Add users to AD for authentication, but not for computer access

Posted on 2006-04-07
Medium Priority
Last Modified: 2010-04-18
I am in a network setting where we use Win 2k3 Sevrer w/ AD for the faculty and staff of our school.  The students are authenticated by an Open Directory Mac OS X server.  This is not a problem for us as the OS X server can host a STUDENT Doamin for our student windows clients.  However, there are times whne I want to use other products' LDAP features for authentication - often these products work better, or only, with AD.  (I like having the two networks segregated for seurity purposes.)  Thus there are times when it would be nice to have users in the AD who could not login to computers on the network.  That way, if my Content Filter, Print server, etc. was using LDAP for authentication from teh Win 2k3 AD sevrer the names and passwords would be there for authentication.  Is ths possible?  I liken this to creating distribution groups as opposed to security groups in AD.  (We need the Open Directory Mac OSX server to stay for purposes of management of the Apple workstations.  It is possible to have Open Directory look at AD for authentication while maintaining apple client management but this adds several layers of complexity and generally teh addition of an expensive product - we do not want to do this)

Any help with this is appreciated.
Question by:jcaballero73
LVL 23

Accepted Solution

TheCleaner earned 352 total points
ID: 16402071
I think you are going down the road of either Microsoft's RADIUS or a 3rd party like Funk (now Juniper) (steel-belted RADIUS).

Or you could in a sense create a user ID in AD, and set the "log on to these workstations" and not list anything.

LVL 51

Assisted Solution

Netman66 earned 348 total points
ID: 16402251

Featured Post

Veeam and MySQL: How to Perform Backup & Recovery

MySQL and the MariaDB variant are among the most used databases in Linux environments, and many critical applications support their data on them. Watch this recorded webinar to find out how Veeam Backup & Replication allows you to get consistent backups of MySQL databases.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

by Batuhan Cetin Within the dynamic life of an IT administrator, we hold many information in our minds like user names, passwords, IDs, phone numbers, incomes, service tags, bills and the order from our wives to buy milk when coming back to home.…
I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an anti-spam), the admin…
Look below the covers at a subform control , and the form that is inside it. Explore properties and see how easy it is to aggregate, get statistics, and synchronize results for your data. A Microsoft Access subform is used to show relevant calcul…

807 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question