Website under construction


Figure 4-5: Long-term goal plan  The figure identifies the following areas:  1



Download 13,37 Mb.
Pdf ko'rish
bet110/131
Sana27.03.2022
Hajmi13,37 Mb.
#512480
1   ...   106   107   108   109   110   111   112   113   ...   131
Bog'liq
9780735697744 Introducing Windows Server 2016 pdf

Figure 4-5:
Long-term goal plan 
The figure identifies the following areas: 
1.
Modernize roles and the delegation model 
2.
Implement smart card or passport authentication for all administrators (
http://aka.ms/passport

3.
Create a specific administrator forest for Active Directory administrators (
http://aka.ms/ESAE

4.
Implement a code-integrity policy for domain controllers in Windows Server 2016 
5.
Implement shielded VMs for domain controllers in Windows Server 2016 and Hyper-V Fabric 
(
http://aka.ms/shieldedvms



123 
CHAPTER 4 | Security and identity 
Identity 
Now let’s take a look at some other elements that go hand-in-hand with security: the improvements 
within the identity stack in Windows Server 2016. 
Active Directory Domain Services 
Microsoft focused on three main areas for improvement in this release: 

Privileged access management 

Azure Active Directory Join 

Microsoft Passport 
Let’s dive into each of these topics a bit deeper to explain the exciting things being introduced into 
the platform. 
Privileged Access Management 
The world of cyber threats becomes more complicated every day, and because it is such an invisible 
threat in most cases, we need to apply security in layers on different levels to mitigate every feasible 
possibility. PAM was introduced to help mitigate common credential theft threats like pass-the-hash, 
spear phishing, and so on. PAM requires that you deploy Microsoft Identify Manager (MIM). 
More info For an introduction and deployment information about MIM, go to 
https://aka.ms/vaz62m

Most Active Directory environments would like to believe that they are completely clean of malicious 
activity, but the truth is that we can’t be 100 percent sure. For this reason, one of the first things PAM 
implements is a new bastion forest where it can guarantee that it is free from malicious activity. A 
special type of trust is established called a PAM Trust. This bastion forest is provisioned by MIM 
during the initial deployment. Figure 4-6 shows the basic concept of the new forest and the PAM trust 
established. 

Download 13,37 Mb.

Do'stlaringiz bilan baham:
1   ...   106   107   108   109   110   111   112   113   ...   131




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish