[{"data":1,"prerenderedAt":1780},["ShallowReactive",2],{"sc:header-data-ko":3,"sc:footer-data-ko":489,"author-ko-thorsten-kunzi-1f055f71c9741a":519,"content-ko-thorsten-kunzi":549,"content-events-ko-thorsten-kunzi":1768,"authors_data:Thorsten Kunzi|​Thorsten Kunzi​":1769},{"lang":4,"home":5,"navigation":17,"meta":479,"contact":485},"de",{"name":6,"folderSwitch":7,"imgLight":10,"img":11,"languages":12},"home",[8,9],"authors","blog","/logos/gk-Logo-sw.svg","/logos/gk-Logo-rgb.svg",{"ko":13},{"title":14,"url":15,"alt":16},"홈","/ko","glueckkanja Logo",[18,127,231,316,395,402],{"name":19,"languages":20,"children":24},"workplace",{"ko":21},{"title":22,"description":23},"Workplace","스마트하고 안전하며 유연한 워크스페이스를 위한 Microsoft 365 기반 솔루션으로, 최신 기술과 ID 서비스를 매끄럽게 통합합니다.",[25,55,91],{"name":26,"languages":27,"children":30},"portfolio",{"ko":28},{"title":29},"Portfolio",[31,37,43,49],{"name":32,"languages":33},"managed-intune",{"ko":34},{"title":35,"url":36},"Managed Intune","/ko/entra-intune/managed-intune",{"name":38,"languages":39},"managed-entra",{"ko":40},{"title":41,"url":42},"Managed Entra","/ko/entra-intune/managed-entra",{"name":44,"languages":45},"managed-workplace",{"ko":46},{"title":47,"url":48},"Managed Workplace","/ko/workplace/managed-workplace",{"name":50,"languages":51},"consulting-services",{"ko":52},{"title":53,"url":54},"Consulting Services","/ko/workplace/consulting-services",{"name":56,"languages":57,"children":60},"microsoft-365-endpoint",{"ko":58},{"title":59},"Microsoft 365 Endpoint",[61,67,73,79,85],{"name":62,"languages":63},"microsoft-entra-suite",{"ko":64},{"title":65,"url":66},"Microsoft Entra Suite","/ko/workplace/microsoft-entra-suite",{"name":68,"languages":69},"microsoft-intune",{"ko":70},{"title":71,"url":72},"Microsoft Intune","/ko/workplace/microsoft-intune",{"name":74,"languages":75},"microsoft-windows",{"ko":76},{"title":77,"url":78},"Microsoft Windows","/ko/workplace/microsoft-windows",{"name":80,"languages":81},"windows-365-cloud-pc",{"ko":82},{"title":83,"url":84},"Windows 365 Cloud PC","/ko/workplace/windows365-cloud-pc",{"name":86,"languages":87},"cloud-workplace-foundation",{"ko":88},{"title":89,"url":90},"Cloud Workplace Foundation","/ko/workplace/cloud-workplace-foundation",{"name":92,"languages":93,"children":96},"microsoft-365-collaboration",{"ko":94},{"title":95},"Microsoft 365 Collaboration",[97,103,109,115,121],{"name":98,"languages":99},"microsoft-copilot",{"ko":100},{"title":101,"url":102},"Microsoft 365 Copilot","/ko/workplace/microsoft-365-copilot",{"name":104,"languages":105},"microsoft-teams",{"ko":106},{"title":107,"url":108},"Teams","/ko/workplace/microsoft-teams",{"name":110,"languages":111},"sharepoint-powerplatform",{"ko":112},{"title":113,"url":114},"SharePoint & Power Platform","/ko/workplace/sharepoint-power-platform",{"name":116,"languages":117},"exchange-online",{"ko":118},{"title":119,"url":120},"Exchange Online","/ko/workplace/exchange-online",{"name":122,"languages":123},"information-protection-compliance",{"ko":124},{"title":125,"url":126},"Information Protection & Compliance","/ko/workplace/information-protection-compliance",{"name":128,"languages":129,"children":133},"azure",{"ko":130},{"title":131,"description":132},"Azure","Azure로 성장을 가속하세요: IaaS와 PaaS를 통해 클라우드 비용을 절감하고 효율을 높이며 혁신을 추진합니다.",[134,151,181],{"name":135,"languages":136,"children":138},"azure-portfolio",{"ko":137},{"title":29},[139,145],{"name":140,"languages":141},"azure-managed-services",{"ko":142},{"title":143,"url":144},"Azure Managed Services","/ko/azure/azure-managed-services",{"name":146,"languages":147},"azure-consulting",{"ko":148},{"title":149,"url":150},"Azure Consulting","/ko/azure/azure-consulting",{"name":152,"languages":153,"children":156},"azure-scenarios",{"ko":154},{"title":155},"시나리오",[157,163,169,175],{"name":158,"languages":159},"plan-your-cloud",{"ko":160},{"title":161,"url":162},"클라우드 계획","/ko/azure/plan-your-cloud",{"name":164,"languages":165},"migrate-to-the-cloud",{"ko":166},{"title":167,"url":168},"클라우드로 마이그레이션","/ko/azure/migrate-to-the-cloud",{"name":170,"languages":171},"innovate-your-business",{"ko":172},{"title":173,"url":174},"비즈니스 혁신","/ko/azure/innovate-your-business",{"name":176,"languages":177},"vmware-exit",{"ko":178},{"title":179,"url":180},"VMware 전략 재검토","/ko/azure/vmware-exit",{"name":182,"languages":183,"children":186},"azure-practices",{"ko":184},{"title":185},"Practices",[187,193,199,202,208,213,219,225],{"name":188,"languages":189},"azure-foundation",{"ko":190},{"title":191,"url":192},"Azure Foundation","/ko/azure/azure-foundation",{"name":194,"languages":195},"azure-ai-foundation",{"ko":196},{"title":197,"url":198},"Azure AI Foundation","/ko/azure/azure-ai-foundation",{"name":86,"languages":200},{"ko":201},{"title":89,"url":90},{"name":203,"languages":204},"azure-data-foundation",{"ko":205},{"title":206,"url":207},"Azure Data Foundation","/ko/azure/azure-data-foundation",{"name":188,"languages":209},{"ko":210},{"title":211,"url":212},"Azure Container Foundation","/ko/azure/azure-container-foundation",{"name":214,"languages":215},"dark-tenant",{"ko":216},{"title":217,"url":218},"Managed Dark Tenant","/ko/azure/managed-dark-tenant",{"name":220,"languages":221},"azure-cloud-adoption-framework",{"ko":222},{"title":223,"url":224},"Cloud Adoption Framework","/ko/azure/cloud-adoption-framework",{"name":226,"languages":227},"azure-cloud-competence-center",{"ko":228},{"title":229,"url":230},"Cloud Competence Center","/ko/azure/cloud-competence-center",{"name":232,"languages":233,"children":242},"security",{"ko":234},{"title":235,"description":236,"emergency":237},"보안","수상 경력의 24/7 매니지드 서비스, 인시던트 대응, 최신 인프라 보호로 클라우드를 지킵니다.",{"text":238,"href":239,"skin":240,"icon":241},"공격을 받고 있나요?","/ko/security/are-you-under-attack","primary","emergency",[243,268,289],{"name":244,"children":245},"security-security-consulting",[246,252,256,262],{"name":247,"languages":248},"managed-red-tenant",{"ko":249},{"title":250,"url":251},"Managed Red Tenant","/ko/security/managed-red-tenant",{"name":214,"languages":253},{"ko":254},{"title":255,"url":218},"Dark