[{"data":1,"prerenderedAt":1732},["ShallowReactive",2],{"sc:header-data-ja":3,"sc:footer-data-ja":489,"author-ja-thorsten-kunzi-1f055f71c9741a":519,"content-ja-thorsten-kunzi":549,"content-events-ja-thorsten-kunzi":1720,"authors_data:Thorsten Kunzi|​Thorsten Kunzi​":1721},{"lang":4,"home":5,"navigation":17,"meta":479,"contact":485},"de",{"name":6,"folderSwitch":7,"imgLight":10,"img":11,"languages":12},"home",[8,9],"authors","blog","/logos/gk-Logo-sw.svg","/logos/gk-Logo-rgb.svg",{"ja":13},{"title":14,"url":15,"alt":16},"ホーム","/ja","glueckkanja Logo",[18,127,231,316,395,402],{"name":19,"languages":20,"children":24},"workplace",{"ja":21},{"title":22,"description":23},"Workplace","Microsoft 365を基盤に、スマートで安全な、柔軟性の高いワークプレイスを実現します。最新のテクノロジーとアイデンティティサービスが一つにつながります。",[25,55,91],{"name":26,"languages":27,"children":30},"portfolio",{"ja":28},{"title":29},"Portfolio",[31,37,43,49],{"name":32,"languages":33},"managed-intune",{"ja":34},{"title":35,"url":36},"Managed Intune","/ja/entra-intune/managed-intune",{"name":38,"languages":39},"managed-entra",{"ja":40},{"title":41,"url":42},"Managed Entra","/ja/entra-intune/managed-entra",{"name":44,"languages":45},"managed-workplace",{"ja":46},{"title":47,"url":48},"Managed Workplace","/ja/workplace/managed-workplace",{"name":50,"languages":51},"consulting-services",{"ja":52},{"title":53,"url":54},"Consulting Services","/ja/workplace/consulting-services",{"name":56,"languages":57,"children":60},"microsoft-365-endpoint",{"ja":58},{"title":59},"Microsoft 365 Endpoint",[61,67,73,79,85],{"name":62,"languages":63},"microsoft-entra-suite",{"ja":64},{"title":65,"url":66},"Microsoft Entra Suite","/ja/workplace/microsoft-entra-suite",{"name":68,"languages":69},"microsoft-intune",{"ja":70},{"title":71,"url":72},"Microsoft Intune","/ja/workplace/microsoft-intune",{"name":74,"languages":75},"microsoft-windows",{"ja":76},{"title":77,"url":78},"Microsoft Windows","/ja/workplace/microsoft-windows",{"name":80,"languages":81},"windows-365-cloud-pc",{"ja":82},{"title":83,"url":84},"Windows 365 Cloud PC","/ja/workplace/windows365-cloud-pc",{"name":86,"languages":87},"cloud-workplace-foundation",{"ja":88},{"title":89,"url":90},"Cloud Workplace Foundation","/ja/workplace/cloud-workplace-foundation",{"name":92,"languages":93,"children":96},"microsoft-365-collaboration",{"ja":94},{"title":95},"Microsoft 365 Collaboration",[97,103,109,115,121],{"name":98,"languages":99},"microsoft-copilot",{"ja":100},{"title":101,"url":102},"Microsoft 365 Copilot","/ja/workplace/microsoft-365-copilot",{"name":104,"languages":105},"microsoft-teams",{"ja":106},{"title":107,"url":108},"Teams","/ja/workplace/microsoft-teams",{"name":110,"languages":111},"sharepoint-powerplatform",{"ja":112},{"title":113,"url":114},"SharePoint & Power Platform","/ja/workplace/sharepoint-power-platform",{"name":116,"languages":117},"exchange-online",{"ja":118},{"title":119,"url":120},"Exchange Online","/ja/workplace/exchange-online",{"name":122,"languages":123},"information-protection-compliance",{"ja":124},{"title":125,"url":126},"Information Protection & Compliance","/ja/workplace/information-protection-compliance",{"name":128,"languages":129,"children":133},"azure",{"ja":130},{"title":131,"description":132},"Azure","Azureで成長を後押しします。IaaSとPaaSによって、クラウドのコストを下げ、効率を高め、イノベーションを進めます。",[134,151,181],{"name":135,"languages":136,"children":138},"azure-portfolio",{"ja":137},{"title":29},[139,145],{"name":140,"languages":141},"azure-managed-services",{"ja":142},{"title":143,"url":144},"Azure Managed Services","/ja/azure/azure-managed-services",{"name":146,"languages":147},"azure-consulting",{"ja":148},{"title":149,"url":150},"Azure Consulting","/ja/azure/azure-consulting",{"name":152,"languages":153,"children":156},"azure-scenarios",{"ja":154},{"title":155},"シナリオ",[157,163,169,175],{"name":158,"languages":159},"plan-your-cloud",{"ja":160},{"title":161,"url":162},"クラウドを計画する","/ja/azure/plan-your-cloud",{"name":164,"languages":165},"migrate-to-the-cloud",{"ja":166},{"title":167,"url":168},"クラウドへ移行する","/ja/azure/migrate-to-the-cloud",{"name":170,"languages":171},"innovate-your-business",{"ja":172},{"title":173,"url":174},"ビジネスを刷新する","/ja/azure/innovate-your-business",{"name":176,"languages":177},"vmware-exit",{"ja":178},{"title":179,"url":180},"VMware戦略を立て直す","/ja/azure/vmware-exit",{"name":182,"languages":183,"children":186},"azure-practices",{"ja":184},{"title":185},"Practices",[187,193,199,202,208,213,219,225],{"name":188,"languages":189},"azure-foundation",{"ja":190},{"title":191,"url":192},"Azure Foundation","/ja/azure/azure-foundation",{"name":194,"languages":195},"azure-ai-foundation",{"ja":196},{"title":197,"url":198},"Azure AI Foundation","/ja/azure/azure-ai-foundation",{"name":86,"languages":200},{"ja":201},{"title":89,"url":90},{"name":203,"languages":204},"azure-data-foundation",{"ja":205},{"title":206,"url":207},"Azure Data Foundation","/ja/azure/azure-data-foundation",{"name":188,"languages":209},{"ja":210},{"title":211,"url":212},"Azure Container Foundation","/ja/azure/azure-container-foundation",{"name":214,"languages":215},"dark-tenant",{"ja":216},{"title":217,"url":218},"Managed Dark Tenant","/ja/azure/managed-dark-tenant",{"name":220,"languages":221},"azure-cloud-adoption-framework",{"ja":222},{"title":223,"url":224},"Cloud Adoption Framework","/ja/azure/cloud-adoption-framework",{"name":226,"languages":227},"azure-cloud-competence-center",{"ja":228},{"title":229,"url":230},"Cloud Competence Center","/ja/azure/cloud-competence-center",{"name":232,"languages":233,"children":242},"security",{"ja":234},{"title":235,"description":236,"emergency":237},"Security","受賞歴のある24時間365日のManaged