Active Directoryã§èªåçã«ã¹ã¯ãªãããå®è¡ããåµããã€ã³ã
Windows Serverã®Active Directoryã«æŒãããã°ãªã³ã»ãã°ãªãã»ã¹ã¿ãŒãã¢ããã»ã·ã£ããããŠã³ã®ããããã®ã¹ã¯ãªãããèšå®ããªããã°ãªããªãã·ãŒã³ã«æŒããåµããã€ã³ããã¡ãã£ãšãŸãšããŠã¿ãŸãããèªåããŸããŸãšåµã£ãŠãå®è¡ãããªãã®ãªãã§ã ãããšãªã£ãéšåã«ã€ããŠã®åå¿é²ã§ãã
ç¹ã«æš©éåšããé©çšå¯Ÿè±¡ãééããŠãããã§ç¡é§ã«æéãæ¶è²»ããããšããªãããã«ã»ã»ã»
ã¹ã¯ãªããã®é çœ®å Žæ
æŠèŠ
BATãã¡ã€ã«ãPowershellãVBSãªã©æ§ã ãªã¹ã¯ãªãããå©çšããŠããã·ã³ã®èµ·åæãçµäºæã«å®è¡ããã¹ã¯ãªãããªã®ã§ããããã®ã¹ã¯ãªããã®é çœ®å Žæã¯ã©ãã§ãè¯ããšãããããããããŸãããADã®ãµãŒãäžã«é 眮ã¯ããã®ã§ãããããã¯ä»ã®ã¯ã©ã€ã¢ã³ããã·ã³ãããããã¯ãŒã¯è¶ ãã«èŠããå¿ èŠæ§ããããããäŸãã°å ±æãããŠããªããããªADã®ãã¹ã¯ãããã«ã¹ã¯ãªãããé 眮ããŠæå®ããŠãå®è¡ãããŸããã
åçµç¹éšéæ¯ã«çšæããã
ADãµãŒãã®ãã°ã«ãŒãããªã·ãŒã®ç®¡çãã«ãŠãADäžã®åçµç¹éšéã«ãªã³ã¯ãããã°ã«ãŒãããªã·ãŒãç·šéãããããªã®ã§ããããã®éã«ã¹ã¯ãªãããæå®ãããã€ã¢ãã°ã«æŒããŠãããã¡ã€ã«ã®è¡šç€ºãã§åºãŠãããã£ã¬ã¯ããªã¯ãããã¯ãŒã¯ã¢ãã¬ã¹ã«åºã¥ããURLãšãªã£ãŠããŸãïŒäŸïŒ\\hogehoge.com\test\policie\ã¿ãããªïŒãããã®åµããã€ã³ãã¯
- åOUäºäžã€ã¹ã¯ãªããã®ã¿ã€ãã«ãã£ãŠçšæãããŠããã©ã«ããç°ãªã
- è¿œå ãã¯ãªãã¯ããéã«åºãŠããã®ã¯ãã®çšæãããŠããã©ã«ããšãªã
- ãããã¯ãŒã¯ã¢ãã¬ã¹ã§ã®ã¢ã¯ã»ã¹ã§ã¯ãèªã¿åãå°çšããšãªã£ãŠãã®ã§ãã®ãŸãŸã ãšãã¡ã€ã«ãå ¥ããããªã
- ãã®ãã©ã«ãã¯ã¯ã©ã€ã¢ã³ãããã¯çŽæ¥çã«èŠããã®ã§ãå®è¡ããäºãå¯èœ
å®éã«ãã®ãã©ã«ãã«ã¹ã¯ãªãããé 眮ãããå Žåã®ããŒã«ã«ã®ãã¹ã¯
ãC:\Windows\SYSVOL\domain\Policies\{ããã«ã©ã³ãã ãªæ°å€}\Machine\Scripts\Shutdownããšãªã£ãŠããã®ã§ãããã¡ã€ã«ã®è¡šç€ºãã§åºãŠããã©ã³ãã æ°å€ä»¥äžã®éšåãã³ããŒããŠããC:\Windows\SYSVOL\domain\Policies\ãç¹ããå Žæãé 眮åºæ¥ããã¹ã«ãªããŸãã