Tenant",{"name":257,"languages":258},"sentinel-data-lake",{"ko":259},{"title":260,"url":261},"Sentinel Data Lake","/ko/security/sentinel-data-lake",{"name":263,"languages":264},"security-consulting",{"ko":265},{"title":266,"url":267},"Security Consulting","/ko/security/security-consulting",{"name":269,"children":270},"security-cloud-security-operations-center",[271,277,283],{"name":272,"languages":273},"cloud-security-operations-center",{"ko":274},{"title":275,"url":276},"Cloud Security Operations Center","/ko/security/cloud-security-operations-center",{"name":278,"languages":279},"global-secure-access",{"ko":280},{"title":281,"url":282},"Global Secure Access","/ko/security/global-secure-access",{"name":284,"languages":285},"my-work-id",{"ko":286},{"title":287,"url":288},"MyWorkID","/ko/security/my-work-id",{"name":290,"children":291},"security-preventive-services",[292,298,304,310],{"name":293,"languages":294},"preventive-services",{"ko":295},{"title":296,"url":297},"Preventive Services","/ko/security/preventive-services",{"name":299,"languages":300},"data-security-services",{"ko":301},{"title":302,"url":303},"Data Security Service","/ko/security/data-security-service",{"name":305,"languages":306},"security-copilot-agents",{"ko":307},{"title":308,"url":309},"Security Copilot Agents","/ko/security/security-copilot-agents",{"name":311,"languages":312},"nis2",{"ko":313},{"title":314,"url":315},"NIS2 이행","/ko/security/red-dark-tenant-nis2",{"name":317,"languages":318,"children":322},"products",{"ko":319},{"title":320,"description":321},"제품","완전히 안전한 100% 클라우드 네이티브 Microsoft 환경을 위한 혁신적인 제품군으로, 협업과 네트워크 인증, 소프트웨어 관리를 강화합니다.",[323,360],{"name":324,"products":325,"children":326},"lorem ipsum 1",true,[327,336,344,352],{"name":328,"img":329,"target":330,"languages":331},"realmjoin","products/realmjoin/realmjoin-nav-logo.svg","_blank",{"ko":332},{"title":333,"url":334,"subtitle":335},"RealmJoin","https://www.realmjoin.com","클라우드 기반 소프트웨어 배포",{"name":337,"img":338,"target":330,"languages":339},"scepman","products/scepman/scepman-nav-logo.svg",{"ko":340},{"title":341,"url":342,"subtitle":343},"SCEPman","https://www.scepman.com","클라우드에서 인증서 배포",{"name":345,"img":346,"target":330,"languages":347},"konnekt","products/konnekt/konnekt-nav-logo.svg",{"ko":348},{"title":349,"url":350,"subtitle":351},"KONNEKT","https://www.konnekt.io","Office 365 데이터를 로컬에서 활용",{"name":353,"img":354,"target":330,"languages":355},"realmigrator","products/realmigrator/realmigrator-nav-logo.svg",{"ko":356},{"title":357,"url":358,"subtitle":359},"RealMigrator","https://www.realmigrator.com","서버 간 데이터 마이그레이션",{"name":361,"products":325,"children":362},"lorem ipsum 2",[363,371,379,387],{"name":364,"img":365,"target":330,"languages":366},"terraprovider","products/terraprovider/terraprovider-nav-logo.svg",{"ko":367},{"title":368,"url":369,"subtitle":370},"TerraProvider","https://www.terraprovider.com","Microsoft 365용 Terraform Provider",{"name":372,"img":373,"target":330,"languages":374},"radiusaas","products/radius/radius-nav-logo.svg",{"ko":375},{"title":376,"url":377,"subtitle":378},"RADIUSaaS","https://www.radius-as-a-service.com","네트워크 인증",{"name":380,"img":381,"target":330,"languages":382},"unifiedcontacts","products/unified-contacts/unifiedcontact-nav-logo.svg",{"ko":383},{"title":384,"url":385,"subtitle":386},"Unified Contacts","https://www.unified-contacts.com","Microsoft Teams에서 연락처 찾기",{"name":388,"img":389,"target":330,"languages":390},"autopilotmonitor","products/autopilot-monitor/AutopilotMonitor-nav-logo.svg",{"ko":391},{"title":392,"url":393,"subtitle":394},"Autopilot Monitor","https://www.autopilotmonitor.com","실시간 Windows Autopilot 모니터링",{"name":396,"languages":397},"casestudies",{"ko":398},{"title":399,"url":400,"description":401},"고객 사례","/ko/casestudies","클라우드의 선구자: Blueprint 기반 접근 방식과 Infrastructure-as-Code 전문성을 갖춘, 포괄적인 클라우드 솔루션을 위한 최고의 Microsoft 파트너입니다.",{"name":403,"languages":404,"children":407},"company",{"ko":405},{"title":406,"description":401},"회사",[408,438,462],{"name":409,"languages":410,"children":413},"company-about-us",{"ko":411},{"title":412},"회사 소개",[414,420,426,432],{"name":415,"languages":416},"company-facts-figures",{"ko":417},{"title":418,"url":419},"주요 현황","/ko/company/facts-and-figures",{"name":421,"languages":422},"company-contact",{"ko":423},{"title":424,"url":425},"연락처 및 위치","/ko/company/contact-and-locations",{"name":427,"languages":428},"switzerland",{"ko":429},{"title":430,"url":431}," glueckkanja 스위스","/ko/company/switzerland",{"name":433,"languages":434},"austria",{"ko":435},{"title":436,"url":437},"glueckkanja 오스트리아","/ko/company/austria",{"name":439,"languages":440,"children":443},"company-career",{"ko":441},{"title":442},"채용",[444,450,456],{"name":445,"languages":446},"company-career-overview",{"ko":447},{"title":448,"url":449},"채용 안내","/ko/career",{"name":451,"languages":452},"company-young-professionals",{"ko":453},{"title":454,"url":455},"Young Professionals","/ko/young-professionals",{"name":457,"languages":458},"company-jobs",{"ko":459},{"title":460,"url":461},"채용 공고","/ko/job-offers",{"name":463,"languages":464,"children":467},"company-latest",{"ko":465},{"title":466},"최신 소식",[468,474],{"name":469,"languages":470},"company-blog",{"ko":471},{"title":472,"url":473},"블로그","/ko/blog",{"name":469,"languages":475},{"ko":476},{"title":477,"url":478},"이벤트","/ko/events",[480],{"name":481,"languages":482},"career-meta",{"ko":483},{"title":442,"url":449,"active":484},false,{"languages":486},{"ko":487},{"title":488,"url":425,"active":484},"문의",{"data":490},{"bgColor":491,"number":492,"mail":493,"brandLogos":494,"logos":495,"links":499,"linksKo":509},"var(--color-gk-mid-blue)","+49 69 4005520","info@glueckkanja.com",null,[496],{"img":10,"alt":16,"url":497,"class":498},"index.html","max-w-19rem",[500,503,506],{"title":501,"url":502},"Datenschutz","/de/privacy",{"title":504,"url":505},"Impressum","/de/imprint",{"title":507,"url":508},"No Cookies","/de/cookies",[510,513,516],{"title":511,"url":512},"개인정보 처리방침","/ko/privacy",{"title":514,"url":515},"법적 고지","/ko/imprint",{"title":517,"url":518},"쿠키 