Infra/MS

[AD] Active Directory ๊ฐœ๋…์— ๋Œ€ํ•ด ์ •๋ฆฌํ•œ ๊ธ€

์˜ค๋ฌ˜ 2025. 1. 2. 22:43

AD์— ๋Œ€ํ•ด ์ •๋ฆฌํ•œ ๊ธ€์ž…๋‹ˆ๋‹ค.

 

๋””๋ ‰ํ„ฐ๋ฆฌ ์„œ๋น„์Šค๋ž€

Active Directory๋Š” MS์—์„œ ๋งŒ๋“  ์œˆ๋„์šฐ์šฉ LDAP ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•˜๋Š” ๋””๋ ‰ํ„ฐ๋ฆฌ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.

์—ฌ๊ธฐ์„œ ๋””๋ ‰ํ„ฐ๋ฆฌ ์„œ๋น„์Šค๋Š”  ์กฐ์ง์˜ ๋„คํŠธ์›Œํฌ ๋ฆฌ์†Œ์Šค(์‚ฌ์šฉ์ž, ๊ทธ๋ฃน, ์ปดํ“จํ„ฐ, ํ”„๋ฆฐํŠธ ๋“ฑ)๋ฅผ ์ €์žฅํ•˜๊ณ  ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ์ž๊ฐ€ ๋ฆฌ์†Œ์Šค์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค.

DB์ฒ˜๋Ÿผ Read ๊ธฐ๋Šฅ์ด ์ตœ์ ํ™” ๋˜์–ด ์žˆ์œผ๋ฉฐ, ๋””๋ ‰ํ„ฐ๋ฆฌ ์•ˆ ๊ฐœ์ฒด๋“ค์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์ฟผ๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ด ๋•Œ ๋””๋ ‰ํ„ฐ๋ฆฌ ์•ˆ์— ์žˆ๋Š” ๋ฐ์ดํ„ฐ๋Š” ํ™•์žฅ๋˜๊ฑฐ๋‚˜ ์ˆ˜์ •์ด ๊ฐ€๋Šฅํ•˜๊ณ , ๋””๋ ‰ํ„ฐ๋ฆฌ ์„œ๋ฒ„๊ฐ„์— ๋ณต์ œ๋ฉ๋‹ˆ๋‹ค.

 

 

Active Directory

์šฉ์–ด์˜ ๊ฒฝ์šฐ ์˜์–ด ๋ฌธ์„œ๋ฅผ ํ•œ๊ธ€๋กœ ์ •๋ฆฌํ•œ ๊ฒƒ์ด๋ผ์„œ ํ˜ผ๋™๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Object = ๊ฐœ์ฒด = ๊ฐ์ฒด

 

์ •์˜

 

  • ๋„คํŠธ์›Œํฌ์˜ ๊ฐœ์ฒด ๊ด€๋ จ ์ •๋ณด๊ฐ€ ์ €์žฅ๋œ ๊ณ„์ธต ๊ตฌ์กฐ๋ฅผ ๊ฐ€์ง„ ๋””๋ ‰ํ„ฐ๋ฆฌ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.
    ์˜ˆ: ADDS(Active Directory Domain Services)๋Š” ๋””๋ ‰ํ„ฐ๋ฆฌ ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๊ณ , ๋„คํŠธ์›Œํฌ ์‚ฌ์šฉ์ž ๋ฐ ๊ด€๋ฆฌ์ž๊ฐ€ ์ด ๋ฐ์ดํ„ฐ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ๋Šฅ

  • ์‚ฌ์šฉ์ž ๊ณ„์ • ์ •๋ณด(์ด๋ฆ„, ๋น„๋ฐ€๋ฒˆํ˜ธ, ์ „ํ™”๋ฒˆํ˜ธ ๋“ฑ) ์ €์žฅ
  • ๋‹ค๋ฅธ ๋„คํŠธ์›Œํฌ์—์„œ ๊ถŒํ•œ์ด ์žˆ๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ํŠน์ • ์ •๋ณด์— ์•ก์„ธ์Šค ๊ฐ€๋Šฅ
  • ๋…ผ๋ฆฌ์ ์ด๊ณ  ๊ณ„์ธต์ ์ธ ๋””๋ ‰ํ„ฐ๋ฆฌ ์ •๋ณด ๊ตฌ์„ฑ์„ ์ œ๊ณต

