å€ãã®æ¥åãå¹ççã«è¡ãã«ã¯ããµãŒãã¹éã®é£æºããŸããŸãéèŠã«ãªã£ãŠããŸãã
ã¢ããªã±ãŒã·ã§ã³ã®é£æºã®äŸãšã㊠Power Automate ã§ã¯ Microsoft 補åã 3rd ããŒãã£ãŒã®è£œåãé£æºããæ¥åãããŒãèªååããããšãå¯èœã§ããããšãã°ãç¹å®ã®ã¿ã€ãã«ãå«ãŸããã¡ãŒã«ããExchange Online ã§åä¿¡ããããTeams ã«éç¥ãéãããšãã£ãããšãç°¡åã«å®çŸã§ããŸãã
äžæ¹ã3rd ããŒãã£ãŒã®è£œåå ã§ãOffice 365 ã®ããŒã¿ãæ©èœãå©çšãããããšãããã§ããããäŸãã°ãSlack å 㧠Teams ã®ãããªäŒè°ãè¡ãããšãã£ãããšãå¯èœã§ãã ãã®ããã«ãå¥ã®ã¢ããªã±ãŒã·ã§ã³ãã Azure ã Office 365 ã®ããŒã¿ãåŒã³åºãã«ã¯ãPower Automate ããSlack ãšãã£ãã¢ããªã±ãŒã·ã§ã³ãã¡ãŒã«ããã¯ã¹ã®äžèº«ãèŠãããTeams ã®æ©èœãåŒã³åºããããã«ããå¿ èŠããããŸãã
ããããé£æºãããã¢ããªã±ãŒã·ã§ã³ã«å¯ŸããID ããã¹ã¯ãŒããšãã£ãèªèšŒæ å ±ããã¹ãŠæž¡ããŠããŸã£ãŠã¯ã察象ã®ã¢ããªã±ãŒã·ã§ã³ã¯å®å šã«ãŠãŒã¶ãŒã«ãªãæ¿ãã£ãŠããã¹ãŠã®ããŒã¿ã«ã¢ã¯ã»ã¹ããããšãå¯èœã«ãªã£ãŠããŸããŸããèªèšŒæ å ±ããã¹ãŠæž¡ãã®ã§ã¯ãªããã¢ããªã±ãŒã·ã§ã³ã«å¿ èŠãªæš©éã®ã¿ãå§ä»»ããæ¹æ³ãå¿ èŠã§ããããšãç解ã§ãããšæããŸãã
ããã§ãAzure AD ã§ã¯ OAuth (ããŒããã) ãšãããããã³ã«ãå©çšããåæã®ãã¬ãŒã ã¯ãŒã¯ãã€ãããå¿ èŠãªæš©éã®ã¿ãã¢ããªã±ãŒã·ã§ã³ã«ä»äžããããšãã§ããããã«ãªã£ãŠããŸãã
åæã®ãã¬ãŒã ã¯ãŒã¯å ã§ã¯ Office 365 ã®ããŒã¿ãæ©èœããAzure AD ã«ããä¿è·ããããªãœãŒã¹ãšåŒã³ãAzure AD ã§ã¯ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ãè¡ãæš©éããã¹ã³ãŒããšããç¯å²ã§ç®¡çããŠããŸãã äžå³ã§ã¢ããªã±ãŒã·ã§ã³ãå¿ èŠãšããæš©éã®ã¿ãäžããããã«ã¯ãExchange Online ãšãããªãœãŒã¹ã®èªã¿èŸŒã¿ã¹ã³ãŒãæš©éãã¢ããªã±ãŒã·ã§ã³ã«ä»äžããŸãã
ããã§ã¯çŽ°ãããããã³ã«ã®è©³çŽ°ã«ã€ããŠã¯èª¬æããŸããããèªèšŒãšæ¿èªã«é¢ããããã¥ã¡ã³ããªã©ã§è©³ãã説æãããŠããŸãã®ã§ãèå³ã®ããæ¹ã¯ã芧ãã ããã
次ã«ã¢ããªã±ãŒã·ã§ã³ã«åæããããšã§ã©ããªãã®ããèŠãŠãããŸãããŸãã¯ãã¢ããªã±ãŒã·ã§ã³ã«äžããæš©éã®çš®é¡ã«ã€ããŠæŒãããŠãããŸãããã
ã¢ããªã±ãŒã·ã§ã³ã«äžããæš©éãšããŠã倧ãã 2 ã€ã®çš®é¡ããããŸãããŠãŒã¶ãŒå§ä»»ã®æš©éãšãã¢ããªã±ãŒã·ã§ã³æš©éã§ãã