Service、インシデント対応、最新水準の保護で、クラウドの安全を見守り、インフラを守ります。",{"text":238,"href":239,"skin":240,"icon":241},"サイバー攻撃の渦中ですか？","/ja/security/are-you-under-attack","primary","emergency",[243,268,289],{"name":244,"children":245},"security-security-consulting",[246,252,256,262],{"name":247,"languages":248},"managed-red-tenant",{"ja":249},{"title":250,"url":251},"Managed Red Tenant","/ja/security/managed-red-tenant",{"name":214,"languages":253},{"ja":254},{"title":255,"url":218},"Dark Tenant",{"name":257,"languages":258},"sentinel-data-lake",{"ja":259},{"title":260,"url":261},"Sentinel Data Lake","/ja/security/sentinel-data-lake",{"name":263,"languages":264},"security-consulting",{"ja":265},{"title":266,"url":267},"Security Consulting","/ja/security/security-consulting",{"name":269,"children":270},"security-cloud-security-operations-center",[271,277,283],{"name":272,"languages":273},"cloud-security-operations-center",{"ja":274},{"title":275,"url":276},"Cloud Security Operations Center","/ja/security/cloud-security-operations-center",{"name":278,"languages":279},"global-secure-access",{"ja":280},{"title":281,"url":282},"Global Secure Access","/ja/security/global-secure-access",{"name":284,"languages":285},"my-work-id",{"ja":286},{"title":287,"url":288},"MyWorkID","/ja/security/my-work-id",{"name":290,"children":291},"security-preventive-services",[292,298,304,310],{"name":293,"languages":294},"preventive-services",{"ja":295},{"title":296,"url":297},"Preventive Services","/ja/security/preventive-services",{"name":299,"languages":300},"data-security-services",{"ja":301},{"title":302,"url":303},"Data Security Service","/ja/security/data-security-service",{"name":305,"languages":306},"security-copilot-agents",{"ja":307},{"title":308,"url":309},"Security Copilot Agents","/ja/security/security-copilot-agents",{"name":311,"languages":312},"nis2",{"ja":313},{"title":314,"url":315},"NIS2を技術で実装する","/ja/security/red-dark-tenant-nis2",{"name":317,"languages":318,"children":322},"products",{"ja":319},{"title":320,"description":321},"製品","完全に安全で100%クラウドネイティブなMicrosoft環境のためのCompanion製品です。協働、ネットワーク認証、ソフトウェア管理を強化します。",[323,360],{"name":324,"products":325,"children":326},"lorem ipsum 1",true,[327,336,344,352],{"name":328,"img":329,"target":330,"languages":331},"realmjoin","products/realmjoin/realmjoin-nav-logo.svg","_blank",{"ja":332},{"title":333,"url":334,"subtitle":335},"RealmJoin","https://www.realmjoin.com","クラウドベースのソフトウェア配布",{"name":337,"img":338,"target":330,"languages":339},"scepman","products/scepman/scepman-nav-logo.svg",{"ja":340},{"title":341,"url":342,"subtitle":343},"SCEPman","https://www.scepman.com","クラウドからの証明書配布",{"name":345,"img":346,"target":330,"languages":347},"konnekt","products/konnekt/konnekt-nav-logo.svg",{"ja":348},{"title":349,"url":350,"subtitle":351},"KONNEKT","https://www.konnekt.io","Office 365のデータをローカルで利用",{"name":353,"img":354,"target":330,"languages":355},"realmigrator","products/realmigrator/realmigrator-nav-logo.svg",{"ja":356},{"title":357,"url":358,"subtitle":359},"RealMigrator","https://www.realmigrator.com","サーバー間のデータ移行",{"name":361,"products":325,"children":362},"lorem ipsum 2",[363,371,379,387],{"name":364,"img":365,"target":330,"languages":366},"terraprovider","products/terraprovider/terraprovider-nav-logo.svg",{"ja":367},{"title":368,"url":369,"subtitle":370},"TerraProvider","https://www.terraprovider.com","Microsoft 365向けのTerraform Provider",{"name":372,"img":373,"target":330,"languages":374},"radiusaas","products/radius/radius-nav-logo.svg",{"ja":375},{"title":376,"url":377,"subtitle":378},"RADIUSaaS","https://www.radius-as-a-service.com","ネットワークの認証",{"name":380,"img":381,"target":330,"languages":382},"unifiedcontacts","products/unified-contacts/unifiedcontact-nav-logo.svg",{"ja":383},{"title":384,"url":385,"subtitle":386},"Unified Contacts","https://www.unified-contacts.com","Microsoft Teamsで連絡先を探す",{"name":388,"img":389,"target":330,"languages":390},"autopilotmonitor","products/autopilot-monitor/AutopilotMonitor-nav-logo.svg",{"ja":391},{"title":392,"url":393,"subtitle":394},"Autopilot Monitor","https://www.autopilotmonitor.com","Windows Autopilotのリアルタイム監視",{"name":396,"languages":397},"casestudies",{"ja":398},{"title":399,"url":400,"description":401},"導入事例","/ja/casestudies","当社はクラウドの先駆者として、包括的なクラウドソリューションを提供するMicrosoftのトップパートナーです。ブループリントに基づくアプローチとInfrastructure as Codeの知見が土台にあります。",{"name":403,"languages":404,"children":407},"company",{"ja":405},{"title":406,"description":401},"会社",[408,438,462],{"name":409,"languages":410,"children":413},"company-about-us",{"ja":411},{"title":412},"会社概要",[414,420,426,432],{"name":415,"languages":416},"company-facts-figures",{"ja":417},{"title":418,"url":419},"Facts & Figures","/ja/company/facts-and-figures",{"name":421,"languages":422},"company-contact",{"ja":423},{"title":424,"url":425},"お問い合わせと拠点","/ja/company/contact-and-locations",{"name":427,"languages":428},"switzerland",{"ja":429},{"title":430,"url":431},"スイスのglueckkanja","/ja/company/switzerland",{"name":433,"languages":434},"austria",{"ja":435},{"title":436,"url":437},"オーストリアのglueckkanja","/ja/company/austria",{"name":439,"languages":440,"children":443},"company-career",{"ja":441},{"title":442},"キャリア",[444,450,456],{"name":445,"languages":446},"company-career-overview",{"ja":447},{"title":448,"url":449},"採用情報","/ja/career",{"name":451,"languages":452},"company-young-professionals",{"ja":453},{"title":454,"url":455},"Young Professionals","/ja/young-professionals",{"name":457,"languages":458},"company-jobs",{"ja":459},{"title":460,"url":461},"募集職種","/ja/job-offers",{"name":463,"languages":464,"children":467},"company-latest",{"ja":465},{"title":466},"最新情報",[468,474],{"name":469,"languages":470},"company-blog",{"ja":471},{"title":472,"url":473},"ブログ","/ja/blog",{"name":469,"languages":475},{"ja":476},{"title":477,"url":478},"イベント","/ja/events",[480],{"name":481,"languages":482},"career-meta",{"ja":483},{"title":442,"url":449,"active":484},false,{"languages":486},{"ja":487},{"title":488,"url":425,"active":484},"お問い合わせ",{"data":490},{"bgColor":491,"number":492,"mail":493,"brandLogos":494,"logos":495,"links":499,"linksJa":509},"var(--color-gk-mid-blue)","+49 