Download presentation
Presentation is loading. Please wait.
Published byBetty Mitchell Modified over 9 years ago
1
FROM MIT KERBEROS TO MICROSOFT ACTIVE DIRECTORY The Pennsylvania State University’s move from a lower case MIT Kerberos realm to a Standard Microsoft Active Directory Deployment
2
OVERVIEW Current state MIT Kerberos “lower case realm name” passwords Open LDAP Central Domains: ACCESS domain “Windows 2008 R2” external one-way trust WIN domain “Windows 2008 R2” external one-way trust – Labs Only 60+ Other Windows domains Current design does not support Exchange Majority of 3 rd party Apps and Hardware authentication and authorization Local control of account live cycle
3
CAMPUS LOCATION MAP
4
BUSINESS REQUIREMENTS Replace MIT Kerberos as authentication store Central account and group provisioning Foundation for other services (eg: Exchange, Skype, Office 365) Improved PSU security posture Restricted administrative accounts Support of non MS clients and vended products POSIXs Attributes Custom Attributes
5
FUNDING FOR CHANGE The current state could not support newer services Security concerns of all Active Directory's - Security Need No central ability to monitor all Account provisioning stores Central Security office had no ability to monitor all Account stores Bleed over from silos did not buy us security Need ability to be more agile Premier Microsoft Contract
6
CHALLENGES Effort and resources Up front costs Team – 9 months to fully staff Initial design started in March Obstacles No migration funding currently for units No funding for auditing and logging Other enhancements Medical School <- Potential future challenge Currently separate Could potentially integrate at undetermined future date
7
TECHNICAL DESIGN Support 180,000 accounts and 2 million groups “CPR, OpenLdap, Grouper” Single Forest, Single Domain Design 2012 R2 Core 2012 R2 Forest Functional Level External DNS 6 Prod Domain Controllers - 64 Gig of RAM, 4 CPUs 4 hosted in VMWare central service 2 on dedicated hardware DNS Bluecat Address Manager, formerly known as Proteus Bluecat DNS/DHCP Server, formerly known as Adonis
8
NAMESPACE AND OU DESIGN Lessons learned from other domains Structure informed by location & Org Chart Minimal depth Facilitate delegated administration Reduced logon time Standard naming conventions Newcomer friendly Command-line friendly
9
OU DESIGN
10
SECURITY DESIGN Administrative Accounts Enterprise Admin, Domain Admin, Workstation Admin, Server Admin, OU Admin Can only create OU Containers and Computer Objects Self Service Portal Create GPOs Create Service Accounts Create Keytabs Central Authoritative source for accounts and groups Central Identity Service for Account information LDAP for additional attributes Grouper and LDAP for group based administration
11
SECURITY PRACTICES Protected privileged accounts LAPS “Local Administrative Password Solution” Secure Remote Desktop Service GPOs to control runas service, logon as network, logon on locally, remote desktop logon Protected Users group for Admin accounts Red Forest? Currently under investigation
12
RDS DESIGN PICTURE
13
WHAT DO YOU WANT TO KNOW? Questions?
14
LINKS http://identity.psu.edu http://identity.psu.edu http://identity.psu.edu/oneforest-project-plan/ Ignite Video on PtH https://channel9.msdn.com/Events/Ignite/2015/BRK2334 https://channel9.msdn.com/Events/Ignite/2015/BRK2334 https://www.nsa.gov/ia/_files/app/Reducing_the_Effectiveness_o f_Pass-the-Hash.pdf https://www.nsa.gov/ia/_files/app/Reducing_the_Effectiveness_o f_Pass-the-Hash.pdf
15
BACKUPS https://wikispaces.psu.edu/display/ONEForest/AD https://wikispaces.psu.edu/display/ONEForest/AD https://wikispaces.psu.edu/pages/viewpage.action?pageId=249 266211 https://wikispaces.psu.edu/pages/viewpage.action?pageId=249 266211 https://wikispaces.psu.edu/display/ONEForest/DNS+Options https://wikispaces.psu.edu/display/ONEForest/DNS+Options https://wikispaces.psu.edu/display/ONEForest/ONEForest+Project +Phases https://wikispaces.psu.edu/display/ONEForest/ONEForest+Project +Phases https://wikispaces.psu.edu/display/ONEForest/ONEForest+Project +Phases+-+Deliverables
16
CURRENT AUTHENTICATION DESIGN
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.