ãŠãŒã¶ãŒå§ä»»ã®æš©éã¯ãã¢ããªã±ãŒã·ã§ã³ããŠãŒã¶ãŒã®ä»£ããã«ããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããã®æš©éã§ãã ã¢ããªã±ãŒã·ã§ã³ãæš©éãåŸãã«ã¯ããªãœãŒã¹ãææãããŠãŒã¶ãŒã®åæãå¿ èŠã§ãã ãã®ãŠãŒã¶ãŒåæãæ±ããããç»é¢ãåé ã®ç»åã§ããç»åã«ããããã«ãŠãŒã¶ãŒãä¿æããŠããæš©éã®äžã§ãå ·äœçã«ã©ã®ãããªæš©éãã¢ããªã±ãŒã·ã§ã³ã«å§ä»»ããã®ããé ç®ãšããŠè¡šç€ºãããŠããŸããç»åã§ããš Read your calendars ãªã©ããããŸãããåæãåŸããããšãã¢ããªã±ãŒã·ã§ã³ã¯ããŠãŒã¶ãŒã®ä»£ããã«äºå®è¡šãèªã¿åããããã«ãªããŸãã
ãŠãŒã¶ãŒããµã€ã³ã€ã³ããŠã¢ã¯ã»ã¹ããã¢ããªã±ãŒã·ã§ã³ã®å€ãã¯ããŠãŒã¶ãŒå§ä»»ã®æš©éã§ã¢ã¯ã»ã¹æš©ãèŠæ±ããŸãã
次ã«ã¢ããªã±ãŒã·ã§ã³ã®æš©éã§ãããããã¯ãç¹å®ã®ã¹ã³ãŒãã®ç¯å²ã§ Azure AD å ã®ãã¹ãŠã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšãå¯èœã§ãã æš©éãšããŠã¯åãååã§ãããŠãŒã¶ãŒå§ä»»ã®æš©éãšãã¢ããªã±ãŒã·ã§ã³å§ä»»ã®æš©éã§ã¯ãè¡ããããšãéããŸãã®ã§ã泚æãã ããã
ãŸããã¢ããªã±ãŒã·ã§ã³ããªãœãŒã¹ã«ã¢ã¯ã»ã¹ãããããŒãç°ãªããŸãããŠãŒã¶ãŒå§ä»»ã®æš©éãããŠãŒã¶ãŒã®ãµã€ã³ã€ã³åŸã«åããŠãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããã®ã«å¯Ÿããã¢ããªã±ãŒã·ã§ã³ã®æš©éã§ã¯ã¢ããªã±ãŒã·ã§ã³ã«äžããããèªèšŒæ å ±ã§èªèšŒãããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¯èœã§ãã
ã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããæš©éã®å§ä»»ãè¡ãã«ã¯ã以äžã®ãããªåæç»é¢ã§ [æ¿è«Ÿ] ãã¯ãªãã¯ããåæãå®äºãããå¿ èŠããããŸãã
å®ã¯ãã®åæã®æ¹æ³ã«ããäžè¬ãŠãŒã¶ãŒã«ãããŠãŒã¶ãŒã®åæãšã管çè ã«ãã管çè ã®åæã® 2 ã€ã®çš®é¡ããããŸãã
ãã®åã®éãããŠãŒã¶ãŒã®åæã¯äžè¬ãŠãŒã¶ãŒæš©éã§è¡ãããšãåºæ¥ããŠãŒã¶ãŒå§ä»»ã®æš©éã®ã¿ ã«åæå¯èœã§ãã
管çè ã®åæã¯ã次㮠3 ã€ã®ã±ãŒã¹ã§å¿ èŠã«ãªããŸãã
- ããã³ãã®èšå®ã§ãŠãŒã¶ãŒã«ã¯åæãèš±å¯ããŠããªã
- äžéšã®é«ãæš©éãèŠæ±ãããŠãŒã¶ãŒå§ä»»ã®æš©é (äŸãã°
SecurityEvents.Read.All
ãšãã£ãæš©é) ã«åæãä»äžãã - ã¢ããªã±ãŒã·ã§ã³æš©éã®èŠæ±ã«å¯ŸããŠåæãä»äžãã
