Building Modern Active Directory: Engineering, Building, and Running Active Directory for the Next 25 Years

Smirnov, Evgenij

  • 出版商: Apress
  • 出版日期: 2024-12-12
  • 售價: $2,360
  • 貴賓價: 9.5$2,242
  • 語言: 英文
  • 頁數: 497
  • 裝訂: Quality Paper - also called trade paper
  • ISBN: 9798868809408
  • ISBN-13: 9798868809408
  • 尚未上市,無法訂購

相關主題

商品描述

Break the vicious circle of designs perpetuating the errors of the past and "just click next and accept the defaults" implementations preventing a secure and reliable future. This book looks at the typical patterns and antipatterns in Active Directory (AD) design, deployment, and operations and provides an approach to building and operating AD that is based on engineering (analyzing and fulfilling requirements) rather than design (formulating requirements).

The book starts with an historical overview of AD and its future 25 years later. You then learn about the challenges that organizations running AD are facing today followed by understanding how to avoid them while learning modern requirements for more efficient and effective AD performance. After that, you go through business requirements influencing the AD topology along with ways to engineer information lookup to protect high-value objects. The book looks at two main protocols and the many dialects that AD offers to engineer an authentication service that fulfills modern requirements while leaving insecure legacy configurations behind. Managing AD from both the security and usability perspectives is discussed next in the book. Building, operating, and transitioning to a modern AD is demonstrated in detail. The book guides you with the next steps of your journey to achieve a secure and reliable AD.

After reading this book, you will be able to bridge the gap between the two approaches by analyzing real-world business requirements, explaining the decision-making process in both design and engineering, and ultimately providing concrete engineering guidelines for typical implementation scenarios.

What Will You Learn

  • Build a modern Active Directory (AD), leaving behind design antipatterns that are not valid anymore
  • Build a "secure by design" AD and accommodate legacy technology without compromising the overall security
  • Understand advanced AD functionality such as controlling object visibility and partitioning Kerberos authentication by Authentication Policies
  • Operate a modern AD, react to changing business requirements, and respond to ever-evolving security threats

Who This Book Is For

Active Directory (AD) architects and consultants who need to provide design and engineering advice to customers; AD administrators tasked with modernizing and securing AD in their organizations; security architects wishing to learn the AD design patterns to watch out for

商品描述(中文翻譯)

打破設計延續過去錯誤的惡性循環,以及「只需點擊下一步並接受預設值」的實作,這些都阻礙了安全可靠的未來。本書探討了在 Active Directory (AD) 設計、部署和運營中的典型模式和反模式,並提供了一種基於工程(分析和滿足需求)而非設計(制定需求)的方法來構建和運營 AD。

本書首先回顧了 AD 的歷史及其未來 25 年後的展望。接著,您將了解當前運行 AD 的組織所面臨的挑戰,並學習如何避免這些挑戰,同時了解現代需求以提高 AD 的效率和效能。之後,您將探討影響 AD 拓撲的業務需求,以及如何設計信息查詢以保護高價值對象。本書還將介紹兩個主要協議及 AD 提供的多種方言,以設計滿足現代需求的身份驗證服務,同時拋棄不安全的舊配置。接下來,本書將討論從安全性和可用性兩個角度管理 AD 的方法。詳細展示了構建、運營和過渡到現代 AD 的過程。本書將指導您邁向實現安全可靠的 AD 的下一步。

閱讀完本書後,您將能夠通過分析現實世界的業務需求,解釋設計和工程中的決策過程,最終為典型實施場景提供具體的工程指導,彌合這兩種方法之間的差距。

您將學到什麼
- 構建一個現代的 Active Directory (AD),拋棄不再有效的設計反模式
- 構建一個「安全設計」的 AD,並在不妥協整體安全性的情況下兼容舊技術
- 理解高級 AD 功能,例如控制對象可見性和通過身份驗證政策對 Kerberos 身份驗證進行分區
- 運營一個現代 AD,對不斷變化的業務需求作出反應,並應對不斷演變的安全威脅

本書適合誰
Active Directory (AD) 架構師和顧問,需要向客戶提供設計和工程建議;負責現代化和保護其組織中 AD 的 AD 管理員;希望學習需要注意的 AD 設計模式的安全架構師。

作者簡介

Evgenij Smirnov has 30 years of experience in IT and IT security consulting. Besides directory services and groupware, he has been, and is still active in, the virtualization and platform management space. One of his greatest passions is PowerShell, where he is a regular community contributor and Microsoft Most Valuable Professional (MVP). After leaving consulting to assume a position with Semperis, again in the Active Directory space, he decided to share his AD-related experience, valued by so many customers over the years, and author this book. You can reach him via: @cj_berlin on Twitter and evgenijsmirnov on LinkedIn.

作者簡介(中文翻譯)

Evgenij Smirnov 擁有 30 年的 IT 及 IT 安全諮詢經驗。除了目錄服務和群件外,他在虛擬化和平台管理領域也一直活躍。PowerShell 是他最大的熱情之一,他是社群的定期貢獻者,也是微軟最有價值專家 (MVP)。在離開諮詢業務後,他加入 Semperis,繼續在 Active Directory 領域工作,並決定分享他多年來受到眾多客戶重視的 AD 相關經驗,撰寫這本書。您可以透過 Twitter 上的 @cj_berlin 和 LinkedIn 上的 evgenijsmirnov 與他聯繫。