 

๊ตฌ์„ฑ ์š”์†Œ

๋ฐ์ดํ„ฐ ์ €์žฅ์†Œ

  • Active Directory ๊ฐœ์ฒด ์ •๋ณด ์ €์žฅ.
  • ๊ฐœ์ฒด
    • ์„œ๋ฒ„
    • ๋ณผ๋ฅจ
    • ํ”„๋ฆฐํ„ฐ
    • ๋„คํŠธ์›Œํฌ ์‚ฌ์šฉ์ž ๋ฐ ์ปดํ“จํ„ฐ ๊ณ„์ •

์Šคํ‚ค๋งˆ

  • ๋””๋ ‰ํ„ฐ๋ฆฌ ์•ˆ์— ์–ด๋–ค ์˜ค๋ธŒ์ ํŠธ๊ฐ€ ํฌํ•จ๋  ์ˆ˜ ์žˆ๋Š”์ง€๋ž‘ ๊ทธ ์˜ค๋ธŒ์ ํŠธ๊ฐ€ ์–ด๋–ค ๋ฐ์ดํ„ฐ ์ €์žฅํ•  ์ˆ˜ ์žˆ๋Š”์ง€๋ฅผ ์ •์˜ํ•ฉ๋‹ˆ๋‹ค.
  • ์Šคํ‚ค๋งˆ์˜ ๊ตฌ์„ฑ ์š”์†Œ๋Š” ํด๋ž˜์Šค, ์†์„ฑ 2๊ฐ€์ง€๊ฐ€ ์ฃผ์š” ๊ตฌ์„ฑ ์š”์†Œ์ž…๋‹ˆ๋‹ค. ์ด ๋‘˜์˜ ๊ทœ์น™์„ ํ†ตํ•ด ๋””๋ ‰ํ„ฐ๋ฆฌ ๊ตฌ์กฐ๊ฐ€ ํ˜•์ƒ๋œ๋‹ค๊ณ  ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ชจ๋“  ์Šคํ‚ค๋งˆ ํด๋ž˜์Šค์™€ ์†์„ฑ์€ ๊ฐ๊ฐ classSchema์™€ attributeSchema ์˜ค๋ธŒ์ ํŠธ๋กœ ์ •์˜๋ฉ๋‹ˆ๋‹ค.

 

ํด๋ž˜์Šค

ํด๋ž˜์Šค๋Š” ์˜ค๋ธŒ์ ํŠธ๊ฐ€ ์–ด๋–ค ์†์„ฑ์„ ๊ฐ€์งˆ ์ˆ˜ ์žˆ๋Š”์ง€์— ๋Œ€ํ•œ ์œ ํ˜•์„ ๊ฒฐ์ •ํ•ฉ๋‹ˆ๋‹ค.

classSchema ์˜ค๋ธŒ์ ํŠธ๋Š” ์Šคํ‚ค๋งˆ์—์„œ ํด๋ž˜์Šค๋ฅผ ์ •์˜ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. ์ด๋Š” ํ•ด๋‹น ํด๋ž˜์Šค์˜ ๋””๋ ‰ํ„ฐ๋ฆฌ ์˜ค๋ธŒ์ ํŠธ๋ฅผ ์ƒ์„ฑํ•˜๊ธฐ ์œ„ํ•œ ํ…œํ”Œ๋ฆฟ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

 

classSchema ์˜ค๋ธŒ์ ํŠธ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ •๋ณด๋ฅผ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค

  • ํด๋ž˜์Šค ์œ ํ˜•: ๊ตฌ์กฐ์ (structural), ์ถ”์ƒ์ (abstract), ๋ณด์กฐ(auxiliary)
  • ์ผ๋ฐ˜ ์ด๋ฆ„๊ณผ Lightweight Directory Access Protocol(LDAP) ํ‘œ์‹œ ์ด๋ฆ„
  • ์˜ค๋ธŒ์ ํŠธ ์ธ์Šคํ„ด์Šค์— ํ•„์š”ํ•œ "ํ•„์ˆ˜ ํฌํ•จ" ๋ฐ "์„ ํƒ ํฌํ•จ" ์†์„ฑ ๋ฆฌ์ŠคํŠธ
  • ์ƒ๋Œ€์  ๊ณ ์œ  ์ด๋ฆ„(Relative Distinguished Name, RDN) ์†์„ฑ
  • ๊ฐ€๋Šฅํ•œ ๋ถ€๋ชจ ํด๋ž˜์Šค ๋ฆฌ์ŠคํŠธ