ãããŸã§ã®è©±ãããã£ãããŸãšãããšä»¥äžã®ãããªå¯Ÿå¿è¡šã«ãªããŸãã
æš©éã®çš®é¡ | åæå¯èœãªãŠãŒã¶ãŒ |
---|---|
ãŠãŒã¶ãŒå§ä»» | äžè¬ãŠãŒã¶ãŒ / 管çè |
ãŠãŒã¶ãŒå§ä»» (äžéšã®æš©é) | 管çè |
ã¢ããªã±ãŒã·ã§ã³æš©é | 管çè |
管çè ã®åæãå¿ èŠãªæš©éã«ã€ããŠã¯ãMicrosoft Graph ã®ã¢ã¯ã»ã¹èš±å¯ã®ãªãã¡ã¬ã³ã¹ ã«ã"管çè ã®åæãå¿ èŠ" ã "ã¯ã" ãšè¡šèšãããŠãããŸãã®ã§ãã¢ããªã«å¿ èŠãªæš©éã«å¯Ÿãã管çè ã®åæãå¿ èŠãã©ãã確èªã§ããŸãã
ãããŸã§ã§æš©éã®çš®é¡ãšãåæã®çš®é¡ããããã 2 ã€ååšããããšã説æããŸããããããããã®ãã¿ãŒã³ã§ã¢ããªã±ãŒã·ã§ã³ãã©ã®ç¯å²ã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹å¯èœãã確èªããŸãããã ãŠãŒã¶ãŒå§ä»»ã®æš©éã®å Žåãã¢ããªã±ãŒã·ã§ã³ãã¢ã¯ã»ã¹ã§ããããŒã¿ã®ç¯å²ã¯ã"èš±å¯ãããã¹ã³ãŒã" ã®ç¯å²ããã€ã"ãµã€ã³ã€ã³ããŠãããŠãŒã¶ãŒãæã€æš©éã®ç¯å²" ã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ãå¯èœã§ãã
äŸãã°ããŠãŒã¶ãŒã®ã¡ãŒã«ãååŸãããMail.Read
ã®æš©éãèŠæ±ããã¢ããªã¯ããµã€ã³ã€ã³ãŠãŒã¶ãŒãã¢ã¯ã»ã¹ã§ããã¡ãŒã«ããã¯ã¹ã«å¯Ÿããèªã¿åãæš©éãäžããããŸãã
ãã®ããããµã€ã³ã€ã³ ãŠãŒã¶ãŒãã¢ã¯ã»ã¹åºæ¥ãªãããŒã¿ã«ã¢ã¯ã»ã¹ããããšã¯ãããŸãããå¿
ããã¹ã³ãŒãã®ç¯å²ãšãµã€ã³ã€ã³ ãŠãŒã¶ãŒãä¿æãããŠãŒã¶ãŒæš©éã®äž¡æ¹ãæºãããªãœãŒã¹ãã¢ã¯ã»ã¹å¯èœãªç¯å²ã§ãã
äžæ¹ãã¢ããªã±ãŒã·ã§ã³ã®æš©éã§ãMail.Read ã®æš©éãèŠæ±ããã¢ããªã¯ãããã³ãã«ç»é²ãããŠãããã¹ãŠã®ã¡ãŒã«ããã¯ã¹ã«å¯Ÿããã¢ã¯ã»ã¹ãå¯èœã§ãããã®ããããã®æš©éãä»äžããã«ã¯ãçžå¿ã®ç®¡çæš©éãå¿ èŠã§ãã
ãããŸã§ãAzure AD ã®åæã®ãã¬ãŒã ã¯ãŒã¯ã«ã€ããŠã®æŠèŠã説æããŸãããã 管çè ã®æ¿èªãå¿ èŠãšè¡šç€ºãããéã®ã察åŠæ¹æ³ã«ã€ããŠèª¬æããŸãããšã¯èšã£ãŠããã»ãšãã©ã®å Žå "管çè ã®æ¿èªãå¿ èŠ" ãšè¡šç€ºãããå Žåãããã³ãã®ç®¡çè ã«ããåæãè¡ããããããŸããã
ãã ãã管çè ã«ããåæãæ±ããããçç±ã«ã€ããŠã¯ããã€ããããŸãã®ã§äž»ãªçç±ã玹ä»ããŸãããŸãã¯ä»¥äžã®ãããŒå³ã確èªãã ããã
管çè ã®åæãæ±ãããã â ïœâ£ ã®ãã¿ãŒã³ã«ã€ããŠã以äžã«èª¬æããŸãã