없음","/ko/cookies",{"id":520,"title":521,"body":522,"description":528,"extension":533,"meta":534,"name":521,"navigation":325,"otherLanguages":535,"path":545,"seo":546,"stem":547,"__hash__":548},"authors/thorsten-kunzi.md","Thorsten Kunzi",{"type":523,"value":524,"toc":529},"minimal",[525],[526,527,528],"p",{},"Als Consultant in den Bereichen Exchange Online, Identity und Modern Workplace unterstützt Thorsten Kunzi seit vielen Jahren Kunden bei der Planung und Umsetzung von Cloud-Projekten. Aufgrund seiner Erfahrung im Bereich der On-Premises Active Directory Security ist er auch im Hardening aktiv und hilft als Teil der APT Response Taskforce bei kompromittierten oder verschlüsselten Kundenumgebungen.",{"title":530,"searchDepth":531,"depth":531,"links":532},"",2,[],"md",{},{"en":536,"es":537,"sv":538,"fi":539,"da":540,"ko":541,"nl":542,"no":543,"ja":544},"As a consultant in the areas of Exchange Online, Identity and Modern Workplace, Thorsten Kunzi has been supporting customers in the planning and implementation of cloud projects for many years. Due to his experience in the area of on-premises Active Directory Security, he is also active in hardening and helps as part of the APT Response Taskforce with compromised or encrypted customer environments.","Como Consultant en las áreas de Exchange Online, Identity y Modern Workplace, Thorsten Kunzi lleva muchos años apoyando a los clientes en la planificación y ejecución de proyectos en la nube. Gracias a su experiencia en el ámbito de la seguridad de Active Directory on-premises, también trabaja en el hardening y ayuda, como parte de la APT Response Taskforce, en entornos de clientes comprometidos o cifrados.","Som Consultant inom områdena Exchange Online, Identity och Modern Workplace har Thorsten Kunzi i många år stöttat kunder i planeringen och genomförandet av molnprojekt. Tack vare sin erfarenhet inom on-premises Active Directory-säkerhet arbetar han även med hardening och hjälper som en del av APT Response Taskforce till i komprometterade eller krypterade kundmiljöer.","Consultantina Exchange Onlinen, Identityn ja Modern Workplacen alueilla Thorsten Kunzi on jo useiden vuosien ajan tukenut asiakkaita pilviprojektien suunnittelussa ja toteutuksessa. On-premises Active Directory -tietoturvan kokemuksensa ansiosta hän työskentelee myös hardeningin parissa ja auttaa osana APT Response Taskforce -tiimiä vaarantuneissa tai salatuissa asiakasympäristöissä.","Som Consultant inden for områderne Exchange Online, Identity og Modern Workplace har Thorsten Kunzi gennem mange år hjulpet kunder med planlægning og gennemførelse af cloud-projekter. På grund af sin erfaring inden for on-premises Active Directory-sikkerhed arbejder han også med hardening og hjælper som en del af APT Response Taskforce ved kompromitterede eller krypterede kundemiljøer.","Exchange Online, Identity, Modern Workplace 분야의 Consultant로서 Thorsten Kunzi는 오랜 기간 동안 고객의 클라우드 프로젝트 계획과 구현을 지원해 왔습니다. 온프레미스 Active Directory 보안 분야의 경험을 바탕으로 하드닝 작업에도 참여하고 있으며, APT Response Taskforce의 일원으로서 침해되거나 암호화된 고객 환경을 지원합니다.","Als Consultant voor Exchange Online, Identity en Modern Workplace ondersteunt Thorsten Kunzi klanten al vele jaren bij de planning en realisatie van cloudprojecten. Door zijn ervaring met On-Premises Active Directory Security is hij ook actief in hardening en helpt hij als onderdeel van de APT Response Taskforce bij gecompromitteerde of versleutelde klantomgevingen.","Som Consultant innen Exchange Online, Identity og Modern Workplace har Thorsten Kunzi i mange år bistått kunder med planlegging og gjennomføring av cloud-prosjekter. På grunn av erfaringen sin innen on-premises Active Directory Security er han også aktiv i hardening og hjelper som del av APT Response Taskforce ved kompromitterte eller krypterte kundemiljøer.","Exchange Online、Identity、Modern Workplaceの領域を担当するコンサルタントとして、Thorsten Kunziは長年にわたりクラウドプロジェクトの計画と実装でお客様を支援しています。オンプレミスのActive Directory Securityでの経験を活かしてHardeningにも携わり、APT Response Taskforceの一員として、侵害されたり暗号化されたりしたお客様環境に対応しています。","/thorsten-kunzi",{"title":521,"description":528},"thorsten-kunzi","YaiG705aTbfkaYxak0GKTbfT-5vntVpIpV6yaXJnw7I",[550,1131],{"id":551,"title":552,"author":553,"body":555,"cta":494,"description":530,"eventid":494,"extension":533,"hideInRecent":325,"layout":1104,"meta":1105,"moment":1109,"navigation":325,"path":1127,"seo":1128,"stem":1129,"tags":494,"webcast":484,"__hash__":1130},"content_ko/posts/2026-01-27-exchange-active-directory.md","후회 없이 Exchange AD 분할 권한 적용하기",[554],"​Thorsten Kunzi​",{"type":523,"value":556,"toc":1086},[557,562,565,572,576,603,606,610,616,631,637,640,644,680,699,704,710,719,723,739,743,750,754,764,769,774,793,797,822,826,846,854,870,884,944,948,972,989,1001,1014,1021,1025,1035,1046,1058,1061,1064,1067,1082],[558,559,561],"h3",{"id":560},"tldr-단점을-제거하면-어떨까요","TLDR: 단점을 제거하면 어떨까요?",[526,563,564],{},"Exchange 사용자, 그룹, 연락처 등이 위치한 곳에서 AD 및 RBAC 권한을 다시 부여하는 방법을 찾았습니다. 이 방식이라면 관리자나 ID 관리 시스템 측에서 별도의 도입 작업이 필요하지 않으며, 제 경험상 이것이 대부분의 기업이 이 모델을 구현하지 못하게 막았던 걸림돌이었습니다. 그러면서도 측면 이동(lateral movement)과 도메인 침해에 대한 보안 이점은 그대로 유지됩니다.",[526,566,567],{},[568,569],"img",{"alt":570,"src":571},"Active Directory","https://res.cloudinary.com/c4a8/image/upload/v1770991330/blog/pics/Blog_-_Exchange_AD_Split_Permissions_-_1.png",[558,573,575],{"id":574},"세-단계로-구현됩니다","세 단계로 구현됩니다:",[577,578,579,593,598],"ol",{},[580,581,582,589,590],"li",{},[583,584,588],"a",{"href":585,"rel":586},"https://learn.microsoft.com/en-us/exchange/permissions/split-permissions/configure-exchange-for-split-permissions#switch-to-active-directory-split-permissions",[587],"nofollow","AD 분할 권한 모델"," 구현",[591,592],"br",{},[580,594,595,596],{},"Exchange 서버에 상실된 AD 권한을 부여하되, 관련 OU에 한해서만 부여",[591,597],{},[580,599,600,601],{},"누락된 PowerShell cmdlet을 다시 활성화하기 위해 Exchange RBAC 부여",[591,602],{},[526,604,605],{},"모두 Microsoft의 가이드, AD ACL 또는 Exchange RBAC 할당을 통해 이루어집니다.",[558,607,609],{"id":608},"지금-왜-신경-써야-할까요","지금 왜 신경 써야 할까요?",[526,611,612,613,615],{},"이 기능은 Exchange 2010 SP1과 함께 도입된 이후로 대체로 간과되거나 무시되어 왔습니다. 그러나 기본 공유 권한 모델은 Active Directory 탈취로 이어지는 큰 보안 위험을 나타냅니다. 