当前位置:网站首页>How can a cloud server safely use local AD/LDAP?
How can a cloud server safely use local AD/LDAP?
2022-08-03 20:14:00 【nington01】
The most comprehensive and effective way to address server access, privacy and security issues has been to use LDAP or Microsoft Active Directory (AD) as a central user directory within enterprise systems for storing user information.Based on this central user directory, some enterprises will also create a “bridge” to connect to the cloud infrastructure, opening up one or more different IaaS platforms (Infrastructure as a Service).
对于远程部署的服务器,企业需要知道哪些用户在访问哪些服务器。Therefore, in pursuit of efficiency, enterprises often adopt cloud-based user management services or identity directory-as-a-service (Directory-as-a-Service) platforms.A cloud user management service, or DaaS, synchronizes users with an internal LDAP or AD directory, enabling automatic user provisioning and management with the help of an identity bridging tool (a lightweight proxy service near AD) that is local to the customer.

What are the advantages of cloud directory services for administrators?
1. No network configuration required
Identity Bridge is a proxy service that securely feeds identity data from both LDAP and AD to DaaS, including all user identities, keeping data in sync without opening firewall ports or exposing corporate core directories to the public network.
2. Improve access security
With DaaS solutions, businesses can keep a central user directory secure, while ensuring that all user data is kept in sync, enabling tight control over server access.Unrelated accounts will not be provisioned or retained after the user is terminated.This is done primarily to ensure that only authorized users have access to internal systems, preventing user account theft, the primary risk for corporate directories.
3. 无需额外管理
除了自动同步用户信息外,DaaS 还会自动同步用户的安全组信息,大大减轻了 IT 管理员的运维负担。Administrators only need to create accounts and set privileged accounts, and then DaaS is responsible for securely copying all account information to all internal systems, applications, and networks, and setting correct access permissions for users.
Cloud-based directory services are the method modern enterprises use to manage and secure access to cloud server infrastructure and beyond.NingDS is a SaaS-based managed LDAP directory service platform, which implements the DaaS technology route, centralizes user management, and provides real single sign-on, WiFi authentication, and more.
If there is no correct method, the unified management of the directory users of the cloud server is a very difficult problem.However, through the identity bridging capabilities in the NingDS cloud identity directory, IT administrators can quickly enable cloud servers to use the enterprise's local AD or LDAP user store.
边栏推荐
- 李沐动手学深度学习V2-BERT微调和代码实现
- ES6 introduction and let, var, const
- 调用EasyCVR云台控制接口时,因网络延迟导致云台操作异常该如何解决?
- 转运RNA(tRNA)甲基化修饰7-甲基胞嘧啶(m7C)|tRNA-m7G
- 利用 rpush 和 blpop 实现 Redis 消息队列
- leetcode 326. Powers of 3
- 深入理解JVM-内存结构
- 【HiFlow】经常忘记签到怎么办?使用腾讯云场景连接器每天提醒你。
- 调用EasyCVR接口时视频流请求出现404,并报错SSL Error,是什么原因?
- matplotlib画polygon, circle
猜你喜欢

Internet Download Manager简介及下载安装包,IDM序列号注册问题解决方法

演讲议题及嘉宾重磅揭晓,TDengine 开发者大会推动数据技术“破局”

ThreadLocal详解

信使mRNA甲基化偶联3-甲基胞嘧啶(m3C)|mRNA-m3C

JMeter笔记5 |Badboy使用和录制

xss.haozi练习通关详解

Benchmarking Lane-changing Decision-making for Deep Reinforcement Learning

ARMuseum

Hinton2022年RobotBrains访谈记录

Detailed AST abstract syntax tree
随机推荐
Anaconda 虚拟环境迁移
async 和 await 原来这么简单
leetcode 1837. The sum of the digits in the K-base representation
charles配置客户端请求全部不走缓存
Edge box + time series database, technology selection behind Midea's digital platform iBuilding
单调栈及其应用
622 设计循环队列——Leetcode天天刷【循环队列,数组模拟,双指针】(2022.8.2)
使用 ReportLab 绘制 PDF
Mapper输出数据中文乱码
leetcode 16.01. Swap numbers (swap the values of 2 numbers without using temporary variables)
剑指 Offer II 044. 二叉树每层的最大值-dfs法
leetcode 072. Finding Square Roots
「学习笔记」高斯消元
8.2模拟赛总结
leetcode 2119. Numbers reversed twice
子结点的数量(2)
MapReduce介绍及执行过程
ES6 introduction and let, var, const
wordpress建立数据库连接时出错
Node version switching tool NVM and npm source manager nrm