69 4005520","info@glueckkanja.com",null,[496],{"img":10,"alt":16,"url":497,"class":498},"index.html","max-w-19rem",[500,503,506],{"title":501,"url":502},"Datenschutz","/de/privacy",{"title":504,"url":505},"Impressum","/de/imprint",{"title":507,"url":508},"No Cookies","/de/cookies",[510,513,516],{"title":511,"url":512},"プライバシーポリシー","/ja/privacy",{"title":514,"url":515},"運営者情報","/ja/imprint",{"title":517,"url":518},"Cookieなし","/ja/cookies",{"id":520,"title":521,"body":522,"description":528,"extension":533,"meta":534,"name":521,"navigation":325,"otherLanguages":535,"path":545,"seo":546,"stem":547,"__hash__":548},"authors/thorsten-kunzi.md","Thorsten Kunzi",{"type":523,"value":524,"toc":529},"minimal",[525],[526,527,528],"p",{},"Als Consultant in den Bereichen Exchange Online, Identity und Modern Workplace unterstützt Thorsten Kunzi seit vielen Jahren Kunden bei der Planung und Umsetzung von Cloud-Projekten. Aufgrund seiner Erfahrung im Bereich der On-Premises Active Directory Security ist er auch im Hardening aktiv und hilft als Teil der APT Response Taskforce bei kompromittierten oder verschlüsselten Kundenumgebungen.",{"title":530,"searchDepth":531,"depth":531,"links":532},"",2,[],"md",{},{"en":536,"es":537,"sv":538,"fi":539,"da":540,"ko":541,"nl":542,"no":543,"ja":544},"As a consultant in the areas of Exchange Online, Identity and Modern Workplace, Thorsten Kunzi has been supporting customers in the planning and implementation of cloud projects for many years. Due to his experience in the area of on-premises Active Directory Security, he is also active in hardening and helps as part of the APT Response Taskforce with compromised or encrypted customer environments.","Como Consultant en las áreas de Exchange Online, Identity y Modern Workplace, Thorsten Kunzi lleva muchos años apoyando a los clientes en la planificación y ejecución de proyectos en la nube. Gracias a su experiencia en el ámbito de la seguridad de Active Directory on-premises, también trabaja en el hardening y ayuda, como parte de la APT Response Taskforce, en entornos de clientes comprometidos o cifrados.","Som Consultant inom områdena Exchange Online, Identity och Modern Workplace har Thorsten Kunzi i många år stöttat kunder i planeringen och genomförandet av molnprojekt. Tack vare sin erfarenhet inom on-premises Active Directory-säkerhet arbetar han även med hardening och hjälper som en del av APT Response Taskforce till i komprometterade eller krypterade kundmiljöer.","Consultantina Exchange Onlinen, Identityn ja Modern Workplacen alueilla Thorsten Kunzi on jo useiden vuosien ajan tukenut asiakkaita pilviprojektien suunnittelussa ja toteutuksessa. On-premises Active Directory -tietoturvan kokemuksensa ansiosta hän työskentelee myös hardeningin parissa ja auttaa osana APT Response Taskforce -tiimiä vaarantuneissa tai salatuissa asiakasympäristöissä.","Som Consultant inden for områderne Exchange Online, Identity og Modern Workplace har Thorsten Kunzi gennem mange år hjulpet kunder med planlægning og gennemførelse af cloud-projekter. På grund af sin erfaring inden for on-premises Active Directory-sikkerhed arbejder han også med hardening og hjælper som en del af APT Response Taskforce ved kompromitterede eller krypterede kundemiljøer.","Exchange Online, Identity, Modern Workplace 분야의 Consultant로서 Thorsten Kunzi는 오랜 기간 동안 고객의 클라우드 프로젝트 계획과 구현을 지원해 왔습니다. 온프레미스 Active Directory 보안 분야의 경험을 바탕으로 하드닝 작업에도 참여하고 있으며, APT Response Taskforce의 일원으로서 침해되거나 암호화된 고객 환경을 지원합니다.","Als Consultant voor Exchange Online, Identity en Modern Workplace ondersteunt Thorsten Kunzi klanten al vele jaren bij de planning en realisatie van cloudprojecten. Door zijn ervaring met On-Premises Active Directory Security is hij ook actief in hardening en helpt hij als onderdeel van de APT Response Taskforce bij gecompromitteerde of versleutelde klantomgevingen.","Som Consultant innen Exchange Online, Identity og Modern Workplace har Thorsten Kunzi i mange år bistått kunder med planlegging og gjennomføring av cloud-prosjekter. På grunn av erfaringen sin innen on-premises Active Directory Security er han også aktiv i hardening og hjelper som del av APT Response Taskforce ved kompromitterte eller krypterte kundemiljøer.","Exchange Online、Identity、Modern Workplaceの領域を担当するコンサルタントとして、Thorsten Kunziは長年にわたりクラウドプロジェクトの計画と実装でお客様を支援しています。オンプレミスのActive Directory Securityでの経験を活かしてHardeningにも携わり、APT Response Taskforceの一員として、侵害されたり暗号化されたりしたお客様環境に対応しています。","/thorsten-kunzi",{"title":521,"description":528},"thorsten-kunzi","YaiG705aTbfkaYxak0GKTbfT-5vntVpIpV6yaXJnw7I",[550,1124],{"id":551,"title":552,"author":553,"body":555,"cta":494,"description":530,"eventid":494,"extension":533,"hideInRecent":325,"layout":1097,"meta":1098,"moment":1102,"navigation":325,"path":1120,"seo":1121,"stem":1122,"tags":494,"webcast":484,"__hash__":1123},"content_ja/posts/2026-01-27-exchange-active-directory.md","​​​Exchange AD Split Permissionsを後悔なく導入する​",[554],"​Thorsten Kunzi​",{"type":523,"value":556,"toc":1079},[557,562,565,572,575,602,605,608,614,629,635,638,641,677,696,701,707,716,719,735,738,745,748,758,763,768,787,790,815,819,839,847,863,877,937,940,965,982,994,1007,1014,1018,1028,1039,1051,1054,1057,1060,1075],[558,559,561],"h3",{"id":560},"tldr欠点を取り除いたらどうなるか","TLDR：欠点を取り除いたらどうなるか",[526,563,564],{},"Exchangeのユーザー、グループ、連絡先などが置かれている場所で、ADとRBACのアクセス許可を再付与する方法を見つけました。この方法なら管理者にもID管理システムにも運用変更は不要です。私の経験では、その運用変更こそが多くの企業で導入を阻んでいた要因でした。