Chapter 5 - Implementing Dynamic Access Contro
Chapter 5 - Implementing Dynamic Access Contro
Chapter 5 - Implementing Dynamic Access Contro
Module 3
• Overview of DAC
• Implementing DAC Components
• Implementing DAC for Access Control
• Implementing Access Denied Assistance
• Implementing and Managing Work Folders
Lesson 1: Overview of DAC
Kerberos Ticket
Contoso\Alice
Receives a Kerberos ticket
User Groups:….
Claims:
Title=SDE
Kerberos and a New Token
User File
AD DS Server
Access Rule
Applies to: @File.Impact = High
Allow | Read, Write | if (@User.Department = @File.Department) AND
(@Device.Managed = True)
Creating and Managing Access Policies
Share
security descriptor
Share permissions
AD DS
(cached in local registry)
File/Folder
security descriptor Cached central access policy definition
Central access policy Cached central access rule
reference
Cached central access rule
NTFS file system
permissions Cached central access rule
Staging policy
Applies to: @File.Impact = High
Allow | Full Control | if (@User.Company=Contoso) AND
(@User.Clearance =High)
Sample Staging Event (4818)
Lesson 4: Implementing Access Denied
Assistance
• What Is Access Denied Assistance?
• Configuring Access Denied Assistance
• Demonstration: Implementing Access Denied Assistance
What Is Access Denied Assistance?