Infrastructure security Active Directory and beyond.

Similar documents
How to best protect Active Directory in your organization. Alistair Holmes. Senior Systems Consultant

ActiveRoles Server v 6.7

Installing, Configuring, and Managing a Microsoft Active Directory

Aurora Hosted Services Hosted AD, Identity Management & ADFS

Department of Information Technology Active Directory Audit Final Report. August promoting efficient & effective local government

Softerra Adaxes Enterprise Directory Solution

Active Directory Objectives

Configuring Managing and Maintaining Windows Server 2008 Servers (6419B)

6.7. Administrator Guide

Cayosoft Administrator. Modern Administration. Cayosoft.com. Unify, Simplify and Secure Microsoft Administration. Features at a Glance

6419: Configuring, Managing, and Maintaining Server 2008

Active Directory Manager Pro New Features

Configuring Windows Server 2008 Active Directory

ECAT SWE Exchange Customer Administration Tool Web Interface User Guide Version 6.7

Keeping Tabs on the Top 5 Critical Changes in Active Directory with Netwrix Auditor

ManageEngine ADManager Plus

Configuring, Managing and Maintaining Windows Server 2008 Servers

R4: Configuring Windows Server 2008 Active Directory

Quality Management Consultancy

M6419 Configuring, Managing and Maintaining Windows Server 2008 Servers

Course 6419A: Configuring, Managing and Maintaining Windows Server 2008 Servers

Configuring, Managing and Maintaining Windows Server 2008-based Servers

Windows Server. Introduction to Windows Server 2008 and Windows Server 2008 R2

Top 10 Security Hardening Settings for Windows Servers and Active Directory

MS 6419 Configuring, Managing and Maintaining Windows Server 2008-based Servers

Course 6419B: Configuring, Managing and Maintaining Windows Server 2008-based Servers

Configuring, Managing and Maintaining Windows Server 2008 Servers

Identity Management with midpoint. Radovan Semančík FOSDEM, January 2016

TestOut Course Outline for: Windows Server 2008 Active Directory

Z-Term V4 Administration Guide

Configuring, Managing and Maintaining Windows Server 2008 Servers

6.7. Access Templates Available out of the Box

With ADManager Plus, there are no extra installations required, and no OPEX, no dependencies on other software!

aaps algacom Account Provisioning System

Stellar Active Directory Manager

ADSelfService Plus Client Software Installation Guide

Outline SSS Configuring and Troubleshooting Windows Server 2008 Active Directory

Course Outline. Course 6419 : Configuring, Managing and Maintaining Windows Server 2008-based Servers. Duration: 5 Days

Quest Software Product Guide

Security and Rights Delegations for the Password Reset PRO Master Service Applies to software versions 2.x.x and 3.x.x

5 Challenges in Active Directory Management and How to Manage Them

MOC 6419: Configuring, Managing, and Maintaining Windows Server 2008

COMPLETE COMPUTING, INC.

ChangeAuditor 5.7. What s New

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Managing and Maintaining a Windows Server 2003 Network Environment

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

6.7. Quick Start Guide

Quest One Identity Solution. Simplifying Identity and Access Management

How to monitor AD security with MOM

ActiveRoles 6.9. Quick Start Guide

Course: Configuring and Troubleshooting Windows Server 2008 Active Direct-ory Domain Services

M6425a Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Active Directory Self-Service FAQ

Active Directory Self-Service Bundle

6425C - Windows Server 2008 R2 Active Directory Domain Services

Installing and Configuring Windows Server 2012

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

2010 Quest Software, Inc. ALL RIGHTS RESERVED. Trademarks. Third Party Contributions

HJ594S. Configuring, Managing and Mantaining Windows Server 2008 Servers (6419)

Configuring and Troubleshooting Windows 2008 Active Directory Domain Services

MS-6425C - Configuring Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Implementing HIPAA Compliance with ScriptLogic

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

ITCertMaster. Safe, simple and fast. 100% Pass guarantee! IT Certification Guaranteed, The Easy Way!