์Šคํ‚ค๋งˆ์—๋Š” ์„ธ ๊ฐ€์ง€ ํด๋ž˜์Šค ์œ ํ˜•์ด ์กด์žฌํ•ฉ๋‹ˆ๋‹ค

๊ตฌ์กฐ์ (Structural) ๋””๋ ‰ํ„ฐ๋ฆฌ์—์„œ ์˜ค๋ธŒ์ ํŠธ(์‚ฌ์šฉ์ž, ์„œ๋ฒ„ ๋“ฑ)๋ฅผ ์ธ์Šคํ„ด์Šคํ™”ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋จ
์ถ”์ƒ์ (Abstract) ๊ตฌ์กฐ์  ํด๋ž˜์Šค๋ฅผ ํŒŒ์ƒ์‹œํ‚ค๊ธฐ ์œ„ํ•œ ํ…œํ”Œ๋ฆฟ ์ œ๊ณต
๋ณด์กฐ์ (Auxiliary) ๊ตฌ์กฐ์  ๋ฐ ์ถ”์ƒ์  ํด๋ž˜์Šค์— ํฌํ•จ๋  ์ˆ˜ ์žˆ๋Š” ์‚ฌ์ „ ์ •์˜๋œ ์†์„ฑ ๋ฆฌ์ŠคํŠธ ํฌํ•จ

 

์†์„ฑ(Attribute)

 

  • ์†์„ฑ์€ ์˜ค๋ธŒ์ ํŠธ๊ฐ€ ์ €์žฅํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐ์ดํ„ฐ์˜ ๋‹จ์œ„์ž…๋‹ˆ๋‹ค.
    • ์˜ˆ: ์‚ฌ์šฉ์ž ํด๋ž˜์Šค์˜ ์†์„ฑ์œผ๋กœ "์ด๋ฆ„(Name)", "์ง๊ธ‰(Title)", "์ด๋ฉ”์ผ(Email)"์ด ์žˆ์„ ์ˆ˜ ์žˆ์Œ.
  • ์†์„ฑ์€ ๊ฐ ๋ฐ์ดํ„ฐ๊ฐ€ ๊ฐ€์งˆ ์ˆ˜ ์žˆ๋Š” ํ˜•์‹, ๊ฐ’์˜ ์ œ์•ฝ ์กฐ๊ฑด ๋“ฑ์„ ์ •์˜ํ•ฉ๋‹ˆ๋‹ค.
    • ๋‹จ์ผ ๊ฐ’ ๋˜๋Š” ๋‹ค์ค‘ ๊ฐ’, ์ตœ์†Œ/์ตœ๋Œ€ ๊ธธ์ด, ํ—ˆ์šฉ๋˜๋Š” ๋ฐ์ดํ„ฐ ์œ ํ˜•(ํ…์ŠคํŠธ, ์ˆซ์ž ๋“ฑ) ๋“ฑ์„ ํฌํ•จ.

์†์„ฑ์€ attributeSchema ์˜ค๋ธŒ์ ํŠธ๋กœ ์ •์˜๋ฉ๋‹ˆ๋‹ค.

 

  • ์ผ๋ฐ˜ ์ด๋ฆ„๊ณผ LDAP ํ‘œ์‹œ ์ด๋ฆ„
  • ๊ตฌ๋ฌธ ๊ทœ์น™
  • ๋ฐ์ดํ„ฐ ์ œ์•ฝ ์กฐ๊ฑด: ๋‹จ์ผ ๊ฐ’(single-valued) ๋˜๋Š” ๋‹ค์ค‘ ๊ฐ’(multivalued), ์ตœ์†Œ ๋ฐ ์ตœ๋Œ€ ๊ฐ’
  • ์†์„ฑ์˜ ์ธ๋ฑ์‹ฑ ์—ฌ๋ถ€ ๋ฐ ๋ฐฉ๋ฒ•