ããã³ãã§ãŠãŒã¶ãŒåæãå¶éãããŠããå Žåãäžè¬ãŠãŒã¶ãŒã«ããã¢ããªã®åæãè¡ãããšã¯åºæ¥ãŸããããã®å Žåãã¢ããªã管çè ã«ããåæãå¿ èŠã®ãªããŠãŒã¶ãŒå§ä»»ã®æš©éã®ã¿ãèŠæ±ããŠããå Žåã§ãã管çè ã«ããåæãå¿ èŠãšãªããŸãã ãŠãŒã¶ãŒã®åæãå¶éãããŠããç°å¢ãã©ããã¯ãAzure ããŒã¿ã«ã® ãšã³ã¿ãŒãã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ã®åæãšã¢ã¯ã»ã¹èš±å¯ ãã確èªã§ããŸãã
[ã¢ããªã±ãŒã·ã§ã³ã«å¯ŸãããŠãŒã¶ãŒã®åæ] ã®èšå®ã [ã¢ããªã«å¯ŸãããŠãŒã¶ãŒã®åæãèš±å¯ãã] ã®å ŽåããŠãŒã¶ãŒåæãå¯èœã§ããèšå®ã [ãŠãŒã¶ãŒã®åæãèš±å¯ããªã] ã®å ŽåããŠãŒã¶ãŒã«ããåæãå¶éãããŠãããããã¢ããªãžã®æš©éãä»äžããããã«ã¯ç®¡çè ã®åæãå¿ èŠã§ãã
äžèš [ã¢ããªã«å¯ŸãããŠãŒã¶ãŒã®åæãèš±å¯ãã] ãš [ãŠãŒã¶ãŒã®åæãèš±å¯ããªã] ã®èšå®ã¯ã以äžã® Microsoft 365 管çããŒã¿ã«ã®ãçµ±åã¢ããªã®èšå® ã®ãã§ãã¯ã®æç¡ãšåçã§ãã
äžæ¹ãåæãšã¢ã¯ã»ã¹èš±å¯ã§èšå®å¯èœãª [確èªæžã¿ã®çºè¡å ããã®ã¢ããªã«å¯ŸããŠéžæãããã¢ã¯ã»ã¹èš±å¯ãäžããããšãžã®ãŠãŒã¶ãŒã®åæãèš±å¯ãã (æšå¥š)] ã¯ãããã®äžéã®éžæè¢ã§ãã
ãã®æšå¥šèšå®ã§ã¯ãäžè¬ãŠãŒã¶ãŒã¯çºè¡è
確èªãè¡ãããã¢ããªããŸãã¯èªããã³ãã«ç»é²ãããã¢ããªã®ã¿ã«åæãå¯èœãšãªããŸããããã«å ã管çè
ãäºåã« äœåœ±é¿ ãšããŠåé¡ããã¢ã¯ã»ã¹èš±å¯ ã«ã®ã¿ãŠãŒã¶ãŒãåæå¯èœãšãªããŸããäŸãã°äžè¬çãªã¢ããªã®ãµã€ã³ã€ã³ã«å¿
èŠãª openid
, profile
, email
, offline_access
ã¯èš±å¯ã Mail.Read
ã®ããã«çµç¹ã®ããŒã¿ã«ã¢ã¯ã»ã¹ããæš©éã¯çŠæ¢ãããšãã£ãèšå®ãå¯èœã§ãã
æšå¥šèšå®ã§ã¯çºè¡è 確èªãè¡ãããŠããªããµãŒã ããŒãã£è£œã¢ããªããçºè¡è 確èªã¯è¡ãããŠãããã®ã®äœåœ±é¿ãšããŠåé¡ãããæš©é以äžã®ã¢ã¯ã»ã¹èš±å¯ãæ±ããã¢ããªã«å¯ŸããŠã¯ããŠãŒã¶ãŒåæãå¶éãããŸãã
[åæãšã¢ã¯ã»ã¹èš±å¯] ã®èšå®ã«ãããŠãŒã¶ãŒåæãå¶éãããå Žåãã¢ããªãå©çšããããã«ã¯ãåŸè¿°ã®æé ã§ç®¡çè ã«ããåæãè¡ãããšãæ€èšãã ããã
äžéšã®é«ãæš©éããã€ãŠãŒã¶ãŒå§ä»»ã®æš©éãã¢ããªãæ±ããŠããå Žåããããã¯ãã¢ããªã±ãŒã·ã§ã³æš©éãèŠæ±ããŠããå Žåã管çè ã«ããåæãå¿ èŠã§ããåŸè¿°ã®æé ã§ç®¡çè ã«ããåæãè¡ãããšãæ€èšãã ããã
ããŸãå€ããªããã¿ãŒã³ã§ã¯ãããŸããã察象ã®ã¢ããªã±ãŒã·ã§ã³ã§ãŠãŒã¶ãŒã®å²ãåœãŠãæå¹ã«ããŠããå ŽåããŠãŒã¶ãŒã«ããã¢ããªã®åæã¯è¡ããŸããããã®å Žåã管çè ããŠãŒã¶ãŒã«æ¿ããããããããã¢ããªã«åæãè¡ãå¿ èŠããããŸãã