User Guide. Directory and Resource Administrator Exchange Administrator. Directory and Resource Administrator Exchange Administrator User Guide

Administering Windows Server 2012

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Reports, Features and benefits of ManageEngine ADAudit Plus

Microsoft. Official Course. Introduction to Active Directory Domain Services. Module 2

How To Configure An Active Directory Domain Services

Course 50382A: Implementing Forefront Identity Manager 2010 OVERVIEW

NE-6425C Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

MCTS: Active Directory (Server 2008)

Novell to Microsoft Conversion: Identity Management Design & Plan

10 Steps to Cleaning Up Active Directory User Accounts and Keeping Them That Way

JIJI AUDIT REPORTER FEATURES

Z-Hire V3 Administration Guide

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

How to Create a Delegated Administrator User Role / To create a Delegated Administrator user role Page 1

6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Lepide Active Directory Self Service. Configuration Guide. Follow the simple steps given in this document to start working with

PCI DSS Compliance: The Importance of Privileged Management. Marco Zhang

Symantec NetBackup Blueprints

DirX Identity V8.5. Secure and flexible Password Management. Technical Data Sheet

411-Administering Windows Server 2012

Reports, Features and benefits of ManageEngine ADAudit Plus

Course 6425C: Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Administering Windows Server 2012

AddLocalUser AddLocalGroup AddLocalUserToLocalGroup AddDomainUserToLocalGroup AddDomainGroupToLocalGroup

CL_50382 Implementing Forefront Identity Manager 2010

Outline SSS Microsoft Windows Server 2008 Hyper-V Virtualization

Transcription:

Infrastructure security Active Directory and beyond. Konstantin Shurunov DLP-2010 2009 2010 Quest Software, Inc. ALL RIGHTS RESERVED

Quest solutions & Financial industry. Financial organizations of all sizes use Quest solutions in their security and compliance strategies. 2

Advantages of Active Directory. AD is already there. AD is scalable. AD is reliable. AD is an extensible technology platform. AD already controls the access to a lot of resources. AD is used by all corporate users already. AD is already there. 3

ActiveRoles Server 4

ActiveRoles quick facts. Globally ActiveRoles is used to provision, manage and secure more than 25 million user accounts Deployments range in size from 500 to 800K+ users Product has been in existence since 2003 Features: Deep dive Active Directory Management Role based security Exchange Provisioning & Management Home folder provisioning IM & Mobile device provisioning Self-Service & Attestation Time based access assignments Integration with complimentary Quest AD management tools ADSI, PowerShell and Web services extensibility 5

Role Based Granular Delegation AD Architect Sr. Administrator Exchange Admins OU Admins / Help Desk End user Self-Service Application / Data Owners Day-to-Day Admin Create OUs Create Objects Join Computers Mailbox Admin Create/Remove Mailboxes Move Mailbox Update Addresses Service Desk Create Users/Groups Create Groups Reset Pwrds, Unlock Accounts Self-Service Update personal Information Request Access Update Phone # App/Data Owners Access Management Assign Assistants Attestation AD / AD LDS Computers Domain Controllers APAC EMEA North America New York Mexico City Cross-platform Applications Databases Directories Platforms Job Function Roles Access 6

Rule Based Data Integrity Business Rule Examples Generate Display Name Description cannot be left blank Phone number must contain 1- ### - ### - #### E-mail address = first letter of first name + last name@quest.com http://www.quest.com/people/ 7

AutoProvison Policies for AD & Beyond Location, Unique Logon Generation, Strong Password Generation, Remote Access Location, NTFS permissions, Share permissions Controlled Store Selection, Alias Generation Access Control / Email Distribution Lists Cross Platform for non AD Integrated Linux/Unix/Java Enabled Create Configure Centralized Provisioning Manual Other Identity Manager Managers, HR and Support Inform Affordable / Efficient / Error Free Completed in Minutes 8

AutoDeprovision Policies for AD & Beyond Disable Account, Set/Clear Attributes, Move to Recycle Bin and Schedule for Deletion in 60-90 Revoke Access, assign permissions to Managers/Admins Assign Self, Hide from GAL, permissions for Mgr/Admins Remove and Record Security and Distribution Group Memberships Initiate Cross Platform Deprovisioning Linux/Unix/Java Disable Lockdown Configure Deprovision ADLDS Manual Other Identity Manager Managers, HR and Support Inform Affordable / Efficient / Error Free Completed in Minutes 9

Workflow Policies Initiators Approval & Activities Configuration Users Multi-Level Approval Object Owners Managers Specific User Specific Group Graphical Workflow Designer Applications or Scripts PowerShell Extensibility Email Approve/Reject Email Notifications Web Based Approval Management Branching / Stopping Audit & Visibility Provides segregation of duties and tracking of request and responses to help with security and compliance 10

Authentication Services 11

InTrust + for AD: Audit and Protection 12

Defender: 2-Factor Authentication Full RADIUS Authentication Server AD-Integrated Token Agnostic 13

Recovery Manager for AD + Forest Edition 14

K.I.S.S. 15

Thank you! 2009 2010 Quest Software, Inc. ALL RIGHTS RESERVED