최근 몇 년간 Exchange가 원격 익스플로잇으로 악명을 떨쳐온 점까지 더하면, 이제는 행동에 나설 때입니다!",[591,614],{},"\n이 문제는 도메인 루트에 부여된 권한이 도메인 전체로 상속되는 데서 비롯됩니다.",[617,618,619,622,625,628],"ul",{},[580,620,621],{},"사용자 및 그룹에 대한 권한 수정(사실상 전체 액세스)",[580,623,624],{},"그룹 구성원 수정",[580,626,627],{},"사용자 암호 재설정",[580,629,630],{},"사용자 및 그룹 생성/삭제",[526,632,633],{},[568,634],{"alt":635,"src":636},"Permissions","https://res.cloudinary.com/c4a8/image/upload/v1770991330/blog/pics/Blog_-_Exchange_AD_Split_Permissions_-_2.png",[526,638,639],{},"일부 높은 권한을 가진 Tier0 사용자 및 그룹만이 AdminSDHolder 프로세스(admincount=1 특성)에 의해 보호되며, 많은 환경에서는 도메인 및/또는 포리스트의 침해를 허용하거나 최소한 심각한 영향을 초래할 수 있는 보호되지 않은 사용자나 그룹이 존재합니다.",[558,641,643],{"id":642},"대표적인-예시","대표적인 예시:",[617,645,646,649,669],{},[580,647,648],{},"PWHashSync를 사용할 때의 Entra Connect Sync 계정",[580,650,651,652],{},"기본 그룹\n",[617,653,654,657,666],{},[580,655,656],{},"EntraConnect 계정과 함께 있는 Allowed RODC Password Replication Group(실제 Windows RODC가 존재하는 경우)",[580,658,659,660,665],{},"더 많은 경로를 보여주는 ",[583,661,664],{"href":662,"rel":663},"https://specterops.io/blog/2025/06/25/untrustworthy-trust-builders-account-operators-replicating-trust-attack-aorta/",[587],"Untrustworthy Trust Builders: Account Operators Replicating Trust Attack (AORTA) - SpecterOps","도 참고하세요(Account Operators 그룹도 유사한 위협입니다)",[580,667,668],{},"보호를 제거하여 공격 경로를 만들기 위해 Protected Users를 비우는 행위",[580,670,671,672],{},"보호되지 않은 사용자 지정 그룹 또는 관리자/서비스 계정\n",[617,673,674,677],{},[580,675,676],{},"GPO에 대한 쓰기 권한(도메인 컨트롤러에 적용됨)",[580,678,679],{},"AD 백업, 백업 서버, PKI 템플릿, 하이퍼바이저 등에 대한 액세스 관리",[526,681,682,683,685,686,691,693,694],{},"이러한 현재 및 향후의 모든 잠재적 경로를 사후에 통제하기란 매우 어렵습니다. _ADM 사용자 지정 OU의 경우 ACL 상속을 비활성화할 수 있지만, 대부분의 기본 개체는 기본 Builtin OU나 Users 컨테이너에서 이동할 수 없어 취약한 상태로 남습니다.",[591,684],{},"\n루트에서 강력한 권한을 제거하는 편이 훨씬 낫고, 이는 Active Directory 분할 권한 모델을 구현함으로써 이루어집니다. ",[583,687,690],{"href":688,"rel":689},"https://learn.microsoft.com/en-us/exchange/permissions/split-permissions/configure-exchange-for-split-permissions",[587],"Configure Exchange Server for split permissions | Microsoft Learn",[591,692],{},"\n그리고 Microsoft도 이에 동의합니다. “…encouraged to implement Active Directory split permissions” ",[583,695,698],{"href":696,"rel":697},"https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/active-directory-hardening-series---part-7-%E2%80%93-implementing-least-privilege/4366626",[587],"Active Directory Hardening Series - Part 7 – Implementing Least Privilege | Microsoft Community Hub",[700,701,703],"h2",{"id":702},"그런데-왜-아무도-하지-않을까요","그런데 왜 아무도 하지 않을까요?",[526,705,706,707,709],{},"분할 권한은 Exchange 2010 SP1이 나오기 전까지는 사용할 수 없었기 때문에 그 무렵에는 이미 모두가 기존 방식을 받아들인 상태였고, 이 기능이 생긴 뒤에도 보안 팀이 도입을 성공적으로 밀어붙이지 못한 것으로 보입니다.",[591,708],{},"\n게다가 이 기능은 관리자 및 IDM 프로세스의 변경을 강제했을 것입니다. 예를 들어 먼저 AD에서 사용자나 배포 목록을 생성한 뒤에야 Exchange를 사용해 “메일 사용(mail enable)”으로 설정하는 식입니다.",[526,711,712,713,715],{},"더 이상 사용할 수 없거나 작동하지 않는 cmdlet:",[591,714],{},[716,717,718],"code",{},"Add-DistributionGroupMember, New-DistributionGroup, New-Mailbox, New-MailContact, New-MailUser, New-RemoteMailbox, Remove-DistributionGroup, Remove-DistributionGroupMember, Remove-Mailbox, Remove-MailContact, Remove-MailUser, Remove-RemoteMailbox, Update-DistributionGroupMember, Add-ADPermission, Remove-ADPermission ",[558,720,722],{"id":721},"적용-방식-예시","적용 방식 예시:",[617,724,725,736],{},[580,726,727,728],{},"New-Mailbox(Exchange가 AD에 쓰는 경우)는 다음과 같이 바뀝니다:\n",[617,729,730,733],{},[580,731,732],{},"New-ADUser(adm.jdoe가 AD에 쓰는 경우)",[580,734,735],{},"Enable-Mailbox",[580,737,738],{},"SendAs 권한을 위한 Add-ADPermission은 Active Directory 사용자 및 컴퓨터의 보안 탭을 통해 수행해야 하며, 표준 관리자에게는 추가 AD 권한이 필요한 경우가 많습니다.",[700,740,742],{"id":741},"후회-없는-방법을-보여주세요","후회 없는 방법을 보여주세요!",[526,744,745,749],{},[746,747,748],"strong",{},"면책 조항",": 다음 링크와 문서를 반드시 완전히 읽고 이해한 뒤, 먼저 테스트 환경에서 수행하고, AD 백업이 최신 상태인지, 복구 절차가 확립되어 있는지 확인하세요!",[558,751,753],{"id":752},"현재-사용-현황-감사","현재 사용 현황 감사",[526,755,756,759,761],{},[746,757,758],{},"먼저 영향을 받는 cmdlet 중 어떤 것이 어떤 OU에서 사용되고 있는지 확인해야 합니다.",[591,760],{},[716,762,763],{},"$CsvPath =\"C:\\temp\\SplitPermissionAdminAuditLog.csv\"",[526,765,766],{},[716,767,768],{},"$Cmdlets = \"Add-ADPermission\",\"Remove-ADPermission\",\"New-DistributionGroup\",\"Remove-DistributionGroup\",\"Add-DistributionGroupMember\",\"Update-DistributionGroupMember\",\"Remove-DistributionGroupMember\",\"New-Mailbox\",\"Remove-Mailbox\",\"New-RemoteMailbox\",\"Remove-RemoteMailbox\",\"New-MailUser\",\"Remove-MailUser\",\"New-MailContact\",\"Remove-MailContact\"",[526,770,771],{},[716,772,773],{},"Search-AdminAuditLog -ResultSize 99000 -Cmdlets $Cmdlets| select RunDate,Caller,ObjectModified,CmdletName,@{Name='CmdletParameters';Expression={[string]::join(\",\", ($_.CmdletParameters))}},succeeded,error | Export-Csv -Path $CsvPath -Delimiter \";\" -Encoding Unicode -NoTypeInformation",[526,775,776,779,781,784,787,790],{},[746,777,778],{},"호출자 및 cmdlet의 빠른 분석:",[591,780],{},[716,782,783],{},"$CSVs=Import-Csv -Path $CsvPath -Delimiter \";\"",[716,785,786],{},"$CSVs|group Caller",[716,788,789],{},"$CSVs|group CmdletName",[716,791,792],{},"AD 권한이 필요한 위치를 파악하기 위해 CSV를 분석하세요. 모든 Exchange 관련 그룹을 전용 OU로 이동하여 최적화할 수도 있습니다.",[558,794,796],{"id":795},"분할-권한-모델-활성화","분할 권한 모델 활성화",[526,798,799,805,807,808,810,813,815,818,819],{},[746,800,801,804],{},[583,802,690],{"href":585,"rel":803},[587],"의 “Switch to Active Directory split permissions” 지침을 따르세요(RBAC 분할 권한이 아님).",[591,806],{},"\n본질적으로 이는 “Exchange Windows Permissions” 그룹의 위험한 권한을 제거하고 Exchange를 그룹 구성원에서도 제거합니다.",[591,809],{},[716,811,812],{},"Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataOFF /PrepareAD /ActiveDirectorySplitPermissions:true",[591,814],{},[746,816,817],{},"되돌리려면 다음을 사용하세요:"," ",[716,820,821],{},"/ActiveDirectorySplitPermissions:false",[558,823,825],{"id":824},"ad-권한-부여","AD 권한 부여",[526,827,828,831,833,834,836,839,841,843],{},[746,829,830],{},"사용자 지정 AD 그룹을 만들고 Exchange 서버를 구성원으로 추가하세요.",[591,832],{},"\n먼저 OU 경로를 조정하세요!",[591,835],{},[716,837,838],{},"New-ADGroup -Name \"AD_Custom Exchange Split permissions replacement\" -GroupCategory Security -GroupScope DomainLocal -Path \"OU=Rights,OU=Groups,OU=T1,OU=_ADM,$((Get-ADDomain).DistinguishedName)\" -Description \"replaces the permissions lost by split permissions on relevant OUs\"",[591,840],{},[591,842],{},[716,844,845],{},"Add-ADGroupMember \"AD_Custom Exchange Split permissions replacement\" -Members \"Exchange Trusted Subsystem\"",[526,847,848,851,853],{},[746,849,850],{},"그룹을 통한 권한이 작동하도록 Exchange 서버를 재부팅하세요",[591,852],{},"\n사용 사례별로 AD 권한 위임을 쉽게 할 수 있도록 스크립트를 만들었습니다.",[855,856,857],"blockquote",{},[526,858,859,865,866,869],{},[746,860,861],{},[862,863,864],"em",{},"INFO:"," 이러한 권한이 없으면 Exchange 서버는 AD로부터 ",[716,867,868],{},"“INSUFF_ACCESS_RIGHTS”"," 오류를 받게 됩니다.",[526,871,872,881,883],{},[746,873,874,875,880],{},"glueckkanja GitHub에서 ",[583,876,879],{"href":877,"rel":878},"https://github.com/glueckkanja/code-snippets/blob/main/ExchangeADSplitPermission/Add-ExchangeADSplitPermissionOnOU.ps1",[587],"Add-ExchangeADSplitPermissionOnOU.ps1","을 다운로드하세요",[591,882],{},"\n다음 PermissionType을 부여할 수 있습니다:",[617,885,886,899,919,932],{},[580,887,888,891],{},[746,889,890],{},"CreateUserAndContact",[617,892,893,896],{},[580,894,895],{},"사용자 및 연락처에 대한 생성/삭제, ResetPassword, WriteAllProperties",[580,897,898],{},"Exchange cmdlet: New-Mailbox, New-RemoteMailbox, New-MailUser, New-MailContact 및 이에 대응하는 Remove-*",[580,900,901,904],{},[746,902,903],{},"GroupManage",[617,905,906,909,912],{},[580,907,908],{},"그룹 생성/삭제, 구성원 수정",[580,910,911],{},"Exchange cmdlet: New-DistributionGroup, Remove-DistributionGroup, Add-DistributionGroupMember, Update-DistributionGroupMember, Remove-DistributionGroupMember",[580,913,914,915],{},"추가 사용 사례: 사용자가 https://",[916,917,918],"on-prem-exchange",{},"/EAC를 통해 자신이 소유한 DistributionGroup을 관리",[580,920,921,924],{},[746,922,923],{},"UserSendAs",[617,925,926,929],{},[580,927,928],{},"사용자에 대한 AD 권한 수정",[580,930,931],{},"Exchange cmdlet: Add-ADPermission",[580,933,934,937],{},[746,935,936],{},"GroupSendAs",[617,938,939,942],{},[580,940,941],{},"그룹에 대한 AD 권한 수정",[580,943,931],{},[558,945,947],{"id":946},"스크립트-사용-방법","스크립트 사용 방법:",[526,949,950],{},[716,951,952,818,955,818,961,818,964,818,969],{},[716,953,954],{},"Add-ExchangeADSplitPermissionOnOU.ps1 -TargetOU",[956,957,958],"b",{},[716,959,960],{},"\u003COU>",[716,962,963],{},"-PermissionType",[956,965,966],{},[716,967,968],{},"\u003CGroupManage|UserSendAs|GroupSendAs|CreateUserAndContact>",[716,970,971],{},"-Trustee \"AD_Custom Exchange Split permissions replacement",[526,973,974,975,977],{},"예:",[591,976],{},[716,978,979,818,982,818,986],{},[716,980,981],{},"Add-ExchangeADSplitPermissionOnOU.ps1 -TargetOU \"OU=ExchangeGroups,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" -PermissionType",[956,983,984],{},[716,985,903],{},[716,987,988],{},"-Trustee \"AD_Custom Exchange Split permissions replacement\"",[526,990,991],{},[716,992,993,818,995,818,999],{},[716,994,981],{},[956,996,997],{},[716,998,936],{},[716,1000,988],{},[526,1002,1003],{},[716,1004,1005,818,1008,818,1012],{},[716,1006,1007],{},"Add-ExchangeADSplitPermissionOnOU.ps1 -TargetOU \"OU=Users,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" -PermissionType",[956,1009,1010],{},[716,1011,923],{},[716,1013,988],{},[526,1015,1016],{},[716,1017,1018],{},[716,1019,1020],{},"Add-ExchangeADSplitPermissionOnOU.ps1 -TargetOU \"OU=Users,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" -PermissionType CreateUserAndContact -Trustee \"AD_Custom Exchange Split permissions replacement\"",[558,1022,1024],{"id":1023},"exchange-rbac-부여","Exchange RBAC 부여",[526,1026,1027,1030,1032],{},[746,1028,1029],{},"Add-DistributionGroupMember 및 Remove-DistributionGroupMember cmdlet에 대해 -BypassSecurityGroupManagerCheck 매개 변수를 다시 활성화:",[591,1031],{},[716,1033,1034],{},"New-RoleGroup -Name \"SplitPermission Security Group Creation and Membership\" -Roles \"Security Group Creation and Membership\" -Members \"Organization Management\",\"Recipient Management\" -Description \"Brings back -BypassSecurityGroupManagerCheck to Add-DistributionGroupMember, but also needs AD ACL for Exchange Server on target DLs\" ",[855,1036,1037],{},[526,1038,1039,818,1043,1045],{},[746,1040,1041],{},[862,1042,864],{},[591,1044],{},"그렇지 않으면 \"-BypassSecurityGroupManagerCheck parameter is not available\" 또는 \"You don't have sufficient permissions. This operation can only be performed by a manager of the group\" 오류가 발생합니다.",[526,1047,1048,1050,1053,1055],{},[591,1049],{},[746,1051,1052],{},"필요한 매개 변수와 함께 New-Mailbox, New-RemoteMailbox, New-MailContact, Remove-... cmdlet을 다시 활성화:",[591,1054],{},[716,1056,1057],{},"New-RoleGroup -Name \"SplitPermission Mail Recipient Creation\" -Roles \"Mail Recipient Creation\" -Members \"Organization Management\",\"Recipient Management\" -Description \"Brings back New-Mailbox, New-RemoteMailbox, New-MailUser, New-MailContact and matching Remove-... cmdlets, but additionally Exchange needs AD ACL for Exchange Server on target OUs\"",[700,1059,1060],{"id":1060},"결론",[526,1062,1063],{},"이 가이드를 통해 더 많은 분들이 Exchange를 통한 침해로부터 Active Directory를 보호하는 이 중요한 단계를 밟기를 바랍니다. 저는 고객사에서 Exchange AD 분할 권한 모델과 이 글에서 소개한 적용 방식을 구현하면서 아직까지 문제를 겪은 적이 없습니다.",[526,1065,1066],{},"저는 Microsoft가 현재의 전부 아니면 전무 방식 대신, 이러한 세분화된 OU 기반 접근 방식을 기본적으로 구현하여 이 방식이 널리 채택되기를 바랍니다.",[526,1068,1069,1070,1075,1076,1081],{},"AD 계층화(Tiering)는 제가 특히 중요하게 여기는 부분입니다. 추가로, Exchange 서버에 Domain Admin(또는 어떤 Tier0 계정으로도) 로그온하지 말고 지금부터는 Tier1으로 취급하며 가능한 한 빨리 AD 계층화를 구현하세요.\n첫 단계로, AD 보안 및 제어 경로를 평가하기 위해 ",[583,1071,1074],{"href":1072,"rel":1073},"https://www.pingcastle.com/",[587],"PingCastle"," 또는 ",[583,1077,1080],{"href":1078,"rel":1079},"https://www.semperis.com/purple-knight/",[587],"Purple Knight"," 같은 도구를 권장합니다.",[1083,1084,1085],"style",{},"\ncode {\n  font-size: inherit\n}\n",{"title":530,"searchDepth":531,"depth":531,"links":1087},[1088,1090,1091,1092,1093,1096,1103],{"id":560,"depth":1089,"text":561},3,{"id":574,"depth":1089,"text":575},{"id":608,"depth":1089,"text":609},{"id":642,"depth":1089,"text":643},{"id":702,"depth":531,"text":703,"children":1094},[1095],{"id":721,"depth":1089,"text":722},{"id":741,"depth":531,"text":742,"children":1097},[1098,1099,1100,1101,1102],{"id":752,"depth":1089,"text":753},{"id":795,"depth":1089,"text":796},{"id":824,"depth":1089,"text":825},{"id":946,"depth":1089,"text":947},{"id":1023,"depth":1089,"text":1024},{"id":1060,"depth":531,"text":1060},"post",{"lang":1106,"seoTitle":1107,"titleClass":1108,"date":1109,"blogtitlepic":1110,"socialimg":1111,"customExcerpt":1112,"keywords":1113,"scripts":1114,"asideNav":1115,"maxContent":325,"published":484},"ko","Exchange AD 분할 권한: 최소 권한으로 Active Directory 보호하기","h2-font-size","2026-01-27","head-vulnerability-management","/blog/heads/head-vulnerability-management.jpg","이미 모든 사서함을 클라우드로 옮긴 조직에서도 온-프레미스 Exchange Server 설치는 여전히 흔하게 남아 있습니다. 