ãŠãŒã¶ãŒã®å²ãåœãŠãå¿ èŠã§ããïŒ ã®èšå®ã [ã¯ã] ãšãªã£ãŠããã¢ããªãããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãèŠæ±ããŠããå Žåã¯ãåŸè¿°ã®æé ã§ç®¡çè ã«ããåæãè¡ãããšãæ€èšãã ããã
â£å¯Ÿè±¡ã®ã¢ããªãæ±ãã API ã®åæèŠæ±ããAzure AD ã«ããããªã¹ã¯ãé«ããšå€æãããå Žå
åæã®èŠæ±ãè¡ã£ãŠããã¢ããªããé床ã«å€ãã®æš©éãèŠæ±ããŠãããªã©ãçµç¹ã®ããŒã¿ãäžæ£ã«ååŸããããšããŠããæªè³ªãªã¢ããªã®å¯èœæ§ããããš Azure AD ãå€æããå ŽåããŠãŒã¶ãŒã«ããåæä»äžãç¡å¹åãã管çè ã®åæãèŠæ±ããå ŽåããããŸããrisk-based step-up consent æ©èœãšåŒã°ããæ¢å®ã§ ON ã«ãªã£ãŠããŸãã
ãŸãã2020 幎 11 æ以éã«æ°ããç»é²ãããçºè¡å ã確èªæžã¿ã§ãªãã»ãšãã©ã®ãã«ãããã³ã ã¢ããªããã® API ã®åæèŠæ±ããAzure AD ã«ãªã¹ã¯ãé«ããšå€æãããããã«ãªããŸããã åæç»é¢ã«ã¯ã以äžã®ããã«ãããã®ã¢ããªã«ã¯ãªã¹ã¯ã䌎ããæªç¢ºèªã®çºè¡å ããã®ãã®ã§ããããšããŠãŒã¶ãŒã«éç¥ããèŠåã衚瀺ãããŸãã
çºè¡å ãæªç¢ºèªã§ããã¢ããªãä¿¡é Œã§ããå ŽåãåŸè¿°ã®æé ã§ç®¡çè ã«ããåæãè¡ãããšãæ€èšãã ããã
äžæ¹ã§ãä»ããã³ãã®ãŠãŒã¶ãŒãå©çšãããã«ãããã³ã ã¢ããªã±ãŒã·ã§ã³ã®å ¬éãæ€èšããŠããå Žåãã¢ããªã±ãŒã·ã§ã³ãå®å¿ããŠå©çšããã ãããã«ãçºè¡è ã®ç¢ºèªãæ€èšãã ããã
管çè
ã«ããåæãå¿
èŠãªããã€ãã®ãã¿ãŒã³ã玹ä»ããŸããããå®éã«ã¢ããªãå©çšããããã«è¡ãã管çè
ã®åæä»äžæé ã¯ã©ã®ãã¿ãŒã³ã§ãåæ§ã§ãã
æé ã«ã€ããŠã¯åŸè¿°ããããŸããããŠãŒã¶ãŒããã®ç³è«ãããšã«åæãå®æœããã®ã¯å°ã
æéãããããŸãããç³è«ãããŒã®æŽåãªã©éçšé¢ã§ãã³ã¹ããããããŸãã
ããã§ãå
·äœçãªåæã®æé ã玹ä»ããåã«ããŠãŒã¶ãŒããã®æš©éç³è«ããã管çè
ãžã®éç¥ããããŠã¬ãã¥ãŒãšæ¿èªããã»ã¹ãæäŸãã管çè
ã®åæã¯ãŒã¯ãããŒ
æ©èœã玹ä»ããŸãã
管çè ã®åæã¯ãŒã¯ãããŒãå©çšããã°ããŠãŒã¶ãŒã管çè ã®åæãå¿ èŠãªã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ããéã«ã管çè ã«å¯Ÿãåæãè¡ããã "èŠæ±" ãããããšãå¯èœã«ãªããŸãã
åæèŠæ±æå¹åããã«ã¯ããšã³ã¿ãŒãã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ã® [åæãšã¢ã¯ã»ã¹èš±å¯ > 管çè ã®åæèšå® ããã[ãŠãŒã¶ãŒã¯ãèªåãåæã§ããªãã¢ããªã«å¯ŸããŠç®¡çè ã®åæãèŠæ±ã§ããŸã] ã®èšå®ã [ã¯ã] ã«èšå®ããŸãã
