premises access
mantraps
internal security controls
- locking up sensitive documents
card-based access
- less secure than smartcards (payment cards)
human security element
authentication
identity federation
claims (security tokens)
configuring authentication between on-premise/cloud environments
- replicating on-premise directory services to cloud-based directory service
something you know
something you have
OTP
something you are
- can expand existing systems to accept biometric authentication (i.e. AD)
logical access control
security groups
distribution groups
- can’t be assigned permissions
DAC
RBAC
rights vs permissions
Windows NTFS permissions
levels of Windows NTFS permissions
DACL
- administrator sets file system permissions
Windows shared folder permissions
Windows shared folder permission levels