28.09.2016 Views

Introducing

IntroducingWindowsServer2016_ebook

IntroducingWindowsServer2016_ebook

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

A REST Endpoint<br />

Windows PowerShell (using the New-PAMRequest cmdlet)<br />

These simple methods can be integrated into other tools like automation runbooks and ticketing<br />

systems to provide further control on the overall process.<br />

Earlier in this chapter, we mentioned the concepts and technology of JIT and JEA, PAM is a way of<br />

implementing this for your environment. Like JIT and JEA, PAM provides time-bound privileges to the<br />

request account and, of course, link it to the privileged group that has the necessary permissions to<br />

perform the task.<br />

You also can adjust the Kerberos ticket lifetime to ensure it has the lowest possible Time-to-Live (TTL)<br />

value. This way, if you sign in and receive a Kerberos ticket, its lifetime will be bound to the time<br />

remaining from the total amount of time PAM has granted you access to the privileged group.<br />

PAM also comes with a variety of new monitoring features to provide greater insight with respect to<br />

who requested access, what type of access was actually granted, and, more important, what activities<br />

that person performed during the privileged-access assignment.<br />

You can view this information MIM or in the Event Viewer, or if you already have System Center<br />

Operations Manager 2012 provisioned and use the Audit Collection Services, you can create<br />

visualizations of the information. Other third-party tools and Operations Management Suite (OMS)<br />

will be able to visualize the information in the future, as well.<br />

Azure Active Directory Join<br />

When enterprises begin to adopt the cloud and the work force becomes mobile, managing an estate<br />

that rarely touches the corporate network can become troublesome. There are a variety of other<br />

challenges that occur; for example, how do you give access to organizational resources on a<br />

noncorporate device. Whatever the challenge Azure Active Directory (Azure AD) Domain Join is<br />

another feature in Windows Server 2016 that will enhance the overall experience for identify and offer<br />

new capabilities for both corporate and personal devices alike. Figure 4-7 demonstrates the<br />

possibilities for Azure AD Join.<br />

124 CHAPTER 4 | Security and identity

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!