๋‹จ์ผ ๊ฐ’๊ณผ ๋‹ค์ค‘ ๊ฐ’ ์†์„ฑ

  • ๋‹จ์ผ ๊ฐ’ ์†์„ฑ: ์˜ค๋ธŒ์ ํŠธ ์ธ์Šคํ„ด์Šค๋Š” ํ•˜๋‚˜์˜ ๊ฐ’๋งŒ ๊ฐ€์งˆ ์ˆ˜ ์žˆ์Œ
  • ๋‹ค์ค‘ ๊ฐ’ ์†์„ฑ: ์˜ค๋ธŒ์ ํŠธ ์ธ์Šคํ„ด์Šค๋Š” ๋™์ผํ•œ ๊ตฌ๋ฌธ์˜ ์—ฌ๋Ÿฌ ๊ฐ’์„ ๊ฐ€์งˆ ์ˆ˜ ์žˆ์Œ
    • ๋‹ค์ค‘ ๊ฐ’ ์†์„ฑ์€ ํฌํ•จ๋œ ๊ฐ’์˜ ์ˆœ์„œ๋ฅผ ์ €์žฅํ•˜์ง€ ์•Š์Œ
    • ๋‹ค์ค‘ ๊ฐ’ ์†์„ฑ์˜ ๊ฐ ๊ฐ’์€ ๊ณ ์œ ํ•ด์•ผ ํ•จ

์ธ๋ฑ์‹ฑ๋œ ์†์„ฑ

  • ๋‹จ์ผ ๊ฐ’ ๋ฐ ๋‹ค์ค‘ ๊ฐ’ ์†์„ฑ ๋ชจ๋‘ ์ธ๋ฑ์‹ฑ๋  ์ˆ˜ ์žˆ์Œ
  • ์ธ๋ฑ์‹ฑ ์žฅ์ : ์†์„ฑ์— ๋Œ€ํ•œ ์ฟผ๋ฆฌ ์„ฑ๋Šฅ ํ–ฅ์ƒ. ์™€์ผ๋“œ์นด๋“œ(*)๋ฅผ ๊ฒ€์ƒ‰ ๋ฌธ์ž์—ด์˜ ์ ‘๋‘์‚ฌ๋‚˜ ์ ‘๋ฏธ์‚ฌ๋กœ ์‚ฌ์šฉ ๊ฐ€๋Šฅ
  • ์ธ๋ฑ์‹ฑ ๋‹จ์ : ๋ณต์ œ, ์˜ค๋ธŒ์ ํŠธ ์ƒ์„ฑ ์‹œ๊ฐ„ ๋ฐ ๋””๋ ‰ํ„ฐ๋ฆฌ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํฌ๊ธฐ์— ๋ถ€์ •์  ์˜ํ–ฅ์„ ๋ฏธ์น˜๋ฏ€๋กœ ์ž์ฃผ ์‚ฌ์šฉ๋˜๋Š” ์†์„ฑ๋งŒ ์ธ๋ฑ์‹ฑํ•˜๋Š” ๊ฒƒ์„ ๊ถŒ์žฅ

 

๊ธ€๋กœ๋ฒŒ ์นดํƒˆ๋กœ๊ทธ

 

  • ๊ธ€๋กœ๋ฒŒ ์นดํƒˆ๋กœ๊ทธ๋Š” ๋””๋ ‰ํ„ฐ๋ฆฌ์˜ ๋ชจ๋“  ๋ช…๋ช… ์ปจํ…์ŠคํŠธ์˜ ๋ถ€๋ถ„ ๋ณต์ œ๋ณธ(replica)์„ ํฌํ•จํ•˜์—ฌ ์‚ฌ์šฉ์ž์™€ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด Active Directory ๋„๋ฉ”์ธ ํŠธ๋ฆฌ์—์„œ ๊ฐœ์ฒด๋ฅผ ๊ฒ€์ƒ‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ์ง€์›ํ•˜๋Š” ๊ตฌ์„ฑ ์š”์†Œ์ž…๋‹ˆ๋‹ค.
  • ์—ญํ• 
    • ๋””๋ ‰ํ„ฐ๋ฆฌ์—์„œ ๋Œ€์ƒ ๊ฐœ์ฒด๋ฅผ ๋น ๋ฅด๊ฒŒ ์ฐพ์„ ์ˆ˜ ์žˆ๋„๋ก ๋•์Šต๋‹ˆ๋‹ค.
    • ํŠน์ • ๋„๋ฉ”์ธ์— ๊ตญํ•œ๋˜์ง€ ์•Š๊ณ  ์ „์ฒด Active Directory ๋„๋ฉ”์ธ ํŠธ๋ฆฌ๋ฅผ ๊ฒ€์ƒ‰ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค.