å³ïŒã·ã£ããããŠã³ã¹ã¯ãªããã®ãã€ã¢ãã°
åçš®ã¹ã¯ãªããã«ã€ããŠ
ã°ã«ãŒãããªã·ãŒç®¡çã«ãŠãåOUã®ããªã·ãŒãç·šéãããããªã®ã§ãããæå³ãåããã觊ã£ãŠããšãåãããåããªãã£ããããŸãããªã·ãŒãšãã£ã¿ã§æ£ããèšå®ãããŠããŠããADåŽã§ãã¡ããšå¯Ÿè±¡ã®OUã«å¯ŸããŠãªããžã§ã¯ããé 眮ããŠããªããšãããããããªã·ãŒèªäœãé©çšãããªãã£ããã
ãŸããGPOã¯çµç¹éšéïŒOUïŒã«å¯ŸããŠãªã³ã¯ã¯åºæ¥ãŸãããã³ã³ããã«å¯ŸããŠã¯ãªã³ã¯ããäºãåºæ¥ãŸãããå¿ ãçµç¹éšéçãäœã£ãŠããããã«çŽä»ããå¿ èŠã«ãªããŸãã
å³ïŒèš4ã€ã®ç¹è²ã®ããã¹ã¯ãªãã
ãã°ãªã³ã»ãã°ãªãã¹ã¯ãªãã
ãã¡ã€ã³ã«å¯ŸããŠãã°ãªã³ããã°ãªãããéã«å®è¡ãããã¹ã¯ãªãããå®è¡æš©éã¯ãŠãŒã¶æš©éã«ãªããŸããäœãããŠãŒã¶ã管çè æš©éãæã£ãŠãããšããŠãã管çè æš©éãèŠæ±ããïŒã€ãŸããUACã«åŒã£ãããïŒãããªã¹ã¯ãªãããããã©ã«ããžã®æžã蟌ã¿ãå¿ èŠãªå Žåã«ãã®ã¹ã¯ãªããã§å®è¡ããŠãå®è¡ã倱æããŸãã
ãŸãããã®ã¹ã¯ãªããã«ã€ããŠã¯å¥ã®ã°ã«ãŒãããªã·ãŒã«æŒããŠé 延å®è¡ãåºæ¥ãããåæçã«å®è¡ãããšãã£ãããªã·ãŒãé åžããäºã§ããã°ãªã³ããããããªãå®è¡ã§ã¯ãªãïŒååŸã«å®è¡ããããããã°ãªã³ã¹ã¯ãªãããå®äºãããŸã§ãã¹ã¯ãããã®è¡šç€ºãåŸ ã£ãããšãã£ãããšãå¯èœã§ãããããã¯ãŒã¯ã«æ¥ç¶ããããŸã§åŸ æ©ãããããªããªã·ãŒãããã®ã§ããããã¯ãŒã¯ãã©ã€ããããŠã³ããããå¿ èŠã®ããã¹ã¯ãªããã®å Žåã¯ãåããæã§é©çšããå¿ èŠããããŸãã
ãŸããã®ããªã·ãŒã¯ããŠãŒã¶ã®æ§æãã«ããã®ã§ãæå®ã®OUã«æå±ããŠããŠãŒã¶ã¢ã«ãŠã³ãã«å¯ŸããŠæå¹åãããŸãïŒGPOããªã³ã¯ããªããŸãŸã§ãã£ãããç¡å¹åããŠããããå Žåã¯åããŸããïŒã
â»äœããã°ãªã³ã¹ã¯ãªããã®é 延å®è¡ãéåæå®è¡ã®ããªã·ãŒã¯ãŠãŒã¶ã®æ§æã§ã¯ãªãã³ã³ãã¥ãŒã¿ã®æ§æã®äžã«ããã®ã§ãæå®OUã«å¯ŸããŠäººã§ã¯ãªãã³ã³ãã¥ãŒã¿ãªããžã§ã¯ããæå±ãããªããšé©çšãããŸããã
å³ïŒãã°ãªã³ã¹ã¯ãªããã®é 延å®è¡ããªã·ãŒ
ã¹ã¿ãŒãã¢ããã¹ã¯ãªãã