ãŸãã[管çè ã®åæèŠæ±ã確èªãããŠãŒã¶ãŒã®éžæ] ã§ãã¢ããªã±ãŒã·ã§ã³ç®¡çè ãã¯ã©ãŠã ã¢ããªã±ãŒã·ã§ã³ç®¡çè 以äžã®ãã£ã¬ã¯ã㪠ããŒã«ãæã€ãŠãŒã¶ãŒããåæèŠæ±ãåãåããŠãŒã¶ãŒãšããŠèšå®ããŸãã
管çè ã®åæèŠæ±æ©èœãæå¹åããç¶æ ã§ã管çè ã®åæãå¿ èŠãªã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ããå Žåã以äžã®ãããªç»é¢ã衚瀺ãããŸãã
æ¿èªèŠæ±ãã¯ãªãã¯ããããšã§ã管çè ã«ã¡ãŒã«éç¥ãéããã管çè ã¯ã¡ãŒã«ã®ãªã³ã¯ãã管çè ã®åæãè¡ããŸããæ°ããç³è«ããã»ã¹ãæå¹åããããšã§ããŠãŒã¶ãŒãå©çšãããã¢ããªã±ãŒã·ã§ã³ãã管çè ãææ¡ããåæãè¡ãå€æãåºæ¥ãŸãã
詳ããã¯ã管çè ã®åæã¯ãŒã¯ãããŒã®æ§æ - Azure Active Directory | Microsoft Docs ã確èªãã ããã
åæã®ã¯ãŒã¯ãããŒãå©çšããªãå Žåããããã¯ãããã¢ããªãå©çšããã«ã¯ã管çè èªèº«ã§åæãå®æœããå¿ èŠããããŸãã æé ãšããŠã¯ã以äžã® 3 ãã¿ãŒã³ããããŸãã®ã§é ã«èª¬æããŸãã
- ã¢ããªã±ãŒã·ã§ã³ã«ç®¡çãŠãŒã¶ãŒã§ã¢ã¯ã»ã¹ãè¡ããçµç¹ã®ä»£çãšããŠåæããã«ãã§ãã¯ããããŠåæãä»äžãã
- ãšã³ã¿ãŒãã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ã®ãAPI ã®ã¢ã¯ã»ã¹èš±å¯ããåæãä»äžãã
- åæãšã³ããã€ã³ããžã¢ã¯ã»ã¹ãè¡ããåæãä»äžãã
ãŸããã¢ããªã±ãŒã·ã§ã³ã«åæãè¡ãããŠãŒã¶ãŒã¯ãã¢ããªã±ãŒã·ã§ã³ç®¡çè ããããã¯ãã¯ã©ãŠã ã¢ããªã±ãŒã·ã§ã³ç®¡çè ã®ãã£ã¬ã¯ã㪠ããŒã«ãå¿ èŠã§ãããŸããMicrosoft Graph API ã®ã¢ããªã±ãŒã·ã§ã³æš©éã«å¯Ÿã管çè ã®åæãäžããã«ã¯ãã°ããŒãã«ç®¡çè ããŒã«ãå¿ èŠã§ãã
ãã¿ãŒã³ 1. ã¢ããªã±ãŒã·ã§ã³ã«ç®¡çãŠãŒã¶ãŒã§ã¢ã¯ã»ã¹ãè¡ããçµç¹ã®ä»£çãšããŠåæããã«ãã§ãã¯ããããŠåæãä»äžãã
- å©çšãããã¢ããªã±ãŒã·ã§ã³ã«ç®¡çè ãšããŠãµã€ã³ã€ã³ãè¡ããŸãã
- åæç»é¢ã«ãŠã[çµç¹ã®ä»£çãšããŠåæãã] ã®ãã§ãã¯ããã¯ã¹ããªã³ã«ããŠãæ¿è«ŸãéžæããŸãã
- ãã§ãã¯ãã€ãå¿ããŠæ¿è«Ÿããå Žåã«ã¯ãåŸè¿°ã®æé ã«ãŠ Azure ããŒã¿ã«ããåæã®ä»äžãè¡ããŸãã
ãã¿ãŒã³ 2. ãšã³ã¿ãŒãã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ã®ãAPI ã®ã¢ã¯ã»ã¹èš±å¯ããåæãä»äžãã
