Topic 1, Litware, IncOverview
Litware, Inc. is a pharmaceutical company that has a subsidiary named fabrikam, inc Litware has offices in Boston and Seattle, but has employees located across the United States. Employees connect remotely to either office by using a VPN connection.
Identity Environment
The network contains an Active Directory forest named litware.com that is linked to an Azure Active Directory (Azure AD) tenant named litware.com. Azure AD Connect uses pass-through authentication and has password hash synchronization disabled.
Litware.com contains a user named User1 who oversees all application development. Litware implements Azure AD Application Proxy.
Fabrikam has an Azure AD tenant named fabrikam.com. The users at Fabrikam access the resources in litware.
com by using gu est accounts in the litware.com tenant.
Cloud Environment
All the users at Litware have Microsoft 365 Enterprise E5 licenses. All the built-in anomaly detection polices in Microsoft Cloud App Security are enabled.
Litware has an Azure subscription associated to the litware.com Azure AD tenant. The subscription contains an Azure Sentinel instance that uses the Azure Active Directory connector and the Office 365 connector.
Azure Sentinel currently collects the Azure AD sign-ins logs and audit logs.
On-premises Environment
The on-premises network contains the severs shown in the following table.

Litwareの両オフィスはインターネットに直接接続しています。両オフィスは、サイト間VPN接続を使用してAzureサブスクリプション内の仮想ネットワークに接続しています。オンプレミスのすべてのドメインコントローラーは、インターネットへのアクセスをブロックされています。
委任要件
Litware では、次の委任要件が特定されています。
* Azure AD Privileged Identity Management (PIM) を使用して、特権ロールの管理を委任します。
* 権限のないユーザーがlitware.com Azure ADテナントにアプリケーションを登録できないようにします。
* アイデンティティ ガバナンスにはカスタム カタログとカスタム プログラムを使用します。
* User1 が Azure AD でエンタープライズアプリケーションを作成できることを確認します。最小権限の原則を適用します。
ライセンス要件
Litware は最近、litware.com Active Directory フォレストに LWLicenses という名前のカスタム ユーザー属性を追加しました。
Litwareは、LWLicenses属性の値を変更することでAzure ADライセンスの割り当てを管理したいと考えています。LWLicenses属性に適切な値を持つユーザーは、Microsoftに自動的に追加される必要があります。
適切なライセンスが割り当てられた 365 グループ。
管理要件
Litware は、Litware のすべての Azure AD ユーザー アカウントを含み、すべての Azure AD ゲスト アカウントを除外する LWGroup1 という名前のグループを作成したいと考えています。
認証要件
Litware では、次の認証要件が識別されます。
* すべての Litware ユーザーに対して多要素認証 (MFA) を実装します。
* Litware のボストン オフィスから Azure AD への認証に MFA を使用するユーザーを除外します。
* litware.com フォレストの禁止パスワード リストを実装します。
* オンプレミスのアプリケーションにアクセスするときに MFA を適用します。
* 外部に漏洩した資格情報を自動的に検出し、修復します
アクセス要件
Litware では、Litware のすべての Azure AD ユーザー アカウントを含み、すべての Azure AD ゲスト アカウントを除外する、LWGroup1 という名前のグループを作成したいと考えています。
監視要件
Litware は、Azure Sentinel の Fusion ルールを使用して、疑わしい Azure AD サインインとそれに続く異常な Microsoft Office 365 アクティビティの組み合わせを含むマルチステージの検出をしたいと考えています。