Vdocuments - MX - Mcsa 70 412 Chapter 03
Vdocuments - MX - Mcsa 70 412 Chapter 03
Vdocuments - MX - Mcsa 70 412 Chapter 03
• Overview of DAC
• Implementing DAC Components
• Implementing DAC for Access Control
• Implementing Access Denied Assistance
• Implementing and Managing Work Folders
Lesson 1: Overview of DAC
Kerberos Ticket
Contoso\Alice
Receives a Kerberos ticket
User Groups:….
Claims:
Title=SDE
Kerberos and a New Token
User File
AD DS Server
Access Rule
Applies to: @File.Impact = High
Allow | Read, Write | if (@User.Department = @File.Department) AND
(@Device.Managed = True)
Creating and Managing Access Policies
• Resource property
definitions are defined in AD
DS
• Resource property
definitions can be used
during file classifications
Staging policy
Applies to: @File.Impact = High
Allow | Full Control | if (@User.Company=Contoso) AND
(@User.Clearance =High)
Sample Staging Event (4818)
Demonstration: Evaluating and Managing DAC
Access attempt:
• User is denied access, sees
troubleshooting text or device-state
troubleshooting
• User can request access via email
Logon Information
Virtual machines: 20412C-LON-DC1,
20412C-LON-SVR1,
20412C-LON-SVR2,
20412C-LON-CL1,
20412C-LON-CL2
User name: Adatum\Administrator
Password: Pa$$w0rd
Estimated Time: 110 minutes
Lab Scenario