Active Directory Domain Services์—์„œ ์‹คํ–‰๋˜๋Š” ๋„๋ฉ”์ธ์€ ์—ฌ๋Ÿฌ ํŒŒํ‹ฐ์…˜(partition) ๋˜๋Š” ๋„ค์ž„ ์ปจํ…์ŠคํŠธ(naming context)๋กœ ๊ตฌ์„ฑ๋ฉ๋‹ˆ๋‹ค.

๊ฐ ์˜ค๋ธŒ์ ํŠธ์˜ DN(Distinguished Name)์—๋Š” ํ•ด๋‹น ์˜ค๋ธŒ์ ํŠธ๋ฅผ ํฌํ•จํ•˜๋Š” ํŒŒํ‹ฐ์…˜์˜ ๋ณต์ œ๋ณธ(replica)์„ ์ฐพ๋Š” ๋ฐ ์ถฉ๋ถ„ํ•œ ์ •๋ณด๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์‚ฌ์šฉ์ž๋‚˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์€ ๋Œ€์ƒ ์˜ค๋ธŒ์ ํŠธ์˜ DN์ด๋‚˜ ํ•ด๋‹น ์˜ค๋ธŒ์ ํŠธ๋ฅผ ํฌํ•จํ•˜๋Š” ํŒŒํ‹ฐ์…˜์„ ๋ชจ๋ฅด๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Šต๋‹ˆ๋‹ค.

 

๊ธ€๋กœ๋ฒŒ ์นดํƒˆ๋กœ๊ทธ๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ๋Œ€์ƒ ์˜ค๋ธŒ์ ํŠธ์˜ 1~2๊ฐœ ์†์„ฑ๊ฐ’๋งŒ ์•Œ์•„๋„ AD์˜ ๋„๋ฉ”์ธ ํŠธ๋ฆฌ์—์„œ ํ•ด๋‹น ์˜ค๋ธŒ์ ํŠธ๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ๊ฒŒ ๋•๋Š” ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค.

 

 

์ฟผ๋ฆฌ ๋ฐ ์ธ๋ฑ์Šค ๋ฉ”์ปค๋‹ˆ์ฆ˜

  • ๋„คํŠธ์›Œํฌ ์‚ฌ์šฉ์ž๋‚˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ๊ฐ์ฒด์™€ ์†์„ฑ์„ ๊ฒ€์ƒ‰ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค.

๋ณต์ œ ์„œ๋น„์Šค

๋””๋ ‰ํ„ฐ๋ฆฌ ๋ฐ์ดํ„ฐ๋ฅผ ๋„คํŠธ์›Œํฌ์— ๋ฐฐํฌํ•ฉ๋‹ˆ๋‹ค. ๋„๋ฉ”์ธ์˜ ๋ชจ๋“  ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ๊ฐ€ ๋ณต์ œ์— ์ฐธ์—ฌํ•˜๋ฉฐ ๋„๋ฉ”์ธ ๋””๋ ‰ํ„ฐ๋ฆฌ ์ •๋ณด์˜ ์ „์ฒด ๋ณต์‚ฌ๋ณธ ๋ณด์œ ํ•˜๊ณ  ์žˆ์œผ๋ฉฐ, ๋ฐ์ดํ„ฐ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ๋ชจ๋“  ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ์— ๋ณต์ œํ•ฉ๋‹ˆ๋‹ค.

 

๋ณต์ œ ๋งค์ปค๋‹ˆ์ฆ˜์€ ์•„๋ž˜์™€ ๊ฐ™์Šต๋‹ˆ๋‹ค.

 

1. ์—ฐ๊ฒฐ ๊ฐœ์ฒด(Connection Object)

