Dynamic Access Control the file server, reimagined Presented by Mark on twitter 1 contents copyright 2013 Mark Minasi.

Slides:



Advertisements
Similar presentations
1 Radio Maria World. 2 Postazioni Transmitter locations.
Advertisements

EcoTherm Plus WGB-K 20 E 4,5 – 20 kW.
Números.
Trend for Precision Soil Testing % Zone or Grid Samples Tested compared to Total Samples.
Trend for Precision Soil Testing % Zone or Grid Samples Tested compared to Total Samples.
AGVISE Laboratories %Zone or Grid Samples – Northwood laboratory
Trend for Precision Soil Testing % Zone or Grid Samples Tested compared to Total Samples.
SKELETAL QUIZ 3.
PDAs Accept Context-Free Languages
Reflection nurulquran.com.
EuroCondens SGB E.
Worksheets.
Slide 1Fig 26-CO, p.795. Slide 2Fig 26-1, p.796 Slide 3Fig 26-2, p.797.
Slide 1Fig 25-CO, p.762. Slide 2Fig 25-1, p.765 Slide 3Fig 25-2, p.765.
& dding ubtracting ractions.
Sequential Logic Design
Addition and Subtraction Equations
David Burdett May 11, 2004 Package Binding for WS CDL.
Western Public Lands Grazing: The Real Costs Explore, enjoy and protect the planet Forest Guardians Jonathan Proctor.
EQUS Conference - Brussels, June 16, 2011 Ambros Uchtenhagen, Michael Schaub Minimum Quality Standards in the field of Drug Demand Reduction Parallel Session.
Add Governors Discretionary (1G) Grants Chapter 6.
CALENDAR.
CHAPTER 18 The Ankle and Lower Leg
ASCII stands for American Standard Code for Information Interchange
The 5S numbers game..
突破信息检索壁垒 -SciFinder Scholar 介绍
A Fractional Order (Proportional and Derivative) Motion Controller Design for A Class of Second-order Systems Center for Self-Organizing Intelligent.
Numerical Analysis 1 EE, NCKU Tien-Hao Chang (Darby Chang)
Break Time Remaining 10:00.
The basics for simulations
PP Test Review Sections 6-1 to 6-6
MM4A6c: Apply the law of sines and the law of cosines.
Figure 3–1 Standard logic symbols for the inverter (ANSI/IEEE Std
Regression with Panel Data
TCCI Barometer March “Establishing a reliable tool for monitoring the financial, business and social activity in the Prefecture of Thessaloniki”
1 Prediction of electrical energy by photovoltaic devices in urban situations By. R.C. Ott July 2011.
TCCI Barometer March “Establishing a reliable tool for monitoring the financial, business and social activity in the Prefecture of Thessaloniki”
Copyright © 2012, Elsevier Inc. All rights Reserved. 1 Chapter 7 Modeling Structure with Blocks.
Copyright © [2002]. Roger L. Costello. All Rights Reserved. 1 XML Schemas Reference Manual Roger L. Costello XML Technologies Course.
Progressive Aerobic Cardiovascular Endurance Run
Biology 2 Plant Kingdom Identification Test Review.
MaK_Full ahead loaded 1 Alarm Page Directory (F11)
Facebook Pages 101: Your Organization’s Foothold on the Social Web A Volunteer Leader Webinar Sponsored by CACO December 1, 2010 Andrew Gossen, Senior.
TCCI Barometer September “Establishing a reliable tool for monitoring the financial, business and social activity in the Prefecture of Thessaloniki”
When you see… Find the zeros You think….
2011 WINNISQUAM COMMUNITY SURVEY YOUTH RISK BEHAVIOR GRADES 9-12 STUDENTS=1021.
Before Between After.
2011 FRANKLIN COMMUNITY SURVEY YOUTH RISK BEHAVIOR GRADES 9-12 STUDENTS=332.
2.10% more children born Die 0.2 years sooner Spend 95.53% less money on health care No class divide 60.84% less electricity 84.40% less oil.
Subtraction: Adding UP
Numeracy Resources for KS2
1 Non Deterministic Automata. 2 Alphabet = Nondeterministic Finite Accepter (NFA)
Static Equilibrium; Elasticity and Fracture
Converting a Fraction to %
Resistência dos Materiais, 5ª ed.
Clock will move after 1 minute
& dding ubtracting ractions.
Lial/Hungerford/Holcomb/Mullins: Mathematics with Applications 11e Finite Mathematics with Applications 11e Copyright ©2015 Pearson Education, Inc. All.
1.step PMIT start + initial project data input Concept Concept.
WARNING This CD is protected by Copyright Laws. FOR HOME USE ONLY. Unauthorised copying, adaptation, rental, lending, distribution, extraction, charging.
UNDERSTANDING THE ISSUES. 22 HILLSBOROUGH IS A REALLY BIG COUNTY.
A Data Warehouse Mining Tool Stephen Turner Chris Frala
1 Dr. Scott Schaefer Least Squares Curves, Rational Representations, Splines and Continuity.
1 Non Deterministic Automata. 2 Alphabet = Nondeterministic Finite Accepter (NFA)
Introduction Embedded Universal Tools and Online Features 2.
úkol = A 77 B 72 C 67 D = A 77 B 72 C 67 D 79.
Schutzvermerk nach DIN 34 beachten 05/04/15 Seite 1 Training EPAM and CANopen Basic Solution: Password * * Level 1 Level 2 * Level 3 Password2 IP-Adr.
Presentation transcript:

Dynamic Access Control the file server, reimagined Presented by Mark on twitter 1 contents copyright 2013 Mark Minasi. Please do not redistribute, and thanks for respecting my copyrights!

Dynamic Access Control 2

High-Level Benefits 3

4

Approach 5

DAC Examples 6

DAC Joins Share and NTFS Perms 7

DAC Appears in Two Places 8

DAC New Notions 9

New Concepts/Skills 10

New Concepts/Skills 11

"And's" in Permissions 12

Making "And" Work 13

Our Opening Situation 14

15 Click Add…

16 Now for the interesting part… click Add a condition

17 In "Add Items," choose the two groups (the UI's not good at showing this)

18 Choose the groups with this dialog box: And then the new permission will look like this: Click OK/Apply and …

New Permission 19

20 Click "Effective Access" to try it out

21 Note "include group membership" (what if-ing,) "select device"

Next, Consider Claims 22

Making an AD Attribute a Claim 23

Promoting AD Attribs to Claims 24

Example: Make "Office" a Claim Type 25

Giving “Office” a Suggested Value (1) 26

Giving “Office” a Suggested Value (2) 27

Giving “Office” a Suggested Value (3) 28

Giving “Office” a Suggested Value (4) 29

Using Claims 30

Creating a Claims-Based ACE 31

Using Claims 32

33 Here you see that now Effective Access lets me give Mark a claim for "what if-ing"

How Does the File Server Know? 34

One More Thing for Claims… 35

Seeing Claims and Setting Values 36 We haven’t enabled the Kerberos settings yet, so whoami can’t help Another example, now that we’ve got everything enabled…

37

Sidebar: You Might Not See Claims 38

Is Using Claims Secure? 39

Now Your Workstation Counts, Too 40

DAC Talk: Review 41

File Classification 42

How to Classify Files? 43

ADAC and DAC 44

Enabling an Existing Property 45

Choosing Two Built-in Properties 46

And Once You’ve Chosen Them… 47

Tell the File Server 48

Example ACE with Resources 49

How Do You Set a Property? 50

Classification UI 51 Right-click any NTFS folder or file and you'll see the new "Classification" tab

If You Classify a Folder… 52

Home-Grown Properties 53

54

Automatic Classification 55

Create the Rule (1) 56

Create the Rule (2) 57

Create the Rule (3) 58 “Content Classifier” means “match a given string or a regular expression” Click this to specify what to look for

Specifying Expression to Match 59

Re-Evaluation Rules 60

Apply the Rule 61 Run this and all of the frightening stuff is immediately marked

FSRM Classification Report 62

FSRM Classification Report 63

When You Run the Classifier… 64

Regular Expression Example 65

When Does it Happen? 66

Back to the Big Picture 67

Contrived but Complete Example 68

Central Access Rules and Policies 69

To Follow Along… 70

More Specific Task List 71

Central Access Rules and Policies 72

73

Where To Make the Conditions 74

Creating a Resource Condition 75

Creating a Resource Condition 76

The Resource Condition is Visible 77

Create the User Condition 78

This Part Should Look Familiar 79 As before, click "Add a condition"

As Should This One… 80

A CAR is Born 81

Next, Create the CA Policy 82

Making a CAP 83

Adding a CAR 84

The new CAP 85

Deploy/Publish the CAP 86

87

Installing the CAP in the GPO 88

Deploy the GPO 89

CAP Installed 90

Testing CAPs 91

92

Using the Staged Permissions 93

Sample

Thanks for Coming! 95