ã¹ã¿ãŒãã¢ããã¹ã¯ãªããã¯ãã³ã³ãã¥ãŒã¿ã®æ§æãã®äžã«ããããªã·ãŒã§ãæå®ã®OUã«æå±ããŠãã³ã³ãã¥ãŒã¿ã«å¯ŸããŠæå¹åãããŸããæ ã«æå®OUã«ã³ã³ãã¥ãŒã¿ãªããžã§ã¯ãïŒéåžžã¯PCã®ã³ã³ãã¥ãŒã¿åã§èªåç»é²ãããŠãããºïŒããã¡ããšãã®OUã«ç§»åãããŠãããªããšé©çšãããŸããã人ã«å¯ŸããŠã§ã¯ãªãã®ã§èŠæ³šæã
ãã°ãªã³ã¹ã¯ãªãããšäŒŒãŠãããã§éãªãã®ã¯ã
- é 延å®è¡ããäºãã§ããŸããããŸããã®ãããªããªã·ãŒèšå®ããããŸãã
- å®è¡æš©éãSYSTEMãªã®ã§ã管çè æš©éãèŠæ±ãããããªEXEã®å®è¡ãããã©ã«ããžã®æžã蟌ã¿ãã¬ãžã¹ããªãžã®æžã蟌ã¿ã«ã€ããŠUACã«åŒã£ãããããšãªãå®è¡ãå¯èœã§ã
- ã¹ã¿ãŒãã¢ãããããšå³æå®è¡ãªã®ã§ãããŠã³ãã«æéã®æããPCçGoogle Driveã®ãã£ã¬ã¯ããªãªã©ã«å¯ŸããŠã¯ããŠã³ãããåã«ã¢ã¯ã»ã¹ãããŠããŸãå¯èœæ§ããããŸãã
ãšãªã£ãŠããŸãããã£ãŠMSI圢åŒã§ã¯ãªãEXE圢åŒã®ã¢ããªã®ãµã€ã¬ã³ãã€ã³ã¹ããŒã«ã§ãã£ãããæ¡ä»¶å€å®ãããŠã¬ãžã¹ããªã®å€ãå€æŽãããªã©ADã®ã¬ãžã¹ããªããªã·ãŒã§ã¯é£ããããšãããããããšãå¯èœã§ãããã ãNASãããŠã³ããããåã«å®è¡ãããŠããŸãå¯èœæ§ãããã®ã§ãéåžžã¯ãµã€ã¬ã³ãã€ã³ã¹ããŒã«ã«é¢ããŠã¯åŸè¿°ã®ã·ã£ããããŠã³ã¹ã¯ãªãããå©çšããŸãã
ã·ã£ããããŠã³ã¹ã¯ãªãã
MSI圢åŒã®ã€ã³ã¹ããŒã©ã®å ŽåãADã§ãµã€ã¬ã³ãã€ã³ã¹ããŒã«é åžãããããšãå¯èœã§ããããããEXE圢åŒã®å Žåã¯ãã®ãããªäºãåºæ¥ãŸããããµã€ã¬ã³ãã€ã³ã¹ããŒã«ããä»çµã¿ãåããŠãããšããŠãã§ãããããªéã«å©çšããã®ãã·ã£ããããŠã³ã¹ã¯ãªããããã¡ãããã³ã³ãã¥ãŒã¿ã®æ§æãã®äžã«ããããªã·ãŒã§ãããããæå®ã®OUã«æå±ããŠãã³ã³ãã¥ãŒã¿ã«å¯ŸããŠæå¹åãããŸããæ ã«æå®OUã«ã³ã³ãã¥ãŒã¿ãªããžã§ã¯ãïŒéåžžã¯PCã®ã³ã³ãã¥ãŒã¿åã§èªåç»é²ãããŠãããºïŒããã¡ããšãã®OUã«ç§»åãããŠãããªããšé©çšãããŸããã人ã«å¯ŸããŠã§ã¯ãªãã®ã§èŠæ³šæã
ãã°ãªãã¹ã¯ãªãããšäŒŒãŠéãªãç¹ã¯
- é 延å®è¡ããäºãã§ããŸããããŸããã®ãããªããªã·ãŒèšå®ããããŸãã