  • ์ •์˜: ์›๋ณธ ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ์—์„œ ๋Œ€์ƒ ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ๋กœ์˜ ๋ณต์ œ ์—ฐ๊ฒฐ์„ ๋‚˜ํƒ€๋‚ด๋Š” Active Directory ๊ฐœ์ฒด์ž…๋‹ˆ๋‹ค.
  • ํŠน์ง•:
    • ๋Œ€์ƒ ์„œ๋ฒ„์˜ NTDS ์„ค์ •(NTDS Settings) ๊ฐœ์ฒด ํ•˜์œ„์— ์œ„์น˜ํ•ฉ๋‹ˆ๋‹ค.
    • ๋ณต์ œ ์›๋ณธ ์„œ๋ฒ„๋ฅผ ์‹๋ณ„ํ•˜๊ณ , ๋ณต์ œ ์ผ์ • ๋ฐ ์ „์†ก ๋ฐฉ๋ฒ•์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.
  • ์ƒ์„ฑ:
    • KCC(์ง€์‹ ์ผ๊ด€์„ฑ ๊ฒ€์‚ฌ๊ธฐ)์— ์˜ํ•ด ์ž๋™ ์ƒ์„ฑ๋˜์ง€๋งŒ, ์ˆ˜๋™์œผ๋กœ๋„ ์ƒ์„ฑ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

2. KCC(์ง€์‹ ์ผ๊ด€์„ฑ ๊ฒ€์‚ฌ๊ธฐ)

  • ์ •์˜: ๋ชจ๋“  ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ์—์„œ ์‹คํ–‰๋˜๋ฉฐ, Active Directory ํฌ๋ฆฌ์ŠคํŠธ์˜ ๋ณต์ œ ํ† ํด๋กœ์ง€๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๋‚ด์žฅ ํ”„๋กœ์„ธ์Šค์ž…๋‹ˆ๋‹ค.
  • ๊ธฐ๋Šฅ:
    • ์‚ฌ์ดํŠธ ๋‚ด(Intrasite) ๋ฐ ์‚ฌ์ดํŠธ ๊ฐ„(Intersite) ๋ณต์ œ ํ† ํด๋กœ์ง€๋ฅผ ์ƒ์„ฑํ•˜๊ณ  ๋™์ ์œผ๋กœ ์กฐ์ •ํ•ฉ๋‹ˆ๋‹ค.
    • ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ์˜ ์ถ”๊ฐ€, ์ œ๊ฑฐ, ์ด๋™, ๋น„์šฉ ๋ฐ ์ผ์ • ๋ณ€๊ฒฝ, ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ์˜ ์ƒํƒœ ๋ณ€ํ™” ๋“ฑ์„ ๋ฐ˜์˜ํ•˜์—ฌ ๋ณต์ œ ํ† ํด๋กœ์ง€๋ฅผ ์กฐ์ •ํ•ฉ๋‹ˆ๋‹ค.

3. ์žฅ์•  ์กฐ์น˜(Failover) ๊ธฐ๋Šฅ

  • ์„ค๋ช…: ๋„คํŠธ์›Œํฌ ์˜ค๋ฅ˜๋‚˜ ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ์˜ ์˜คํ”„๋ผ์ธ ์ƒํƒœ๋ฅผ ์šฐํšŒํ•˜์—ฌ ๋ณต์ œ๊ฐ€ ์ง€์†๋˜๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.
  • ๋™์ž‘:
    • KCC๋Š” ์ฃผ๊ธฐ์ ์œผ๋กœ ์‹คํ–‰๋˜์–ด ๋ณต์ œ ํ† ํด๋กœ์ง€๋ฅผ ํ‰๊ฐ€ํ•˜๊ณ , ํ•„์š” ์‹œ ๋‹ค๋ฅธ ๋ณต์ œ ํŒŒํŠธ๋„ˆ์™€์˜ ์ž„์‹œ ์—ฐ๊ฒฐ์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

4. ์„œ๋ธŒ๋„ท(Subnet)

  • ์ •์˜: ๋…ผ๋ฆฌ์  IP ์ฃผ์†Œ ์ง‘ํ•ฉ์ด ํ• ๋‹น๋œ TCP/IP ๋„คํŠธ์›Œํฌ ์„ธ๊ทธ๋จผํŠธ์ž…๋‹ˆ๋‹ค.
  • ์—ญํ• : ๋„คํŠธ์›Œํฌ์—์„œ ๋ฌผ๋ฆฌ์  ๊ทผ์ ‘์„ฑ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ์ปดํ“จํ„ฐ๋ฅผ ๊ทธ๋ฃนํ™”ํ•˜๋ฉฐ, Active Directory์—์„œ ์ปดํ“จํ„ฐ๋ฅผ ์‚ฌ์ดํŠธ์— ๋งคํ•‘ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

5. ์‚ฌ์ดํŠธ(Site)