それでいて、ラテラルムーブメントとドメイン侵害に対するセキュリティ上の利点はそのまま得られます。",[526,566,567],{},[568,569],"img",{"alt":570,"src":571},"Active Directory","https://res.cloudinary.com/c4a8/image/upload/v1770991330/blog/pics/Blog_-_Exchange_AD_Split_Permissions_-_1.png",[558,573,574],{"id":574},"実現は3つのステップです",[576,577,578,592,597],"ol",{},[579,580,581,588,589],"li",{},[582,583,587],"a",{"href":584,"rel":585},"https://learn.microsoft.com/en-us/exchange/permissions/split-permissions/configure-exchange-for-split-permissions#switch-to-active-directory-split-permissions",[586],"nofollow","AD split permission model","を実装する",[590,591],"br",{},[579,593,594,595],{},"失われたADのアクセス許可を、関連するOUに限定してExchangeサーバーに付与する",[590,596],{},[579,598,599,600],{},"使えなくなったPowerShellコマンドレットを再度有効にするため、Exchange RBACを付与する",[590,601],{},[526,603,604],{},"いずれもMicrosoftのガイダンス、AD ACL、またはExchange RBACの割り当てによって行います。",[558,606,607],{"id":607},"なぜ今これが重要なのか",[526,609,610,611,613],{},"Exchange 2010 SP1で導入されて以来、この仕組みはほとんど見過ごされるか無視されてきました。しかし既定の共有アクセス許可モデルは、Active Directoryを乗っ取られる大きなセキュリティリスクです。ここ数年Exchangeがリモートからの攻撃で悪名高いことと合わせると、いま手を打つべき時期です。",[590,612],{},"\n問題の出発点は、ドメインのルートに付与され、ドメイン全体へ継承されていく特権にあります。",[615,616,617,620,623,626],"ul",{},[579,618,619],{},"ユーザーとグループのアクセス許可の変更（実質的にフルアクセス）",[579,621,622],{},"グループメンバーの変更",[579,624,625],{},"ユーザーのパスワードリセット",[579,627,628],{},"ユーザーとグループの作成・削除",[526,630,631],{},[568,632],{"alt":633,"src":634},"アクセス許可","https://res.cloudinary.com/c4a8/image/upload/v1770991330/blog/pics/Blog_-_Exchange_AD_Split_Permissions_-_2.png",[526,636,637],{},"AdminSDHolderプロセス（属性admincount=1）で保護されるのは一部の高特権Tier0ユーザーとグループだけであり、多くの環境には保護されていないユーザーやグループが残ります。それらはドメインやフォレストの侵害につながるか、少なくとも深刻な影響を招く可能性があります。",[558,639,640],{"id":640},"代表的な例",[615,642,643,646,666],{},[579,644,645],{},"PWHashSyncを使用している場合のEntra Connect Syncアカウント",[579,647,648,649],{},"既定のグループ\n",[615,650,651,654,663],{},[579,652,653],{},"Allowed RODC Password Replication GroupとEntraConnectアカウントの組み合わせ（実際のWindows RODCが存在する場合）",[579,655,656,657,662],{},"さらに多くの経路を示す",[582,658,661],{"href":659,"rel":660},"https://specterops.io/blog/2025/06/25/untrustworthy-trust-builders-account-operators-replicating-trust-attack-aorta/",[586],"Untrustworthy Trust Builders: Account Operators Replicating Trust Attack (AORTA) - SpecterOps","も参照してください（Account Operatorsグループも同様の脅威です）",[579,664,665],{},"Protected Usersを空にして保護を外し、攻撃経路を作る手口",[579,667,668,669],{},"保護されていないカスタムグループや管理・サービスアカウント\n",[615,670,671,674],{},[579,672,673],{},"GPOへの書き込みアクセス許可（ドメインコントローラーに適用されるもの）",[579,675,676],{},"ADバックアップ、バックアップサーバー、PKIテンプレート、ハイパーバイザーなどへのアクセス管理",[526,678,679,680,682,683,688,690,691],{},"これら現在および将来の潜在的な経路をすべて後追いで封じ込めるのは非常に困難です。_ADMというカスタムOUであればACLの継承を無効化できますが、既定のオブジェクトの多くは既定のBuiltin OUやUsersコンテナーから移動できず、脆弱なまま残ります。",[590,681],{},"\nルートから強力なアクセス許可を取り除くほうがはるかに良く、それはActive Directory分割アクセス許可モデルを実装することで実現できます。",[582,684,687],{"href":685,"rel":686},"https://learn.microsoft.com/en-us/exchange/permissions/split-permissions/configure-exchange-for-split-permissions",[586],"Configure Exchange Server for split permissions | Microsoft Learn",[590,689],{},"\nMicrosoftも「…Active Directory分割アクセス許可の実装を推奨します」と述べています。",[582,692,695],{"href":693,"rel":694},"https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/active-directory-hardening-series---part-7-%E2%80%93-implementing-least-privilege/4366626",[586],"Active Directory Hardening Series - Part 7 – Implementing Least Privilege | Microsoft Community Hub",[697,698,700],"h2",{"id":699},"しかしなぜ誰もやらないのか","しかし、なぜ誰もやらないのか",[526,702,703,704,706],{},"分割アクセス許可はExchange 2010 SP1まで利用できず、その頃には誰もが既定の状態を受け入れていました。登場後もセキュリティチームは導入を押し通せなかったように見えます。",[590,705],{},"\nさらに、ADで先にユーザーや配布リストを作成し、その後でExchangeから「メール有効化」するなど、管理プロセスとIDMプロセスの変更を強いるものでもありました。",[526,708,709,710,712],{},"利用できなくなる、または動作しなくなるコマンドレット",[590,711],{},[713,714,715],"code",{},"Add-DistributionGroupMember, New-DistributionGroup, New-Mailbox, New-MailContact, New-MailUser, New-RemoteMailbox, Remove-DistributionGroup, Remove-DistributionGroupMember, Remove-Mailbox, Remove-MailContact, Remove-MailUser, Remove-RemoteMailbox, Update-DistributionGroupMember, Add-ADPermission, Remove-ADPermission ",[558,717,718],{"id":718},"運用変更の例",[615,720,721,732],{},[579,722,723,724],{},"New-Mailbox（ExchangeがADに書き込む）は次のようになります\n",[615,725,726,729],{},[579,727,728],{},"New-ADUser（adm.jdoeがADに書き込む）",[579,730,731],{},"Enable-Mailbox",[579,733,734],{},"SendAs権限のためのAdd-ADPermissionは、Active Directoryユーザーとコンピューターのセキュリティタブから行う必要があり、標準の管理者には追加のADアクセス許可が必要になることも多くなります。",[697,736,737],{"id":737},"後悔しない方法を紹介します",[526,739,740,744],{},[741,742,743],"strong",{},"免責事項","：以下のリンクと記事を最後まで読んで理解し、まずテスト環境で実施し、ADのバックアップが最新であることと復旧手順が確立されていることを必ず確認してください。",[558,746,747],{"id":747},"現在の利用状況を監査する",[526,749,750,753,755],{},[741,751,752],{},"まず、対象のコマンドレットのどれがどのOUで使われているかを確認してください。",[590,754],{},[713,756,757],{},"$CsvPath =\"C:\\temp\\SplitPermissionAdminAuditLog.csv\"",[526,759,760],{},[713,761,762],{},"$Cmdlets = \"Add-ADPermission\",\"Remove-ADPermission\",\"New-DistributionGroup\",\"Remove-DistributionGroup\",\"Add-DistributionGroupMember\",\"Update-DistributionGroupMember\",\"Remove-DistributionGroupMember\",\"New-Mailbox\",\"Remove-Mailbox\",\"New-RemoteMailbox\",\"Remove-RemoteMailbox\",\"New-MailUser\",\"Remove-MailUser\",\"New-MailContact\",\"Remove-MailContact\"",[526,764,765],{},[713,766,767],{},"Search-AdminAuditLog -ResultSize 99000 -Cmdlets $Cmdlets| select RunDate,Caller,ObjectModified,CmdletName,@{Name='CmdletParameters';Expression={[string]::join(\",\", ($_.CmdletParameters))}},succeeded,error | Export-Csv -Path $CsvPath -Delimiter \";\" -Encoding Unicode -NoTypeInformation",[526,769,770,773,775,778,781,784],{},[741,771,772],{},"呼び出し元とコマンドレットの簡易分析",[590,774],{},[713,776,777],{},"$CSVs=Import-Csv -Path $CsvPath -Delimiter \";\"",[713,779,780],{},"$CSVs|group Caller",[713,782,783],{},"$CSVs|group CmdletName",[713,785,786],{},"Analyze the CSV for where AD permissions will be needed. Potentially optimize by moving all Exchange relevant groups into dedicated OUs.",[558,788,789],{"id":789},"分割アクセス許可モデルを有効にする",[526,791,792,798,800,801,803,806,808,811,812],{},[741,793,794,797],{},[582,795,687],{"href":584,"rel":796},[586],"の「Switch