- å®è¡æš©éãSYSTEMãªã®ã§ã管çè æš©éãèŠæ±ãããããªEXEã®å®è¡ãããã©ã«ããžã®æžã蟌ã¿ãã¬ãžã¹ããªãžã®æžã蟌ã¿ã«ã€ããŠUACã«åŒã£ãããããšãªãå®è¡ãå¯èœã§ã
- é«éã¹ã¿ãŒãã¢ãããæå¹ãªå Žåãã·ã£ããããŠã³ãçºããããã€ãããŒã·ã§ã³ïŒäŒæ¢ç¶æ ïŒãšãªããããå®è¡ãããªã
BATãã¡ã€ã«ã§ç®¡çè æš©éã䜿ã£ãŠã®èªåå®è¡ãåºæ¥ãç¹ã¯ã¹ã¿ãŒãã¢ããã¹ã¯ãªãããšåãã§ãããã·ã£ããããŠã³ã®å Žåã¯NASãGoogle Driveã§ãããŠã³ããããŠãããºã®ç¶æ ã§äœ¿ããã®ã§ãäžè¬çã«EXEã®ãµã€ã¬ã³ãã€ã³ã¹ããŒã«ã§å©çšãããŸãã
äœããäžèšã«ããããã«é»æºãã©ã³ã®é«éã¹ã¿ãŒãã¢ãããæå¹ãªå Žåã«ã¯ãã·ã£ããããŠã³ãå®è¡ããŠãããã¯ã·ã£ããããŠã³ã§ã¯ãªãäŒæ¢ç¶æ ã«ãªãã ããªã®ã§ãåœç¶ã·ã£ããããŠã³ã¹ã¯ãªãããå®è¡ãããŸããããã£ãŠãåŸè¿°ã®ã¹ã¿ãŒãã¢ããã¹ã¯ãªããã䜵çšããŠãç¹å®ãã¡ã€ã«ã®æç¡ãå ã«é«éã¹ã¿ãŒãã¢ããããªãã«ããããã«ããŠäœ¿ãããããŠã¢ããªãã€ã³ã¹ããŒã«ãããããé«éã¹ã¿ãŒãã¢ããããªã³ã«æ»ããšããä»çµã¿ã«ããŠããŸãã
å³ïŒé«éã¹ã¿ãŒãã¢ããã®èšå®å Žæ
å³ïŒé«éã¹ã¿ãŒãã¢ããã®ã¬ãžã¹ããªã®å Žæ
é«éã¹ã¿ãŒãã¢ãããªã³ãªãã¹ã¯ãªãã
ã¹ã¿ãŒãã¢ããã¹ã¯ãªããããã³ã·ã£ããããŠã³ã¹ã¯ãªããã¯ãã¯ã©ã€ã¢ã³ããã·ã³ããé«éã¹ã¿ãŒãã¢ãããæå¹ããªå ŽåãçºåããŸãããã·ã£ããããŠã³ãå®è¡ããŠãããã¯ãã€ãããŒã·ã§ã³ãå®è¡ãããŠãã ãã§ã·ã£ããããŠã³ãšã¯ç°ãªãçºã§ããèªåã®å Žåã¯ã·ã£ããããŠã³ã¹ã¯ãªããã§å¿ èŠãªãé«éã¹ã¿ãŒãã¢ããã®ãªããã«ã€ããŠãã¢ããªãã€ã³ã¹ããŒã«æžã¿ãã©ãããèªåå€å®ããŠãªã³ãªãããçºã«å©çšããŠããŸãïŒç®¡çè æš©éãèŠæ±ããã¬ãžã¹ããªãèªã¿æžããããïŒã以äžã®ãããªBATãã¡ã€ã«ãå©çšããŠããŸãã
ãã®ã¹ã¯ãªãããã¹ã¿ãŒãã¢ããã¹ã¯ãªããã«ä»èŸŒãããšã§å€å®ãå®è¡ãããŠãªã³ãªããåæ ãããŸããã·ã¹ãã æš©éãå¿ èŠãªã®ã§ããã°ãªã³ã¹ã¯ãªããã§ã¯å®è¡ã§ããŸããã®ã§èŠæ³šæã
1 2 3 4 5 6 7 8 9 10 11 12 13 14 |
