当前位置:网站首页>How can a cloud server safely use local AD/LDAP?
How can a cloud server safely use local AD/LDAP?
2022-08-03 20:14:00 【nington01】
The most comprehensive and effective way to address server access, privacy and security issues has been to use LDAP or Microsoft Active Directory (AD) as a central user directory within enterprise systems for storing user information.Based on this central user directory, some enterprises will also create a “bridge” to connect to the cloud infrastructure, opening up one or more different IaaS platforms (Infrastructure as a Service).
对于远程部署的服务器,企业需要知道哪些用户在访问哪些服务器。Therefore, in pursuit of efficiency, enterprises often adopt cloud-based user management services or identity directory-as-a-service (Directory-as-a-Service) platforms.A cloud user management service, or DaaS, synchronizes users with an internal LDAP or AD directory, enabling automatic user provisioning and management with the help of an identity bridging tool (a lightweight proxy service near AD) that is local to the customer.
What are the advantages of cloud directory services for administrators?
1. No network configuration required
Identity Bridge is a proxy service that securely feeds identity data from both LDAP and AD to DaaS, including all user identities, keeping data in sync without opening firewall ports or exposing corporate core directories to the public network.
2. Improve access security
With DaaS solutions, businesses can keep a central user directory secure, while ensuring that all user data is kept in sync, enabling tight control over server access.Unrelated accounts will not be provisioned or retained after the user is terminated.This is done primarily to ensure that only authorized users have access to internal systems, preventing user account theft, the primary risk for corporate directories.
3. 无需额外管理
除了自动同步用户信息外,DaaS 还会自动同步用户的安全组信息,大大减轻了 IT 管理员的运维负担。Administrators only need to create accounts and set privileged accounts, and then DaaS is responsible for securely copying all account information to all internal systems, applications, and networks, and setting correct access permissions for users.
Cloud-based directory services are the method modern enterprises use to manage and secure access to cloud server infrastructure and beyond.NingDS is a SaaS-based managed LDAP directory service platform, which implements the DaaS technology route, centralizes user management, and provides real single sign-on, WiFi authentication, and more.
If there is no correct method, the unified management of the directory users of the cloud server is a very difficult problem.However, through the identity bridging capabilities in the NingDS cloud identity directory, IT administrators can quickly enable cloud servers to use the enterprise's local AD or LDAP user store.
- LeetCode 1374. 生成每种字符都是奇数个的字符串
- glusterfs 搭建使用
- Detailed steps for tensorflow-gpu2.4.1 installation and configuration
- leetcode 2119. Numbers reversed twice
- 子树的大小
- Detailed AST abstract syntax tree
- Internet Download Manager简介及下载安装包,IDM序列号注册问题解决方法
- 汉源高科8光口12电口交换机千兆8光8电12电16电网管型工业以太网交换机
- Go语言为任意类型添加方法
- 机器学习中专业术语的个人理解与总结(纯小白)
小马智行起诉擎天智卡:索赔6000万 彭军称要斗争到底
Internet Download Manager简介及下载安装包,IDM序列号注册问题解决方法
Why BI software can't handle correlation analysis
RNA-ATTO 390|RNA-ATTO 425|RNA-ATTO 465|RNA-ATTO 488|RNA-ATTO 495|RNA-ATTO 520近红外荧光染料标记核糖核酸RNA
622 设计循环队列——Leetcode天天刷【循环队列,数组模拟,双指针】(2022.8.2)
- [email protected] 594/[email prote"/>
RNA核糖核酸修饰Alexa 568/[email protected] 594/[email prote
RNA核糖核酸修饰RNA-HiLyte FluorTM 405荧光染料|RNA-HiLyte FluorTM 405
利用 rpush 和 blpop 实现 Redis 消息队列
The sword refers to Offer II 044. The maximum value of each level of the binary tree-dfs method
Detailed steps for tensorflow-gpu2.4.1 installation and configuration
leetcode 231. 2 的幂
Detailed explanation of JWT
Solidity智能合约开发 — 4.1-合约创建和函数修饰器
Benchmarking Lane-changing Decision-making for Deep Reinforcement Learning
In-depth understanding of JVM-memory structure
百利药业IPO过会:扣非后年亏1.5亿 奥博资本是股东
从腾讯阿里等大厂出来创业搞 Web3、元宇宙的人在搞什么
JS 内置构造函数 扩展 prototype 继承 借用构造函数 组合式 原型式creat 寄生式 寄生组合式 call apply instanceof
PHP according to the longitude and latitude calculated distance two points
剑指 Offer II 044. 二叉树每层的最大值-dfs法
Edge box + time series database, technology selection behind Midea's digital platform iBuilding