to Active Directory split permissions」の手順に従ってください（RBAC分割アクセス許可ではありません）",[590,799],{},"\n実質的には、「Exchange Windows Permissions」グループの危険なアクセス許可が削除され、あわせてExchangeがそのグループのメンバーから外されます。",[590,802],{},[713,804,805],{},"Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataOFF /PrepareAD /ActiveDirectorySplitPermissions:true",[590,807],{},[741,809,810],{},"元に戻すには次を使用します","： ",[713,813,814],{},"/ActiveDirectorySplitPermissions:false",[558,816,818],{"id":817},"adのアクセス許可を付与する","ADのアクセス許可を付与する",[526,820,821,824,826,827,829,832,834,836],{},[741,822,823],{},"カスタムADグループを作成し、Exchangeサーバーをそのメンバーにします。",[590,825],{},"\n先にOUのパスを調整してください。",[590,828],{},[713,830,831],{},"New-ADGroup -Name \"AD_Custom Exchange Split permissions replacement\" -GroupCategory Security -GroupScope DomainLocal -Path \"OU=Rights,OU=Groups,OU=T1,OU=_ADM,$((Get-ADDomain).DistinguishedName)\" -Description \"replaces the permissions lost by split permissions on relevant OUs\"",[590,833],{},[590,835],{},[713,837,838],{},"Add-ADGroupMember \"AD_Custom Exchange Split permissions replacement\" -Members \"Exchange Trusted Subsystem\"",[526,840,841,844,846],{},[741,842,843],{},"グループ経由のアクセス許可を有効にするため、Exchangeサーバーを再起動してください",[590,845],{},"\nユースケースごとにADアクセス許可を簡単に委任できるスクリプトを作成しました。",[848,849,850],"blockquote",{},[526,851,852,858,859,862],{},[741,853,854],{},[855,856,857],"em",{},"INFO:"," これらのアクセス許可がないと、ExchangeサーバーはADから",[713,860,861],{},"“INSUFF_ACCESS_RIGHTS”","というエラーを受け取ります。",[526,864,865,874,876],{},[741,866,867,868,873],{},"glueckkanjaのGitHubから",[582,869,872],{"href":870,"rel":871},"https://github.com/glueckkanja/code-snippets/blob/main/ExchangeADSplitPermission/Add-ExchangeADSplitPermissionOnOU.ps1",[586],"Add-ExchangeADSplitPermissionOnOU.ps1","をダウンロードしてください",[590,875],{},"\n付与できるPermissionTypeは次のとおりです。",[615,878,879,892,912,925],{},[579,880,881,884],{},[741,882,883],{},"CreateUserAndContact",[615,885,886,889],{},[579,887,888],{},"ユーザーと連絡先に対するCreate/delete、ResetPassword、WriteAllProperties",[579,890,891],{},"Exchangeコマンドレット: New-Mailbox, New-RemoteMailbox, New-MailUser, New-MailContactと対応するRemove-*",[579,893,894,897],{},[741,895,896],{},"GroupManage",[615,898,899,902,905],{},[579,900,901],{},"グループの作成・削除、メンバーの変更",[579,903,904],{},"Exchangeコマンドレット: New-DistributionGroup, Remove-DistributionGroup, Add-DistributionGroupMember, Update-DistributionGroupMember, Remove-DistributionGroupMember",[579,906,907,908],{},"その他のユースケース: ユーザーが自分の所有するDistributionGroupをhttps://",[909,910,911],"on-prem-exchange",{},"/EAC経由で管理する",[579,913,914,917],{},[741,915,916],{},"UserSendAs",[615,918,919,922],{},[579,920,921],{},"ユーザーのADアクセス許可の変更",[579,923,924],{},"Exchangeコマンドレット: Add-ADPermission",[579,926,927,930],{},[741,928,929],{},"GroupSendAs",[615,931,932,935],{},[579,933,934],{},"グループのADアクセス許可の変更",[579,936,924],{},[558,938,939],{"id":939},"スクリプトの使い方",[526,941,942],{},[713,943,944,947,948,947,954,947,957,947,962],{},[713,945,946],{},"Add-ExchangeADSplitPermissionOnOU.ps1 -TargetOU"," ",[949,950,951],"b",{},[713,952,953],{},"\u003COU>",[713,955,956],{},"-PermissionType",[949,958,959],{},[713,960,961],{},"\u003CGroupManage|UserSendAs|GroupSendAs|CreateUserAndContact>",[713,963,964],{},"-Trustee \"AD_Custom Exchange Split permissions replacement",[526,966,967,968,970],{},"例",[590,969],{},[713,971,972,947,975,947,979],{},[713,973,974],{},"Add-ExchangeADSplitPermissionOnOU.ps1 -TargetOU \"OU=ExchangeGroups,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" -PermissionType",[949,976,977],{},[713,978,896],{},[713,980,981],{},"-Trustee \"AD_Custom Exchange Split permissions replacement\"",[526,983,984],{},[713,985,986,947,988,947,992],{},[713,987,974],{},[949,989,990],{},[713,991,929],{},[713,993,981],{},[526,995,996],{},[713,997,998,947,1001,947,1005],{},[713,999,1000],{},"Add-ExchangeADSplitPermissionOnOU.ps1 -TargetOU \"OU=Users,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" -PermissionType",[949,1002,1003],{},[713,1004,916],{},[713,1006,981],{},[526,1008,1009],{},[713,1010,1011],{},[713,1012,1013],{},"Add-ExchangeADSplitPermissionOnOU.ps1 -TargetOU \"OU=Users,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" -PermissionType CreateUserAndContact -Trustee \"AD_Custom Exchange Split permissions replacement\"",[558,1015,1017],{"id":1016},"exchange-rbacを付与する","Exchange RBACを付与する",[526,1019,1020,1023,1025],{},[741,1021,1022],{},"Add-DistributionGroupMemberとRemove-DistributionGroupMemberの各コマンドレットで-BypassSecurityGroupManagerCheckパラメーターを再度有効にします",[590,1024],{},[713,1026,1027],{},"New-RoleGroup -Name \"SplitPermission Security Group Creation and Membership\" -Roles \"Security Group Creation and Membership\" -Members \"Organization Management\",\"Recipient Management\" -Description \"Brings back -BypassSecurityGroupManagerCheck to Add-DistributionGroupMember, but also needs AD ACL for Exchange Server on target DLs\" ",[848,1029,1030],{},[526,1031,1032,947,1036,1038],{},[741,1033,1034],{},[855,1035,857],{},[590,1037],{},"これを行わないと \"-BypassSecurityGroupManagerCheck parameter is not available\" または \"You don't have sufficient permissions. This operation can only be performed by a manager of the group\" というエラーになります。",[526,1040,1041,1043,1046,1048],{},[590,1042],{},[741,1044,1045],{},"New-Mailbox、New-RemoteMailbox、New-MailContact、Remove-... の各コマンドレットを必要なパラメーター付きで再度有効にします",[590,1047],{},[713,1049,1050],{},"New-RoleGroup -Name \"SplitPermission Mail Recipient Creation\" -Roles \"Mail Recipient Creation\" -Members \"Organization Management\",\"Recipient Management\" -Description \"Brings back New-Mailbox, New-RemoteMailbox, New-MailUser, New-MailContact and matching Remove-... cmdlets, but additionally Exchange needs AD ACL for Exchange Server on target OUs\"",[697,1052,1053],{"id":1053},"まとめ",[526,1055,1056],{},"このガイドをきっかけに、Exchange経由のActive Directory侵害を防ぐというこの重要な一歩を踏み出す組織が増えることを願っています。