  • ์ •์˜: ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๊ณ  ๋น ๋ฅธ ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ์„ ์‚ฌ์šฉํ•˜๋Š” ํ•˜๋‚˜ ์ด์ƒ์˜ TCP/IP ์„œ๋ธŒ๋„ท์„ ๋‚˜ํƒ€๋‚ด๋Š” Active Directory ๊ฐœ์ฒด์ž…๋‹ˆ๋‹ค.
  • ๊ธฐ๋Šฅ:
    • Active Directory ์•ก์„ธ์Šค ๋ฐ ๋ณต์ œ๋ฅผ ์ตœ์ ํ™”ํ•˜์—ฌ ๋„คํŠธ์›Œํฌ ์‚ฌ์šฉ์„ ํšจ์œจ์ ์œผ๋กœ ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค.
    • ์‚ฌ์ดํŠธ๋Š” ๋‘˜ ์ด์ƒ์˜ ๋„๋ฉ”์ธ์—์„œ ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ๋ฅผ ํฌํ•จํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ๋„๋ฉ”์ธ์€ ์—ฌ๋Ÿฌ ์‚ฌ์ดํŠธ์— ๊ฑธ์ณ ์žˆ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

6. ์‚ฌ์ดํŠธ ๋งํฌ(Site Link)

  • ์ •์˜: KCC๊ฐ€ Active Directory ๋ณต์ œ ์—ฐ๊ฒฐ์„ ์„ค์ •ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•˜๋Š” ๋…ผ๋ฆฌ์  ๊ฒฝ๋กœ๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š” ๊ฐœ์ฒด์ž…๋‹ˆ๋‹ค.
  • ํŠน์ง•:
    • ์ง€์ •๋œ ์‚ฌ์ดํŠธ ๊ฐ„ ์ „์†ก์„ ํ†ตํ•ด ์ผ์ •ํ•œ ๋น„์šฉ์œผ๋กœ ํ†ต์‹ ํ•  ์ˆ˜ ์žˆ๋Š” ์‚ฌ์ดํŠธ ์ง‘ํ•ฉ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค.
    • ์‚ฌ์ดํŠธ ๋งํฌ๋ฅผ ํ†ตํ•ด ํ•œ ์‚ฌ์ดํŠธ์˜ ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ๊ฐ€ ๋‹ค๋ฅธ ์‚ฌ์ดํŠธ์˜ ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ์™€ ๋””๋ ‰ํ„ฐ๋ฆฌ ๋ณ€๊ฒฝ ๋‚ด์šฉ์„ ๋ณต์ œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

7. ์‚ฌ์ดํŠธ ๋งํฌ ๋ธŒ๋ฆฌ์ง€(Site Link Bridge)

  • ์ •์˜: ์‚ฌ์ดํŠธ ๋งํฌ์˜ ์ง‘ํ•ฉ์„ ๋‚˜ํƒ€๋‚ด๋ฉฐ, ๊ธฐ๋ณธ์ ์œผ๋กœ ๋ชจ๋“  ์‚ฌ์ดํŠธ ๋งํฌ๋Š” ์ „์ด์ (Transitive)์œผ๋กœ ๊ฐ„์ฃผ๋ฉ๋‹ˆ๋‹ค.
  • ๊ธฐ๋Šฅ: ์‚ฌ์ดํŠธ ๋งํฌ ๋ธŒ๋ฆฌ์ง€๋ฅผ ํ†ตํ•ด ๊ฐ„์ ‘์ ์œผ๋กœ ์—ฐ๊ฒฐ๋œ ์‚ฌ์ดํŠธ ๊ฐ„์—๋„ ๋ณต์ œ๊ฐ€ ๊ฐ€๋Šฅํ•˜๋„๋ก ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

8. ๊ธ€๋กœ๋ฒŒ ์นดํƒˆ๋กœ๊ทธ ์„œ๋ฒ„(Global Catalog Server)

  • ์ •์˜: ํฌ๋ฆฌ์ŠคํŠธ ๋‚ด ๋ชจ๋“  ๋„๋ฉ”์ธ์˜ ๋ชจ๋“  ๊ฐœ์ฒด์— ๋Œ€ํ•œ ๋ถ€๋ถ„์ ์ธ ์†์„ฑ ์ง‘ํ•ฉ์„ ์ €์žฅํ•˜๋Š” ๋„๋ฉ”์ธ ์ปจํŠธ๋กค๋Ÿฌ์ž…๋‹ˆ๋‹ค.
  • ์—ญํ• : ์‚ฌ์šฉ์ž์™€ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ๋””๋ ‰ํ„ฐ๋ฆฌ์—์„œ ๊ฐœ์ฒด๋ฅผ ๋น ๋ฅด๊ฒŒ ๊ฒ€์ƒ‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