또한 Exchange는 Active Directory 내에서 여전히 매우 강력한 권한을 가지므로, 대부분의 경우 전체 AD를 장악하고 나아가 기업 IT 대부분을 손에 넣는 강력한 공격 경로가 존재합니다. 이른바 “AD 분할 권한(AD Split permissions)”으로 전환하면 이 치명적인 권한이 제거되며, 저는 지금까지 도입을 가로막아 온 단점들을 없앤 솔루션을 설계했습니다.","Exchange Server, Active Directory, AD 분할 권한, RBAC, Exchange 권한, AdminSDHolder, 최소 권한, AD ACL, PowerShell",{"slick":325,"form":325},{"menuItems":1116},[1117,1119,1121,1123,1125],{"href":1118,"text":561},"#tldr-단점을-제거하면-어떨까요",{"href":1120,"text":609},"#지금-왜-신경-써야-할까요",{"href":1122,"text":703},"#그런데-왜-아무도-하지-않을까요",{"href":1124,"text":742},"#후회-없는-방법을-보여주세요",{"href":1126,"text":1060},"#결론","/posts/2026-01-27-exchange-active-directory",{"title":552,"description":530},"posts/2026-01-27-exchange-active-directory","mcfYx9iUa3uq8uecLxNRRESZtYidQyM_fPQx2AmREsc",{"id":1132,"title":1133,"author":1134,"body":1135,"cta":494,"description":530,"eventid":494,"extension":533,"hideInRecent":484,"layout":1104,"meta":1745,"moment":1747,"navigation":325,"path":1764,"seo":1765,"stem":1766,"tags":494,"webcast":484,"__hash__":1767},"content_ko/posts/2026-03-01-exchange-ad-split-permissions-hardening.md","후회 없는 Exchange AD Split Permissions",[521],{"type":523,"value":1136,"toc":1732},[1137,1141,1144,1148,1153,1166,1168,1175,1180,1184,1192,1203,1207,1210,1214,1245,1264,1268,1276,1284,1289,1304,1308,1314,1316,1321,1381,1386,1423,1426,1430,1440,1447,1463,1473,1475,1478,1524,1527,1534,1540,1543,1556,1571,1582,1592,1596,1654,1656,1661,1681,1688,1712,1714,1717,1720,1730],[700,1138,1140],{"id":1139},"tldr-단점을-없앤다면","TLDR: 단점을 없앤다면?",[526,1142,1143],{},"저는 Exchange 사용자, 그룹, 연락처가 위치한 바로 그 지점에 AD 및 RBAC 권한을 직접 다시 부여하는 방법을 찾았습니다. 이 방법은 관리자나 ID 관리 시스템에 아무런 변경도 요구하지 않습니다. 제 경험상 바로 이 마찰이 대부분의 기업에서 도입을 가로막는 주요 원인이었습니다. 그러면서도 측면 이동(lateral movement)과 도메인 장악에 대한 보안 이점은 그대로 유지됩니다.",[526,1145,1146],{},[568,1147],{"alt":570,"src":571},[526,1149,1150],{},[746,1151,1152],{},"세 단계로 이루어집니다:",[577,1154,1156,1161,1164],{"style":1155},"margin: 0.25rem 0",[580,1157,1158,589],{},[583,1159,1160],{"href":585},"AD split permission 모델",[580,1162,1163],{},"Exchange 서버에 잃어버린 AD 권한을 부여하되, 관련 OU에만 부여",[580,1165,600],{},[526,1167,605],{},[1169,1170],"video-frame",{"thumb":1171,"alt":1172,"id":1173,":full-width":1174},"/thumbs/thumb-exchange-ad-split-permissions-webcast.jpg","발표자가 노트북 앞에 앉아 glueckkanja의 Step 1: Active Directory Permissions라는 제목의 슬라이드를 설명하고 있습니다. 슬라이드는 위임 그룹을 만드는 PowerShell 명령(New-ADGroup, Add-ADGroupMember)과 Add-ExchangeADSplitPermissionOnOU.ps1 스크립트를 통해 권한을 적용하는 방법 등 Microsoft Exchange AD Split Permissions를 구현하는 방법을 다룹니다.","soNZkNRopSQ","true",[1176,1177,1179],"div",{"style":1178},"background:var(--color-gk-light-grey); margin-top:0.5rem; padding:0.5rem 1rem; font-size:0.85rem; color:var(--color-gk-dark-blue)","웹캐스트: 후회 없는 Exchange AD Split Permissions. 단계별 구현 가이드",[700,1181,1183],{"id":1182},"왜-지금-중요한가","왜 지금 중요한가?",[526,1185,1186,1187,1189,1191],{},"이 모델은 Exchange 2010 SP1에서 도입된 이후 대부분 간과되거나 무시되어 왔습니다. 하지만 기본값인 공유 권한(shared permissions) 모델은 Active Directory 장악이라는 큰 보안 위험을 내포합니다. 지난 몇 년간 Exchange가 원격 익스플로잇으로 악명 높았던 점까지 고려하면, 이제 행동에 나설 때입니다!",[591,1188],{},[591,1190],{},"\n문제는 도메인 루트에 부여된 권한이 도메인 전체로 상속된다는 점에서 비롯됩니다.",[617,1193,1194,1197,1199,1201],{"style":1155},[580,1195,1196],{},"사용자 및 그룹에 대한 권한 수정 (사실상 전체 액세스)",[580,1198,624],{},[580,1200,627],{},[580,1202,630],{},[526,1204,1205],{},[568,1206],{"alt":635,"src":636},[526,1208,1209],{},"AdminSDHolder 프로세스(admincount=1 특성)로 보호되는 것은 일부 고권한 Tier 0 사용자와 그룹뿐이며, 많은 환경에서는 도메인 또는 포리스트(forest) 장악을 허용하거나 최소한 심각한 영향을 초래할 수 있는 보호되지 않은 사용자나 그룹이 존재합니다.",[526,1211,1212],{},[746,1213,643],{},[617,1215,1216,1219,1236],{"style":1155},[580,1217,1218],{},"Password Hash Sync를 사용할 때의 Entra Connect Sync 계정",[580,1220,1221,1222],{},"기본 그룹",[617,1223,1225,1228,1233],{"style":1224},"margin: 0",[580,1226,1227],{},"Entra Connect 계정과 결합된 Allowed RODC Password Replication Group(실제 Windows RODC가 존재하는 경우)",[580,1229,659,1230,665],{},[583,1231,664],{"href":1232,"target":330},"https://specterops.io/blog/2025/06/25/untrustworthy-trust-builders-account-operators-replicating-trust-attack-aorta",[580,1234,1235],{},"보호를 제거해 공격 벡터를 만들기 위한 Protected Users 비우기",[580,1237,1238,1239],{},"보호되지 않은 사용자 지정 그룹 또는 관리자/서비스 계정",[617,1240,1241,1243],{"style":1224},[580,1242,676],{},[580,1244,679],{},[526,1246,1247,1248,1250,1252,1253,1256,1258,1260,1261],{},"이러한 현재와 미래의 모든 잠재적 경로를 사후에 억제하기란 매우 어렵습니다. _ADM 사용자 지정 OU의 경우 ACL 상속을 비활성화할 수 있지만, 대부분의 기본 개체는 기본 Builtin OU나 Users 컨테이너에서 이동할 수 없어 취약한 상태로 남습니다.",[591,1249],{},[591,1251],{},"\n루트에서 강력한 권한을 제거하는 편이 훨씬 낫고, 이는 Active Directory split permissions 모델을 구현함으로써 이루어집니다. ",[583,1254,690],{"href":688,"rel":1255},[587],[591,1257],{},[591,1259],{},"\n그리고 Microsoft도 이에 동의합니다: “…encouraged to implement Active Directory split permissions” ",[583,1262,698],{"href":696,"rel":1263},[587],[700,1265,1267],{"id":1266},"그런데-왜-아무도-하지-않을까","그런데 왜 아무도 하지 않을까?",[526,1269,1270,1271,1273,1275],{},"split permissions는 Exchange 2010 SP1이 나오기 전까지는 사용할 수 없었기 때문에, 그때쯤이면 이미 모두가 기존 방식을 받아들인 상태였고, 이 기능이 생긴 뒤에도 보안 팀이 이를 성공적으로 밀어붙이지 못한 것으로 보입니다.",[591,1272],{},[591,1274],{},"\n게다가 이 모델은 관리자 및 IDM 프로세스의 변경을 강제했을 것입니다. 