Exchange AD分割アクセス許可モデルと本記事の運用方法をお客様の環境で実装してきましたが、これまで問題に遭遇したことはありません。",[526,1058,1059],{},"現在のオールオアナッシングの方式ではなく、OU単位できめ細かく制御できる仕組みをMicrosoftがネイティブに提供してくれれば、広く採用されるようになるはずです。",[526,1061,1062,1063,1068,1069,1074],{},"ADのTier分離は私が特に大切にしているテーマです。あわせてお願いしたいのは、Exchangeサーバーへドメイン管理者（あるいはTier0の）アカウントでログオンせず、今後はTier1として扱い、できるだけ早くADのTier分離を実装することです。\n最初の一歩としては、",[582,1064,1067],{"href":1065,"rel":1066},"https://www.pingcastle.com/",[586],"PingCastle","や",[582,1070,1073],{"href":1071,"rel":1072},"https://www.semperis.com/purple-knight/",[586],"Purple Knight","といったツールでADのセキュリティとコントロールパスを評価することをおすすめします。",[1076,1077,1078],"style",{},"\ncode {\n  font-size: inherit\n}\n",{"title":530,"searchDepth":531,"depth":531,"links":1080},[1081,1083,1084,1085,1086,1089,1096],{"id":560,"depth":1082,"text":561},3,{"id":574,"depth":1082,"text":574},{"id":607,"depth":1082,"text":607},{"id":640,"depth":1082,"text":640},{"id":699,"depth":531,"text":700,"children":1087},[1088],{"id":718,"depth":1082,"text":718},{"id":737,"depth":531,"text":737,"children":1090},[1091,1092,1093,1094,1095],{"id":747,"depth":1082,"text":747},{"id":789,"depth":1082,"text":789},{"id":817,"depth":1082,"text":818},{"id":939,"depth":1082,"text":939},{"id":1016,"depth":1082,"text":1017},{"id":1053,"depth":531,"text":1053},"post",{"lang":1099,"seoTitle":1100,"titleClass":1101,"date":1102,"blogtitlepic":1103,"socialimg":1104,"customExcerpt":1105,"keywords":1106,"scripts":1107,"asideNav":1108,"maxContent":325,"published":484},"ja","Exchange AD Split Permissions：最小権限でActive Directoryを守る","h2-font-size","2026-01-27","head-vulnerability-management","/blog/heads/head-vulnerability-management.jpg","メールボックスをすべてクラウドへ移行した組織でも、オンプレミスのExchange Serverは依然として広く残っています。しかもExchangeはActive Directory内で非常に強い権限を持ち続けるため、多くの場合、AD全体、ひいては企業ITの大半を掌握できる強力な攻撃経路が存在します。いわゆる「AD Split Permissions」へ切り替えればこの致命的なアクセス許可は取り除かれます。そして私は、これまで導入を阻んできた欠点を解消するソリューションを設計しました。","Exchange Server, Active Directory, AD分割アクセス許可, RBAC, Exchangeアクセス許可, AdminSDHolder, 最小権限, AD ACL, PowerShell",{"slick":325,"form":325},{"menuItems":1109},[1110,1112,1114,1116,1118],{"href":1111,"text":561},"#tldr欠点を取り除いたらどうなるか",{"href":1113,"text":607},"#なぜ今これが重要なのか",{"href":1115,"text":700},"#しかしなぜ誰もやらないのか",{"href":1117,"text":737},"#後悔しない方法を紹介します",{"href":1119,"text":1053},"#まとめ","/posts/2026-01-27-exchange-active-directory",{"title":552,"description":530},"posts/2026-01-27-exchange-active-directory","bW6RfFCITt4u5b5WOaqXY06kmEW00z2XmAICrlP5mBk",{"id":1125,"title":1126,"author":1127,"body":1128,"cta":494,"description":530,"eventid":494,"extension":533,"hideInRecent":484,"layout":1097,"meta":1703,"moment":1704,"navigation":325,"path":1716,"seo":1717,"stem":1718,"tags":494,"webcast":484,"__hash__":1719},"content_ja/posts/2026-03-01-exchange-ad-split-permissions-hardening.md","Exchange AD Split Permissionsを後悔なく導入する",[521],{"type":523,"value":1129,"toc":1690},[1130,1132,1135,1139,1144,1156,1158,1165,1170,1172,1178,1188,1192,1195,1199,1229,1245,1247,1253,1261,1265,1278,1280,1284,1286,1290,1350,1354,1391,1394,1396,1406,1409,1425,1435,1437,1439,1485,1488,1495,1500,1503,1516,1531,1542,1552,1556,1614,1616,1620,1640,1647,1670,1672,1675,1678,1688],[697,1131,561],{"id":560},[526,1133,1134],{},"Exchangeのユーザー、グループ、連絡先が置かれている場所で、ADとRBACのアクセス許可を直接再付与する方法を見つけました。管理者にもID管理システムにも変更は不要です。私の経験では、この摩擦こそが多くの企業にとって最大の障害でした。それでいて、ラテラルムーブメントとドメイン侵害に対するセキュリティ上の利点はそのまま残ります。",[526,1136,1137],{},[568,1138],{"alt":570,"src":571},[526,1140,1141],{},[741,1142,1143],{},"実現は3つのステップです。",[576,1145,1147,1152,1154],{"style":1146},"margin: 0.25rem 0",[579,1148,1149,588],{},[582,1150,1151],{"href":584},"AD分割アクセス許可モデル",[579,1153,594],{},[579,1155,599],{},[526,1157,604],{},[1159,1160],"video-frame",{"thumb":1161,"alt":1162,"id":1163,":full-width":1164},"/thumbs/thumb-exchange-ad-split-permissions-webcast.jpg","発表者がノートパソコンの前に座り、glueckkanjaの「Step 1: Active Directory Permissions」と題されたスライドを解説しています。スライドではMicrosoft Exchange AD Split Permissionsの実装方法として、委任グループを作成するPowerShellコマンド（New-ADGroup、Add-ADGroupMember）と、スクリプトAdd-ExchangeADSplitPermissionOnOU.ps1によるアクセス許可の適用が示されています。","soNZkNRopSQ","true",[1166,1167,1169],"div",{"style":1168},"background:var(--color-gk-light-grey); margin-top:0.5rem; padding:0.5rem 1rem; font-size:0.85rem; color:var(--color-gk-dark-blue)","ウェビナー：Exchange AD Split Permissions without regrets. 手順を追った実装ガイド",[697,1171,607],{"id":607},[526,1173,610,1174,1176,613],{},[590,1175],{},[590,1177],{},[615,1179,1180,1182,1184,1186],{"style":1146},[579,1181,619],{},[579,1183,622],{},[579,1185,625],{},[579,1187,628],{},[526,1189,1190],{},[568,1191],{"alt":633,"src":634},[526,1193,1194],{},"AdminSDHolderプロセス（属性admincount=1）で保護されるのは一部の高特権Tier 0ユーザーとグループだけであり、多くの環境には保護されていないユーザーやグループが残ります。それらはドメインやフォレストの侵害につながるか、少なくとも深刻な影響を招く可能性があります。",[526,1196,1197],{},[741,1198,640],{},[615,1200,1201,1204,1220],{"style":1146},[579,1202,1203],{},"Password Hash Syncを使用している場合のEntra Connect Syncアカウント",[579,1205,1206,1207],{},"既定のグループ",[615,1208,1210,1213,1218],{"style":1209},"margin: 0",[579,1211,1212],{},"Allowed RODC Password Replication GroupとEntra Connectアカウントの組み合わせ（実際のWindows RODCが存在する場合）",[579,1214,656,1215,662],{},[582,1216,661],{"href":1217,"target":330},"https://specterops.io/blog/2025/06/25/untrustworthy-trust-builders-account-operators-replicating-trust-attack-aorta",[579,1219,665],{},[579,1221,1222,1223],{},"保護されていないカスタムグループや管理・サービスアカウント",[615,1224,1225,1227],{"style":1209},[579,1226,673],{},[579,1228,676],{},[526,1230,679,1231,1233,682,1235,1238,1240,690,1242],{},[590,1232],{},[590,1234],{},[582,1236,687],{"href":685,"rel":1237},[586],[590,1239],{},[590,1241],{},[582,1243,695],{"href":693,"rel":1244},[586],[697,1246,700],{"id":699},[526,1248,703,1249,1251,706],{},[590,1250],{},[590,1252],{},[848,1254,1255],{},[526,1256,1257,1260],{},[741,1258,1259],{},"Info:"," 次のコマンドレットは利用できなくなるか、動作しなくなります。