Solved

Limit AD querying ability / scope to a users OU

Posted on 2010-09-07
1
485 Views
Last Modified: 2012-05-10
We would like to limit a users access to quering AD for entries, by for example only allowing him to query his own OU, and not the entire domain tree.

Is there an efficient way to do this? Maybe setting some kind of policy somewhere?

The issue is that we have customers who have their own isolated VM servers for applications outside our ASP environment. For easy user management and control, as well as some application requirements, those servers are members of our global domain. In order to allow application administrators access to the server, we add them to the local administrators group, but we really don't want them to be able to roam and explore our AD as they please, and as such, the question above arose.

Thank you!
0
Comment
Question by:CatalinT
1 Comment
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 33618753
So by default authenticated users have read access to AD; you would have to remote that then assign permissions to what they need....test anything out before you do it....things can break if you do it wrong.

Some more info here   http://www.usercube.com/blog/lock-down-active-directory-account

Thanks

Mike
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Powershell Active Directory Attribute LVR Metadata 3 19
LOGINSERVER and nltest /dsgetdc 3 40
Weird issue with VMWare ESXi 6 host 3 64
Exchange and Domain Controller 3 33
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question