예를 들어 사용자나 배포 목록을 먼저 AD에서 만든 다음에야 Exchange를 사용해 “mail enable”하는 식입니다.",[855,1277,1278],{},[526,1279,1280,1283],{},[746,1281,1282],{},"Info:"," 다음 cmdlet은 더 이상 사용할 수 없거나 작동하지 않습니다: Add-DistributionGroupMember, New-DistributionGroup, New-Mailbox, New-MailContact, New-MailUser, New-RemoteMailbox, Remove-DistributionGroup, Remove-DistributionGroupMember, Remove-Mailbox, Remove-MailContact, Remove-MailUser, Remove-RemoteMailbox, Update-DistributionGroupMember, Add-ADPermission, Remove-ADPermission",[526,1285,1286],{},[746,1287,1288],{},"적용 예시:",[617,1290,1291,1301],{"style":1155},[580,1292,1293,1294],{},"New-Mailbox(Exchange가 AD에 쓰는 작업)는 다음처럼 바뀝니다:",[617,1295,1296,1299],{"style":1224},[580,1297,1298],{},"New-ADUser(adm.jdoe가 AD에 쓰는 작업)",[580,1300,735],{},[580,1302,1303],{},"SendAs 권한을 위한 Add-ADPermission은 Active Directory 사용자 및 컴퓨터의 보안 탭에서 수행해야 하며, 일반 관리자에게는 추가 AD 권한이 필요한 경우가 많습니다.",[700,1305,1307],{"id":1306},"후회-없는-방법을-알려드립니다","후회 없는 방법을 알려드립니다",[526,1309,1310,1313],{},[746,1311,1312],{},"주의사항",": 다음 링크와 문서를 반드시 끝까지 읽고 이해한 뒤, 먼저 테스트 환경에서 수행하고, AD 백업이 최신 상태이며 복구 절차가 마련되어 있는지 확인하세요!",[558,1315,753],{"id":752},[526,1317,1318],{},[746,1319,1320],{},"먼저 영향을 받는 cmdlet 중 어떤 것이 어떤 OU에서 사용되고 있는지 확인해야 합니다:",[1322,1323,1324,1332,1334,1340,1342],"code-block",{},[1325,1326,1327,1331],"span",{},[1325,1328,1330],{"style":1329},"color:var(--color-gk-orange)","$CsvPath"," = \"C:\\temp\\SplitPermissionAdminAuditLog.csv\"",[591,1333],{},[1325,1335,1336,1339],{},[1325,1337,1338],{"style":1329},"$Cmdlets"," = \"Add-ADPermission\",\"Remove-ADPermission\",\"New-DistributionGroup\",\"Remove-DistributionGroup\",\"Add-DistributionGroupMember\",\"Update-DistributionGroupMember\",\"Remove-DistributionGroupMember\",\"New-Mailbox\",\"Remove-Mailbox\",\"New-RemoteMailbox\",\"Remove-RemoteMailbox\",\"New-MailUser\",\"Remove-MailUser\",\"New-MailContact\",\"Remove-MailContact\"",[591,1341],{},[1325,1343,1344,818,1347,1351,1352,818,1355,1357,1358,1361,1362,818,1365,818,1368,818,1370,1373,1374,1377,1378],{},[1325,1345,1346],{"style":1329},"Search-AdminAuditLog",[1325,1348,1350],{"style":1349},"color:var(--color-gk-mid-blue)","-ResultSize"," 99000 ",[1325,1353,1354],{"style":1349},"-Cmdlets",[1325,1356,1338],{"style":1329}," | ",[1325,1359,1360],{"style":1329},"Select-Object"," RunDate,Caller,ObjectModified,CmdletName,@{Name='CmdletParameters';Expression={[string]::join(\",\", ($\\_.CmdletParameters))}},succeeded,error | ",[1325,1363,1364],{"style":1329},"Export-Csv",[1325,1366,1367],{"style":1349},"-Path",[1325,1369,1330],{"style":1329},[1325,1371,1372],{"style":1349},"-Delimiter"," \";\" ",[1325,1375,1376],{"style":1349},"-Encoding"," Unicode ",[1325,1379,1380],{"style":1349},"-NoTypeInformation",[526,1382,1383],{},[746,1384,1385],{},"호출자(caller)와 cmdlet에 대한 빠른 분석:",[1322,1387,1388,1404,1406,1414,1416],{},[1325,1389,1390,1393,1394,818,1397,818,1399,818,1401,1403],{},[1325,1391,1392],{"style":1329},"$CSVs"," = ",[1325,1395,1396],{"style":1329},"Import-Csv",[1325,1398,1367],{"style":1349},[1325,1400,1330],{"style":1329},[1325,1402,1372],{"style":1349}," \";\"",[591,1405],{},[1325,1407,1408,1357,1410,1413],{},[1325,1409,1392],{"style":1329},[1325,1411,1412],{"style":1329},"Group-Object"," Caller",[591,1415],{},[1325,1417,1418,1357,1420,1422],{},[1325,1419,1392],{"style":1329},[1325,1421,1412],{"style":1329}," CmdletName",[526,1424,1425],{},"AD 권한이 어디에 필요할지 파악하기 위해 CSV를 분석하세요. 필요하다면 Exchange 관련 그룹을 모두 전용 OU로 옮겨 최적화할 수 있습니다.",[700,1427,1429],{"id":1428},"split-permissions-모델-활성화","Split Permissions 모델 활성화",[526,1431,1432,1433,1437],{},"다음 문서에서 Microsoft의 지침 **\"Switch to Active Directory split permissions\"**를 따르세요:\n",[583,1434,690],{"href":1435,"rel":1436},"https://learn.microsoft.com/en-us/exchange/configure-exchange-server-for-split-permissions",[587],[862,1438,1439],{},"(RBAC split permissions가 아닙니다)",[526,1441,1442,1443,1446],{},"요컨대 이 작업은 ",[746,1444,1445],{},"\"Exchange Windows Permissions\""," 그룹의 위험한 권한을 제거하고, Exchange를 그룹 구성원에서도 제외합니다.",[1322,1448,1449],{},[1325,1450,1451,818,1454,818,1457,818,1460],{},[1325,1452,1453],{"style":1329},"Setup.exe",[1325,1455,1456],{"style":1349},"/IAcceptExchangeServerLicenseTerms_DiagnosticDataOFF",[1325,1458,1459],{"style":1349},"/PrepareAD",[1325,1461,1462],{"style":1349},"/ActiveDirectorySplitPermissions:true",[1176,1464,1466,1467,1469,1470,1472],{"style":1465},"background:#f4f4f4; border-left:4px solid var(--color-gk-petrol); border-radius:0 6px 6px 0; padding:0.75rem 1rem; margin:1rem 0; font-size:0.88rem; color:#000520;","\n  ",[746,1468,1282],{}," 되돌리려면 ",[716,1471,821],{},"를 사용하면 됩니다.\n",[558,1474,825],{"id":824},[526,1476,1477],{},"사용자 지정 AD 그룹을 만들고 Exchange 서버를 구성원으로 추가합니다.",[1322,1479,1480,1486,1488,818,1491,1494,1495,1498,1499,1502,1503,818,1505,818,1508,1511,1512,1514,1494,1517,1520,1521],{},[1325,1481,1482],{},[1325,1483,1485],{"style":1484},"color:var(--color-black-40)","# adjust OU Path first!",[591,1487],{},[1325,1489,1490],{"style":1329},"New-ADGroup",[1325,1492,1493],{"style":1349},"-Name"," \"AD_Custom Exchange Split permissions replacement\" ",[1325,1496,1497],{"style":1349},"-GroupCategory"," Security ",[1325,1500,1501],{"style":1349},"-GroupScope"," DomainLocal ",[1325,1504,1367],{"style":1349},[746,1506,1507],{},"\"OU=Rights,OU=Groups,OU=T1,OU=_ADM,$((Get-ADDomain).DistinguishedName)\"",[1325,1509,1510],{"style":1349},"-Description"," \"replaces the permissions lost by split permissions on relevant OUs\"",[591,1513],{},[1325,1515,1516],{"style":1329},"Add-ADGroupMember",[1325,1518,1519],{"style":1349},"-Members"," \"Exchange Trusted Subsystem\"\n",[1325,1522,1523],{"style":1484},"# reboot Exchange servers for permissions via group to work",[526,1525,1526],{},"저는 사용 사례별로 AD 권한 위임을 쉽게 할 수 있도록 스크립트를 만들었습니다.",[855,1528,1529],{},[526,1530,1531,1532,869],{},"이 권한이 없으면 Exchange 서버는 AD로부터 ",[716,1533,868],{},[526,1535,874,1536,1539],{},[583,1537,879],{"href":877,"rel":1538},[587],"을 다운로드하세요.",[526,1541,1542],{},"다음 PermissionType을 부여할 수 있습니다:",[526,1544,1546,1548,895,1550,1552],{"style":1545},"background:#f5f5f5;padding:0.5rem 1rem;margin:0.25rem 0;border-left:3px solid #d8d8d8;",[746,1547,890],{},[591,1549],{},[591,1551],{},[1553,1554,1555],"small",{},"Exchange cmdlet: `New-Mailbox`, `New-RemoteMailbox`, `New-MailUser`, `New-MailContact` 및 이에 대응하는 `Remove-*`",[526,1557,1559,1561,908,1563,1565],{"style":1558},"background:#f5f5f5;padding:0.5rem 1rem;margin:0.25rem 0;border-left:3px solid #d8d8d8",[746,1560,903],{},[591,1562],{},[591,1564],{},[1553,1566,1567,1568,1570],{},"Exchange cmdlet: `New-DistributionGroup`, `Remove-DistributionGroup`, `Add-DistributionGroupMember`, `Update-DistributionGroupMember`, `Remove-DistributionGroupMember`",[591,1569],{},"또한: 사용자가 EAC를 통해 자신이 소유한 DistributionGroup을 