ãã§ã«ãã¢ããªã±ãŒã·ã§ã³ã Azure ããŒã¿ã«ã®ãšã³ã¿ãŒãã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ã«ç»é²ãããŠããå Žåã«å©çšã§ããæé ã§ãã é£æºã¢ããªã®æ§æã«ãã£ãŠã¯ãã¿ãŒã³ 2 ã§ã¯å¿ èŠãªæš©éã«åæã§ããªãå Žåããããããå¯èœã§ããã°ããŸãã¯ãã¿ãŒã³ 1 ã®æé ããè©Šããã ããã
- Azure ããŒã¿ã« (https://portal.azure.com/) ã«ã°ããŒãã«ç®¡çè ãšããŠãµã€ã³ã€ã³ããŸãã
- å·Šãã€ã³ãã Azure Active Directory ãéžæããŸãã
- ãšã³ã¿ããŒã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ãéžæããŸãã
- æ€çŽ¢ããã¯ã¹ã«åœè©²ã®ã¢ããªã±ãŒã·ã§ã³ ID ãããã¯ãã¢ããªã±ãŒã·ã§ã³åãå ¥åããåœè©²ã®ã¢ããªã±ãŒã·ã§ã³ãéžæããŸãã
- [ã¢ã¯ã»ã¹èš±å¯] ãéžæãã[âtenantåâ ã«ç®¡çè ã®åæãäžããŸã] ãã¿ã³ãã¯ãªãã¯ããŸãã
- åæç»é¢ã衚瀺ãããŸãã®ã§ã[æ¿è«Ÿ] ãã¯ãªãã¯ããŸãã
éåžžã¯äžè¿°ã® 2 ã€ã®æé ã«ãŠãã¢ããªã±ãŒã·ã§ã³ã«åæãè¡ãããšãå€ãã§ãããã¢ããªã±ãŒã·ã§ã³ã®æäŸå ã«ãã£ãŠã¯ãåæã®ãšã³ããã€ã³ããå©çšããäºåã«ç®¡çè ã«ããåæãè¡ãããæå®ãããŠãããã®ããããŸãã
åæã®ãšã³ããã€ã³ãã«ã€ããŠã詳ãã㯠Microsoft ID ãã©ãããã©ãŒã ã®ã¹ã³ãŒããã¢ã¯ã»ã¹èš±å¯ãããã³åæããã¥ã¡ã³ãå ã® ãã£ã¬ã¯ããªç®¡çè ã«ã¢ã¯ã»ã¹èš±å¯ãèŠæ±ãã ã確èªãã ããã
Important
管çè ã®åæãå®æœããã«ãé¢ããããã管çè ã®æ¿èªãå¿ èŠã§ããã®ç»é¢ã衚瀺ãããå Žåã®å¯ŸåŠæ¹æ³ã«ã€ããŠã¯é¢é£ããã°ã確èªããŠãã ããã
ã¢ããªã±ãŒã·ã§ã³ã«åæãè¡ããšãã¢ããªã¯ä»äžãããæš©éã®ç¯å²ã§ Azure AD ã§ä¿è·ããããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšãå¯èœã§ãã å®éã«ãã©ã®ãŠãŒã¶ãŒã (ãããã¯ç®¡çè ã) ã¢ããªã«åæãè¡ã£ãŠãããã¯ãAzure AD ã®ãšã³ã¿ãŒãã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ã察象ã®ã¢ããªãã確èªã§ããŸãã
- Azure ããŒã¿ã« (https://portal.azure.com/) ã«ã°ããŒãã«ç®¡çè ãšããŠãµã€ã³ã€ã³ããŸãã
- å·Šãã€ã³ãã Azure Active Directory ãéžæããŸãã
- ãšã³ã¿ãŒãã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ãéžæããŸãã
- æ€çŽ¢ããã¯ã¹ã«åœè©²ã®ã¢ããªã±ãŒã·ã§ã³ ID ãããã¯ãã¢ããªã±ãŒã·ã§ã³åãå ¥åããåœè©²ã®ã¢ããªã±ãŒã·ã§ã³ãéžæããŸãã