Add-DistributionGroupMember, New-DistributionGroup, New-Mailbox, New-MailContact, New-MailUser, New-RemoteMailbox, Remove-DistributionGroup, Remove-DistributionGroupMember, Remove-Mailbox, Remove-MailContact, Remove-MailUser, Remove-RemoteMailbox, Update-DistributionGroupMember, Add-ADPermission, Remove-ADPermission",[526,1262,1263],{},[741,1264,718],{},[615,1266,1267,1276],{"style":1146},[579,1268,1269,1270],{},"New-Mailbox（ExchangeがADに書き込む）は次のようになります",[615,1271,1272,1274],{"style":1209},[579,1273,728],{},[579,1275,731],{},[579,1277,734],{},[697,1279,737],{"id":737},[526,1281,1282,744],{},[741,1283,743],{},[558,1285,747],{"id":747},[526,1287,1288],{},[741,1289,752],{},[1291,1292,1293,1301,1303,1309,1311],"code-block",{},[1294,1295,1296,1300],"span",{},[1294,1297,1299],{"style":1298},"color:var(--color-gk-orange)","$CsvPath"," = \"C:\\temp\\SplitPermissionAdminAuditLog.csv\"",[590,1302],{},[1294,1304,1305,1308],{},[1294,1306,1307],{"style":1298},"$Cmdlets"," = \"Add-ADPermission\",\"Remove-ADPermission\",\"New-DistributionGroup\",\"Remove-DistributionGroup\",\"Add-DistributionGroupMember\",\"Update-DistributionGroupMember\",\"Remove-DistributionGroupMember\",\"New-Mailbox\",\"Remove-Mailbox\",\"New-RemoteMailbox\",\"Remove-RemoteMailbox\",\"New-MailUser\",\"Remove-MailUser\",\"New-MailContact\",\"Remove-MailContact\"",[590,1310],{},[1294,1312,1313,947,1316,1320,1321,947,1324,1326,1327,1330,1331,947,1334,947,1337,947,1339,1342,1343,1346,1347],{},[1294,1314,1315],{"style":1298},"Search-AdminAuditLog",[1294,1317,1319],{"style":1318},"color:var(--color-gk-mid-blue)","-ResultSize"," 99000 ",[1294,1322,1323],{"style":1318},"-Cmdlets",[1294,1325,1307],{"style":1298}," | ",[1294,1328,1329],{"style":1298},"Select-Object"," RunDate,Caller,ObjectModified,CmdletName,@{Name='CmdletParameters';Expression={[string]::join(\",\", ($\\_.CmdletParameters))}},succeeded,error | ",[1294,1332,1333],{"style":1298},"Export-Csv",[1294,1335,1336],{"style":1318},"-Path",[1294,1338,1299],{"style":1298},[1294,1340,1341],{"style":1318},"-Delimiter"," \";\" ",[1294,1344,1345],{"style":1318},"-Encoding"," Unicode ",[1294,1348,1349],{"style":1318},"-NoTypeInformation",[526,1351,1352],{},[741,1353,772],{},[1291,1355,1356,1372,1374,1382,1384],{},[1294,1357,1358,1361,1362,947,1365,947,1367,947,1369,1371],{},[1294,1359,1360],{"style":1298},"$CSVs"," = ",[1294,1363,1364],{"style":1298},"Import-Csv",[1294,1366,1336],{"style":1318},[1294,1368,1299],{"style":1298},[1294,1370,1341],{"style":1318}," \";\"",[590,1373],{},[1294,1375,1376,1326,1378,1381],{},[1294,1377,1360],{"style":1298},[1294,1379,1380],{"style":1298},"Group-Object"," Caller",[590,1383],{},[1294,1385,1386,1326,1388,1390],{},[1294,1387,1360],{"style":1298},[1294,1389,1380],{"style":1298}," CmdletName",[526,1392,1393],{},"CSVを分析し、ADのアクセス許可がどこで必要になるかを把握してください。Exchange関連のグループを専用のOUにまとめておくと、さらに最適化できる場合があります。",[697,1395,789],{"id":789},[526,1397,1398,1402,1403],{},[582,1399,687],{"href":1400,"rel":1401},"https://learn.microsoft.com/en-us/exchange/configure-exchange-server-for-split-permissions",[586],"\nに記載されたMicrosoftの手順**「Switch to Active Directory split permissions」**に従ってください。\n",[855,1404,1405],{},"（RBAC分割アクセス許可ではありません）",[526,1407,1408],{},"実質的には、**「Exchange Windows Permissions」**グループの危険なアクセス許可が削除され、あわせてExchangeがそのグループのメンバーから外されます。",[1291,1410,1411],{},[1294,1412,1413,947,1416,947,1419,947,1422],{},[1294,1414,1415],{"style":1298},"Setup.exe",[1294,1417,1418],{"style":1318},"/IAcceptExchangeServerLicenseTerms_DiagnosticDataOFF",[1294,1420,1421],{"style":1318},"/PrepareAD",[1294,1423,1424],{"style":1318},"/ActiveDirectorySplitPermissions:true",[1166,1426,1428,1429,1431,1432,1434],{"style":1427},"background:#f4f4f4; border-left:4px solid var(--color-gk-petrol); border-radius:0 6px 6px 0; padding:0.75rem 1rem; margin:1rem 0; font-size:0.88rem; color:#000520;","\n  ",[741,1430,1259],{}," 元に戻すには ",[713,1433,814],{}," を使うだけです\n",[558,1436,818],{"id":817},[526,1438,823],{},[1291,1440,1441,1447,1449,947,1452,1455,1456,1459,1460,1463,1464,947,1466,947,1469,1472,1473,1475,1455,1478,1481,1482],{},[1294,1442,1443],{},[1294,1444,1446],{"style":1445},"color:var(--color-black-40)","# adjust OU Path first!",[590,1448],{},[1294,1450,1451],{"style":1298},"New-ADGroup",[1294,1453,1454],{"style":1318},"-Name"," \"AD_Custom Exchange Split permissions replacement\" ",[1294,1457,1458],{"style":1318},"-GroupCategory"," Security ",[1294,1461,1462],{"style":1318},"-GroupScope"," DomainLocal ",[1294,1465,1336],{"style":1318},[741,1467,1468],{},"\"OU=Rights,OU=Groups,OU=T1,OU=_ADM,$((Get-ADDomain).DistinguishedName)\"",[1294,1470,1471],{"style":1318},"-Description"," \"replaces the permissions lost by split permissions on relevant OUs\"",[590,1474],{},[1294,1476,1477],{"style":1298},"Add-ADGroupMember",[1294,1479,1480],{"style":1318},"-Members"," \"Exchange Trusted Subsystem\"\n",[1294,1483,1484],{"style":1445},"# reboot Exchange servers for permissions via group to work",[526,1486,1487],{},"ユースケースごとにADアクセス許可を簡単に委任できるスクリプトを作成しました。",[848,1489,1490],{},[526,1491,1492,1493,862],{},"これらのアクセス許可がないと、ExchangeサーバーはADから",[713,1494,861],{},[526,1496,867,1497,873],{},[582,1498,872],{"href":870,"rel":1499},[586],[526,1501,1502],{},"付与できるPermissionTypeは次のとおりです。",[526,1504,1506,1508,888,1510,1512],{"style":1505},"background:#f5f5f5;padding:0.5rem 1rem;margin:0.25rem 0;border-left:3px solid #d8d8d8;",[741,1507,883],{},[590,1509],{},[590,1511],{},[1513,1514,1515],"small",{},"Exchangeコマンドレット: `New-Mailbox`, `New-RemoteMailbox`, `New-MailUser`, `New-MailContact` と対応する `Remove-*`",[526,1517,1519,1521,901,1523,1525],{"style":1518},"background:#f5f5f5;padding:0.5rem 1rem;margin:0.25rem 0;border-left:3px solid #d8d8d8",[741,1520,896],{},[590,1522],{},[590,1524],{},[1513,1526,1527,1528,1530],{},"Exchangeコマンドレット: `New-DistributionGroup`, `Remove-DistributionGroup`, `Add-DistributionGroupMember`, `Update-DistributionGroupMember`, `Remove-DistributionGroupMember`",[590,1529],{},"その他: ユーザーが自分の所有するDistributionGroupをEAC経由で管理する",[526,1532,1533,1535,921,1537,1539],{"style":1518},[741,1534,916],{},[590,1536],{},[590,1538],{},[1513,1540,1541],{},"Exchangeコマンドレット: `Add-ADPermission`",[526,1543,1544,1546,934,1548,1550],{"style":1518},[741,1545,929],{},[590,1547],{},[590,1549],{},[1513,1551,1541],{},[526,1553,1554],{},[741,1555,939],{},[1291,1557,1558,947,1560,1563,1564,1566,1567,1570,1571,1574,1576,947,1578,1580,1581,1583,1584,1570,1586,947,1588,1580,1590,1592,1593,1570,1595,947,1597,1599,1600,1602,1603,1570,1605,947,1607,1599,1609,1611,1612,1570],{},[1294,1559,872],{"style":1298},[1294,1561,1562],{"style":1318},"-TargetOU"," \u003COU> ",[1294,1565,956],{"style":1318}," \u003CGroupManage|UserSendAs|GroupSendAs|CreateUserAndContact> ",[1294,1568,1569],{"style":1318},"-Trustee"," \"AD_Custom Exchange Split permissions replacement\"\n",[1294,1572,1573],{"style":1445},"# For example",[590,1575],{},[1294,1577,872],{"style":1298},[1294,1579,1562],{"style":1318}," \"OU=ExchangeGroups,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" ",[1294,1582,956],{"style":1318}," GroupManage ",[1294,1585,1569],{"style":1318},[1294,1587,872],{"style":1298},[1294,1589,1562],{"style":1318},[1294,1591,956],{"style":1318}," GroupSendAs ",[1294,1594,1569],{"style":1318},[1294,1596,872],{"style":1298},[1294,1598,1562],{"style":1318}," \"OU=Users,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" ",[1294,1601,956],{"style":1318}," UserSendAs ",[1294,1604,1569],{"style":1318},[1294,1606,872],{"style":1298},[1294,1608,1562],{"style":1318},[1294,1610,956],{"style":1318}," CreateUserAndContact ",[1294,1613,1569],{"style":1318},[558,1615,1017],{"id":1016},[526,1617,1618],{},[741,1619,1022],{},[1291,1621,1622],{},[1294,1623,1624,947,1627,1629,1630,1633,1634,1636,1637,1639],{},[1294,1625,1626],{"style":1298},"New-RoleGroup",[1294,1628,1454],{"style":1318}," \"SplitPermission Security Group Creation and Membership\" ",[1294,1631,1632],{"style":1318},"-Roles"," \"Security Group Creation and Membership\" ",[1294,1635,1480],{"style":1318}," \"Organization Management\",\"Recipient Management\" ",[1294,1638,1471],{"style":1318}," \"Brings back -BypassSecurityGroupManagerCheck to Add-DistributionGroupMember, but also needs AD ACL for Exchange Server on target DLs\"",[848,1641,1642],{},[526,1643,1644,1646],{},[741,1645,1259],{}," これを行わないと \"-BypassSecurityGroupManagerCheck parameter is not available\" または \"You don't have sufficient permissions. This operation can only be performed by a manager of the group\" というエラーになります。",[526,1648,1649,1651,1653,1655],{},[590,1650],{},[741,1652,1045],{},[590,1654],{},[1291,1656,1657,947,1659,1661,1662,1664,1665,1636,1667,1669],{},[1294,1658,1626],{"style":1298},[1294,1660,1454],{"style":1318}," \"SplitPermission Mail Recipient Creation\" ",[1294,1663,1632],{"style":1318}," \"Mail Recipient Creation\" ",[1294,1666,1480],{"style":1318},[1294,1668,1471],{"style":1318}," \"Brings back New-Mailbox, New-RemoteMailbox, New-MailUser, New-MailContact and matching Remove-... cmdlets, but additionally Exchange needs AD ACL for Exchange Server on target OUs\"",[697,1671,1053],{"id":1053},[526,1673,1674],{},"このガイドが、Exchange経由のActive Directory侵害を防ぐという重要な一歩を、より多くの組織が踏み出す助けになれば幸いです。複数のお客様でExchange AD Split Permissionsモデルを実装してきましたが、これまで問題に遭遇したことはなく、導入もスムーズに進んでいます。",[526,1676,1677],{},"現在のオールオアナッシングの方式ではなく、OU単位でこの粒度を実現できるネイティブの仕組みをMicrosoftが提供してくれれば、広く採用されるようになるはずです。",[526,1679,1680,1681,1068,1684,1687],{},"ADのTier分離について一言。Exchangeサーバーへドメイン管理者やその他のTier 0アカウントでログオンしないでください。ExchangeサーバーはTier 1として扱い、できるだけ早くADのTier分離を実装してください。最初の一歩としては、",[582,1682,1067],{"href":1065,"rel":1683},[586],[582,1685,1073],{"href":1071,"rel":1686},[586],"でADのセキュリティ状況を評価し、コントロールパスの露出を洗い出すことをおすすめします。",[1076,1689,1078],{},{"title":530,"searchDepth":531,"depth":531,"links":1691},[1692,1693,1694,1695,1698,1702],{"id":560,"depth":531,"text":561},{"id":607,"depth":531,"text":607},{"id":699,"depth":531,"text":700},{"id":737,"depth":531,"text":737,"children":1696},[1697],{"id":747,"depth":1082,"text":747},{"id":789,"depth":531,"text":789,"children":1699},[1700,1701],{"id":817,"depth":1082,"text":818},{"id":1016,"depth":1082,"text":1017},{"id":1053,"depth":531,"text":1053},{"lang":1099,"seoTitle":1100,"titleClass":1101,"date":1704,"blogtitlepic":1705,"socialimg":1706,"customExcerpt":1707,"keywords":1106,"scripts":1708,"asideNav":1709,"maxContent":325,"published":325},"2026-03-01","head-exchange-ad-split-permissions","/blog/heads/head-exchange-ad-split-permissions.jpg","メールボックスをすべてクラウドへ移行済みの組織でも、オンプレミスのExchangeサーバーは動き続けていることが多く、それはActive Directoryにとって過小評価されたセキュリティリスクでもあります。「AD Split Permissions」モデルは、攻撃者がドメイン全体の侵害に悪用しうる広範なADの特権をExchangeから取り除きます。これまで導入が進まなかった主な理由は、管理者に強いるプロセス変更でした。本記事では、まさにそのハードルをスマートに乗り越える方法を紹介します。失われたADのアクセス許可を関連するOUにだけ選択的に再付与するスクリプトを使えば、慣れ親しんだ運用をそのままに、セキュリティ上の効果を余さず得られます。",{"slick":325,"form":325},{"menuItems":1710},[1711,1712,1713,1714,1715],{"href":1111,"text":561},{"href":1113,"text":607},{"href":1115,"text":700},{"href":1117,"text":737},{"href":1119,"text":1053},"/posts/2026-03-01-exchange-ad-split-permissions-hardening",{"title":1126,"description":530},"posts/2026-03-01-exchange-ad-split-permissions-hardening","nKUJDr2vxu6-4osz5GwwEI4qKNJRCdcRKnB9X84zc0s",[],{"id":1722,"extension":1723,"meta":1724,"stem":8,"__hash__":1731},"authors_data/authors.json","json",{"Thorsten Kunzi":1725},{"display_name":521,"avatar":1726,"permalink":1727,"twitter":1728,"linkedin":1729,"imageOffsetTop":1730},"people/author-thorsten-kunzi.png","/authors/thorsten-kunzi","glueckkanjagab","company/glueckkanja-gab","72%","1csawlkJxRljy93GTOnXEkwLqAv9Lcj-apxRvoodAOY",1791383994343]