@echo off rem 確èªãããã¡ã€ã« set text=C:\Program Files\hogehoge\tomato.exe rem ãã¡ã€ã«ãååšããŠãããã€ã³ã¹ããŒã«æžã¿ãšå€æ if exist "%text%" ( echo "é«éã¹ã¿ãŒãã¢ãããªã³" reg add "HKLM\SYSTEM\ControlSet001\Control\Session Manager\Power" /f /v "HiberbootEnabled" /t REG_DWORD /d 1 exit /b ) else ( echo "é«éã¹ã¿ãŒãã¢ãããªã" reg add "HKLM\SYSTEM\ControlSet001\Control\Session Manager\Power" /f /v "HiberbootEnabled" /t REG_DWORD /d 0 exit /b ) |
ããªã·ãŒé©çšãšå®è¡ç¢ºèª
ãã¡ããšæå®ã®OUã«äººãã³ã³ãã¥ãŒã¿ãªããžã§ã¯ãã移åãããŠããã°ãåOUã«å¯ŸããŠé©çšããããªã·ãŒã¯ããã¡ã€ã³ã«ãã°ãªã³æã«é©çšãããŸãããŸããé©åãªã³ãŒããšæš©éãèæ ®ããã¹ã¯ãªããã§ãããªãã°ãããããã®å®è¡ã¿ã€ãã³ã°ã§ãã¡ããšå®è¡ããŠãããŸãïŒã·ã£ããããŠã³ã¹ã¯ãªããã ãã¯æ³šæãå¿ èŠã§ããïŒã
ãããVPNã§åšå® ã¯ãŒã¯ãšãã£ãå Žåã§ãVPNåç·åŽããADãèŠããªã人ã®å Žåã¯ããã®ããªã·ãŒã¯é©çšãããªãããšããããŸããADãèŠããŠããã®ã§ããã°
1 |
gpupdate /force |
ãšã³ãã³ããæãŠã°ãæåã§ããªã·ãŒãæŸã£ãŠããŠé©çšããããã«ãªããŸãããŸããçŸåšé©çšæžã¿ã®ã°ã«ãŒãããªã·ãŒããã³åè¿°ã§ã»ããããã¹ã¯ãªããã®å®è¡çµæã«ã€ããŠã¯
1 |
gpresult /v |
ãšã³ãã³ããæãŠã°ã確èªããããšãåºæ¥ãã¹ã¯ãªããã«ã€ããŠã¯æçµå®è¡ããã€ã§ãã£ãã®ãã確èªããããšãå¯èœã§ãïŒå®è¡ãããŠããªãå Žåã¯ããã®ã¹ã¯ãªããã¯ãŸã å®è¡ãããŠããŸãããšåºãŸãïŒã
å³ïŒã¹ã¯ãªããã®å®è¡çµæ確èª
å³ïŒããªã·ãŒé©çšç¶æ³ç¢ºèª
é¢é£ãªã³ã¯
- ActiveDirectoryã§GPOãé©çšãããªãæã«ç¢ºèªãããããš
- Windows Serverã®ãã°ãªã³ã¹ã¯ãªããã®å Žæãšèšå®
- ãã¡ã€ã«ãååšããŠããå Žåã«ã®ã¿ã³ãã³ããå®è¡ãã
- ã¬ãžã¹ããªã®å€æŽãã³ãã³ãã§å®è¡ããæ¹æ³
- ããããã¡ã€ã«ã§æ¡ä»¶åå²ã䜿ã
- ã³ãã³ãããã³ãã | å€æ°ã®å®£èšãšå€ãä»£å ¥ããæ¹æ³
- Windowsã®ã¹ã¿ãŒãã¢ããïŒã·ã£ããããŠã³ã¹ã¯ãªãããå®è¡ãããªã
- ãAD GPOããã°ãªã³ã»èµ·åã¹ã¯ãªããèšå®ãšåäœç¢ºèª