- [ã¢ã¯ã»ã¹èš±å¯] ãéžæããŸãã
ãŠãŒã¶ãŒå§ä»»ã®æš©éã¯ã[ãŠãŒã¶ãŒã®åæ] ã¿ããã確èªã§ããŸãã [èš±å¯å ] ãã¯ãªãã¯ããã ããšãããããã® API ã®èš±å¯ã«å¯Ÿããã©ã®ãŠãŒã¶ãŒãåææžã¿ã確èªã§ããŸãã
äžæ¹ã管çè ã®åæãå®äºããŠããå Žåã«ã¯ã[管çè ã®åæ] ã¿ãã«åææžã¿ã®æš©éäžèŠ§ã衚瀺ãããŸãã [çš®é¡] ã [Delegated] ãšãªã£ãŠãããã®ãããŠãŒã¶ãŒå§ä»»ã®æš©éãApplication ãšãªã£ãŠãããã®ãã¢ããªã±ãŒã·ã§ã³æš©éã® API ã®ã¢ã¯ã»ã¹èš±å¯ã§ãã
ã¢ããªã±ãŒã·ã§ã³ã«ä»äžãã API ã®æš©éãåãæ¶ãã«ã¯ããšã³ã¿ãŒãã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ããã¢ããªãåé€ããã ãããšãæå¹ã§ãã
- Azure ããŒã¿ã« (https://portal.azure.com/) ã«ã°ããŒãã«ç®¡çè ãšããŠãµã€ã³ã€ã³ããŸãã
- å·Šãã€ã³ãã Azure Active Directory ãéžæããŸãã
- ãšã³ã¿ãŒãã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ãéžæããŸãã
- æ€çŽ¢ããã¯ã¹ã«åœè©²ã®ã¢ããªã±ãŒã·ã§ã³ ID ãããã¯ãã¢ããªã±ãŒã·ã§ã³åãå ¥åããåœè©²ã®ã¢ããªã±ãŒã·ã§ã³ãéžæããŸãã
- [ããããã£] ãéžæããŸãã
- [åé€] ãéžæãã確èªç»é¢ã§ [ã¯ã] ãã¯ãªãã¯ãããšã³ã¿ãŒãã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ãåé€ããŸãã
ãšã³ã¿ãŒãã©ã€ãº ã¢ããªã±ãŒã·ã§ã³ãåé€ããããšã§ãã¢ããªã«ä»äžãããã¹ãŠã®æš©éãåé€ãããŸãããŸãã[ãŠãŒã¶ãŒã®ãµã€ã³ã€ã³ãæå¹ã«ãªã£ãŠããŸãã ?] ã®èšå®ã [ããã] ã«èšå®ããããšã§ãäžæçã«æš©éãç¡å¹ã«ããããšãå¯èœã§ãã
æåŸã«ãããã質åãšããã®åçã玹ä»ããŸãã
ãã§ã« 3rd ããŒãã£è£œã¢ããªãå©çšããŠããç°å¢ã§ããŠãŒã¶ãŒåæã®èšå®ãåŸãããªãã«ããŸãããçŸåšã¢ããªãå©çšããŠãããŠãŒã¶ãŒã¯ãåŒãç¶ãã¢ããªãå©çšã§ããŸããã
ã¯ãããŠãŒã¶ãŒåæã®èšå®ããªãã«é ããå Žåã§ãããã§ã«åææžã¿ã®æš©éã«ã€ããŠã¯ãåŒãç¶ãã¢ããªã±ãŒã·ã§ã³ã¯å©çšã§ããŸããåæã®èšå®ãå€æŽããåã«ã¢ããªã«äžåºŠãã¢ã¯ã»ã¹ããããšããªããŠãŒã¶ãŒã¯ã管çè ã®åæãå®äºãããŸã§ã¢ããªã«ã¢ã¯ã»ã¹ããããšã¯åºæ¥ãŸããã
ããã³ãã§åææžã¿ã® API ã®æš©éãšã¢ããªãäžèŠ§è¡šç€ºããããšã¯åºæ¥ãŸããã
Get-AzureADPSPermissions ãå®è¡ããããšã§ãããã³ãã§åææžã¿ã® API ã®æš©éãšã¢ããªãäžèŠ§è¡šç€ºããããšãå¯èœã§ãã