관리",[526,1572,1573,1575,928,1577,1579],{"style":1558},[746,1574,923],{},[591,1576],{},[591,1578],{},[1553,1580,1581],{},"Exchange cmdlet: `Add-ADPermission`",[526,1583,1584,1586,941,1588,1590],{"style":1558},[746,1585,936],{},[591,1587],{},[591,1589],{},[1553,1591,1581],{},[526,1593,1594],{},[746,1595,947],{},[1322,1597,1598,818,1600,1603,1604,1606,1607,1610,1611,1614,1616,818,1618,1620,1621,1623,1624,1610,1626,818,1628,1620,1630,1632,1633,1610,1635,818,1637,1639,1640,1642,1643,1610,1645,818,1647,1639,1649,1651,1652,1610],{},[1325,1599,879],{"style":1329},[1325,1601,1602],{"style":1349},"-TargetOU"," \u003COU> ",[1325,1605,963],{"style":1349}," \u003CGroupManage|UserSendAs|GroupSendAs|CreateUserAndContact> ",[1325,1608,1609],{"style":1349},"-Trustee"," \"AD_Custom Exchange Split permissions replacement\"\n",[1325,1612,1613],{"style":1484},"# For example",[591,1615],{},[1325,1617,879],{"style":1329},[1325,1619,1602],{"style":1349}," \"OU=ExchangeGroups,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" ",[1325,1622,963],{"style":1349}," GroupManage ",[1325,1625,1609],{"style":1349},[1325,1627,879],{"style":1329},[1325,1629,1602],{"style":1349},[1325,1631,963],{"style":1349}," GroupSendAs ",[1325,1634,1609],{"style":1349},[1325,1636,879],{"style":1329},[1325,1638,1602],{"style":1349}," \"OU=Users,OU=HQ,OU=Alderaan,$((Get-ADDomain).DistinguishedName)\" ",[1325,1641,963],{"style":1349}," UserSendAs ",[1325,1644,1609],{"style":1349},[1325,1646,879],{"style":1329},[1325,1648,1602],{"style":1349},[1325,1650,963],{"style":1349}," CreateUserAndContact ",[1325,1653,1609],{"style":1349},[558,1655,1024],{"id":1023},[526,1657,1658],{},[746,1659,1660],{},"Add-DistributionGroupMember 및 Remove-DistributionGroupMember cmdlet에서 -BypassSecurityGroupManagerCheck 매개변수 다시 활성화:",[1322,1662,1663],{},[1325,1664,1665,818,1668,1670,1671,1674,1675,1677,1678,1680],{},[1325,1666,1667],{"style":1329},"New-RoleGroup",[1325,1669,1493],{"style":1349}," \"SplitPermission Security Group Creation and Membership\" ",[1325,1672,1673],{"style":1349},"-Roles"," \"Security Group Creation and Membership\" ",[1325,1676,1519],{"style":1349}," \"Organization Management\",\"Recipient Management\" ",[1325,1679,1510],{"style":1349}," \"Brings back -BypassSecurityGroupManagerCheck to Add-DistributionGroupMember, but also needs AD ACL for Exchange Server on target DLs\"",[855,1682,1683],{},[526,1684,1685,1687],{},[746,1686,1282],{}," 그렇지 않으면 “-BypassSecurityGroupManagerCheck parameter is not available” 또는 “You don't have sufficient permissions. This operation can only be performed by a manager of the group” 오류가 발생합니다.",[526,1689,1690,1692,1695,1697],{},[591,1691],{},[746,1693,1694],{},"필요한 매개변수와 함께 New-Mailbox, New-RemoteMailbox, New-MailContact, Remove-... cmdlet 다시 활성화:",[591,1696],{},[1322,1698,1699,818,1701,1703,1704,1706,1707,1677,1709,1711],{},[1325,1700,1667],{"style":1329},[1325,1702,1493],{"style":1349}," \"SplitPermission Mail Recipient Creation\" ",[1325,1705,1673],{"style":1349}," \"Mail Recipient Creation\" ",[1325,1708,1519],{"style":1349},[1325,1710,1510],{"style":1349}," \"Brings back New-Mailbox, New-RemoteMailbox, New-MailUser, New-MailContact and matching Remove-... cmdlets, but additionally Exchange needs AD ACL for Exchange Server on target OUs\"",[700,1713,1060],{"id":1060},[526,1715,1716],{},"이 가이드가 더 많은 조직이 Exchange를 통한 침해로부터 Active Directory를 보호하는 중요한 걸음을 내딛는 데 도움이 되길 바랍니다. 여러 고객사에 Exchange AD Split Permissions 모델을 구현한 제 경험상 아무런 문제도 겪지 않았고, 도입 과정도 순조로웠습니다.",[526,1718,1719],{},"또한 Microsoft가 현재의 전부 아니면 전무(all-or-nothing) 방식 대신 이 정도의 세분화를 달성할 수 있는 네이티브 OU 기반 접근 방식을 도입하기를 바랍니다. 그렇게 되면 폭넓은 도입이 훨씬 쉬워질 것입니다.",[526,1721,1722,1723,1075,1726,1729],{},"AD Tiering에 관한 참고: Exchange 서버에 Domain Admin이나 그 밖의 Tier 0 계정으로 로그온하지 마세요. Exchange 서버는 Tier 1으로 취급하고, 가능한 한 빨리 AD Tiering을 구현하세요. 첫 단계로 AD 보안 상태를 평가하고 컨트롤 경로 노출을 식별하기 위해 ",[583,1724,1074],{"href":1072,"rel":1725},[587],[583,1727,1080],{"href":1078,"rel":1728},[587],"를 사용할 것을 권장합니다.",[1083,1731,1085],{},{"title":530,"searchDepth":531,"depth":531,"links":1733},[1734,1735,1736,1737,1740,1744],{"id":1139,"depth":531,"text":1140},{"id":1182,"depth":531,"text":1183},{"id":1266,"depth":531,"text":1267},{"id":1306,"depth":531,"text":1307,"children":1738},[1739],{"id":752,"depth":1089,"text":753},{"id":1428,"depth":531,"text":1429,"children":1741},[1742,1743],{"id":824,"depth":1089,"text":825},{"id":1023,"depth":1089,"text":1024},{"id":1060,"depth":531,"text":1060},{"lang":1106,"seoTitle":1746,"titleClass":1108,"date":1747,"blogtitlepic":1748,"socialimg":1749,"customExcerpt":1750,"keywords":1751,"scripts":1752,"asideNav":1753,"maxContent":325,"published":325},"Exchange AD Split Permissions: 최소 권한으로 Active Directory 보호하기","2026-03-01","head-exchange-ad-split-permissions","/blog/heads/head-exchange-ad-split-permissions.jpg","클라우드로 사서함을 완전히 마이그레이션한 조직조차도 여전히 온프레미스 Exchange 서버를 운영하는 경우가 많으며, 이는 Active Directory에 대한 과소평가된 보안 위험을 함께 가져옵니다. “AD Split Permissions” 모델은 공격자가 전체 도메인 장악에 악용할 수 있는 Exchange의 광범위한 AD 권한을 제거합니다. 지금까지 이 모델의 도입은 관리자에게 강제되는 프로세스 변경 때문에 대부분 실패해 왔습니다. 이 글에서는 바로 그 장벽을 우아하게 넘는 방법을 소개합니다. 관련 OU에만 선택적으로 잃어버린 AD 권한을 다시 부여하는 스크립트를 통해, 익숙한 관리자 워크플로를 유지하면서도 완전한 보안 이점을 달성하는 방법입니다.","Exchange Server, Active Directory, AD split permissions, RBAC, Exchange 권한, AdminSDHolder, 최소 권한, AD ACL, PowerShell",{"slick":325,"form":325},{"menuItems":1754},[1755,1757,1759,1761,1763],{"href":1756,"text":1140},"#tldr-단점을-없앤다면",{"href":1758,"text":1183},"#왜-지금-중요한가",{"href":1760,"text":1267},"#그런데-왜-아무도-하지-않을까",{"href":1762,"text":1307},"#후회-없는-방법을-알려드립니다",{"href":1126,"text":1060},"/posts/2026-03-01-exchange-ad-split-permissions-hardening",{"title":1133,"description":530},"posts/2026-03-01-exchange-ad-split-permissions-hardening","3xunEa4D5NvoQvuu19U82h8wKzEZKzj5FMJixE9RQbA",[],{"id":1770,"extension":1771,"meta":1772,"stem":8,"__hash__":1779},"authors_data/authors.json","json",{"Thorsten Kunzi":1773},{"display_name":521,"avatar":1774,"permalink":1775,"twitter":1776,"linkedin":1777,"imageOffsetTop":1778},"people/author-thorsten-kunzi.png","/authors/thorsten-kunzi","glueckkanjagab","company/glueckkanja-gab","72%","1csawlkJxRljy93GTOnXEkwLqAv9Lcj-apxRvoodAOY",1791383993855]