Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Windows Server Security Essentials

You're reading from   Windows Server Security Essentials Develop and implement a secure Microsoft infrastructure platform using native and built-in tools

Arrow left icon
Product type Paperback
Published in Feb 2015
Publisher
ISBN-13 9781784398729
Length 240 pages
Edition 1st Edition
Arrow right icon
Toc

Dynamic Access Control

As mentioned before, Dynamic Access Control (DAC) was introduced in Windows Server 2012. There are some requirements to support DAC in an enterprise. You need to have at least one Windows Server 2012 Domain Controller and the Active Directory Forest Functional Level (FFL) must be at least Windows 2003. Also, before you can start using the benefits of DAC, the Kerberos Key Distribution Center (KDC) support for claims, compound authentication and Kerberos armoring setting must be enabled on all Domain Controllers.

On a higher level, the following steps are required to configure and implement a DAC mechanism in an Active Directory environment:

  • Enable KDC support
  • Create claim type
  • Create resource properties
  • Create Central Access Rule (CAR)
  • Create Central Access Policy (CAP)
  • Deploy Central Access Policy using GPO
  • Configure...
lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime