Monday, January 9, 2012

Microsoft’s Active Directory Security Feature

Active Directory helps to manage corporate identities, credentials, information protection, and system and application settings through different technologies. It is an adoption of the IEEE X.500. An enterprise-class directory service that is scalable, built from the ground using Internet-standard technologies, with fully integrated at the operating-system level. It can simplify administration and makes it easier for users to find resources. Microsoft’s Active Directory has a wide range of features and capabilities. Some of the features of Microsoft’s Active Directory is a centralized data storage, scalability, extensibility, manageability, security integration and signed and encrypted LDAP traffic.



Security Features of Microsoft’s Active Directory 
Authentication & Authorization  
Replication and trust monitoring

    Authentication & Authorization
    Active Directory supports multiple authentication protocols such as Kerberos V5 protocol, Secure Sockets Layer (SSL) v3, and Transport Layer Security (TLS) using X.509 v3 certificates, and security groups that span domains efficiently. These ensure that the clients are authorized and authenticated before allowing to access.

    Replication and trust monitoring
    Active Directory provides Windows Management Instrumentation (WMI) classes to monitor domain controllers are successfully replicating Active Directory information and that trusts are functioning properly. Since domain controllers control the keys to the Windows kingdom. Therefore, requires it to be more secure than other servers.

    Reference
    http://www.microsoft.com/en-us/server-cloud/windows-server/active-directory-overview.aspx
    http://microsoftguru.com.au/2011/05/28/microsoft-active-directory-best-practice/
    http://technet.microsoft.com/en-us/library/cc737139%28WS.10%29.aspx
    http://www.persiadeveloper.net/index.php/tutorials/windows-server/active-directory/47-active-directory-services-features.html

    4 comments:

    1. Hi Yian Hock, after reading your blog, I find that you have summarized the key points up and explained what Microsoft Active Directory is. The image that you have provided is very easy to understand, showing what Active Directory is all about. However, it would be good to actually have a video that explains about active directory as well. You could have also talked about the differences between LDAP, Active Directory and also X.500. Furthermore, you could actually bold out the key points out so that people will actually find it easier to read besides reading the whole paragraph.

      Derrick
      1004000D

      ReplyDelete
    2. Able to get a full view of what you are trying to explain. The information you have described and is very detailed and comprehensive. the key points are all there. Maybe you can give some examples on how these security features are been using in the real-world. hence, the image that you have provided is very easy to understand But, overall great!

      nadhirah mok
      1006230E

      ReplyDelete
    3. Hi Yian Hock, I just read your blog and I enjoyed reading your blog. I find that this blog you wrote makes it easier for me to understand Microsoft’s Active Directory better. You have clearly explained what Microsoft’s Active Directory is all about. The image you put also makes sense to what you are explaining. However, it will be great if you can add in more images for the rest of the security features so that your reader can understand for the remaining security features. The information about Microsoft’s Active Directory was well-researched. Your information length is just nice. It is not too wordy. Overall, it was good.

      ReplyDelete
    4. Hey there, what a well summarized points you got. It is a straight to the point post and i am able to understand it with your simple explanation. In addition, the reference contains more explanation but is quite long but thankfully you have made it simple and short. Overall, well done.

      ReplyDelete