9. ๋ฒ”์šฉ ๊ทธ๋ฃน ๊ตฌ์„ฑ์› ์ž๊ฒฉ ์บ์‹ฑ(Universal Group Membership Caching)

  • ์„ค๋ช…: ๊ธ€๋กœ๋ฒŒ ์นดํƒˆ๋กœ๊ทธ ์„œ๋ฒ„ ์—†์ด๋„ ์‚ฌ์šฉ์ž ๋กœ๊ทธ์˜จ์„ ์ง€์›ํ•˜๊ธฐ ์œ„ํ•ด ๋ฒ”์šฉ ๊ทธ๋ฃน ๊ตฌ์„ฑ์› ์ž๊ฒฉ ์ •๋ณด๋ฅผ ์บ์‹ฑํ•˜๋Š” ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค.
  • ์žฅ์ : ์›๊ฒฉ ์‚ฌ์ดํŠธ์—์„œ ๊ธ€๋กœ๋ฒŒ ์นดํƒˆ๋กœ๊ทธ ์„œ๋ฒ„์˜ ํ•„์š”์„ฑ์„ ์ค„์—ฌ ๋„คํŠธ์›Œํฌ ํŠธ๋ž˜ํ”ฝ์„ ๊ฐ์†Œ์‹œํ‚ต๋‹ˆ๋‹ค.

 

๋ณด์•ˆ ๋ฐ ๊ด€๋ฆฌ

๋ณด์•ˆ ํ†ตํ•ฉ

  • ๋กœ๊ทธ์˜จ ์ธ์ฆ: ๋””๋ ‰ํ„ฐ๋ฆฌ ๊ฐœ์ฒด์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ์ œ์–ด
  • ๊ด€๋ฆฌ ๊ธฐ๋Šฅ
    • ๋‹จ์ผ ๋„คํŠธ์›Œํฌ ๋กœ๊ทธ์˜จ์œผ๋กœ ๋””๋ ‰ํ„ฐ๋ฆฌ ๋ฐ์ดํ„ฐ ๋ฐ ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ
    • ์ ‘๊ทผ ๊ถŒํ•œ์ด ์žˆ๋Š” ์‚ฌ์šฉ์ž๋Š” ๋„คํŠธ์›Œํฌ์˜ ๋ชจ๋“  ์œ„์น˜์—์„œ ๋ฆฌ์†Œ์Šค ์•ก์„ธ์Šค ๊ฐ€๋Šฅ

์ •์ฑ… ๊ธฐ๋ฐ˜ ๊ด€๋ฆฌ

  • ๋ณต์žกํ•œ ๋„คํŠธ์›Œํฌ๋„ ์‰ฝ๊ฒŒ ๊ด€๋ฆฌ ๊ฐ€๋Šฅ.

์ฐธ๊ณ  ๋ฌธ์„œ

https://learn.microsoft.com/ko-kr/windows-server/identity/ad-ds/get-started/virtual-dc/active-directory-domain-services-overview

 

Active Directory Domain Services ๊ฐœ์š”

์ž์„ธํžˆ ์•Œ์•„๋ณด๊ธฐ: Active Directory Domain Services ๊ฐœ์š”

learn.microsoft.com

https://learn.microsoft.com/ko-kr/previous-versions/windows/it-pro/windows-server-2003/cc739086(v=ws.10)

 

Understanding Schema: Active Directory

Understanding Schema Article 06/06/2011 In this article --> Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server 2003 with SP1, Windows Server 2003 with SP2 Understanding schema This section covers:

learn.microsoft.com

 

https://learn.microsoft.com/ko-kr/previous-versions/windows/it-pro/windows-server-2003/cc781408(v=ws.10)

 

Understanding Active Directory: Active Directory

Understanding Active Directory Article 06/06/2011 In this article --> Applies To: Windows Server 2003, Windows Server 2003 R2, Windows Server 2003 with SP1, Windows Server 2003 with SP2 Understanding Active Directory Active Directory is an implementation o

learn.microsoft.com