[Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 495
  • Last Modified:

Limit AD querying ability / scope to a users OU

We would like to limit a users access to quering AD for entries, by for example only allowing him to query his own OU, and not the entire domain tree.

Is there an efficient way to do this? Maybe setting some kind of policy somewhere?

The issue is that we have customers who have their own isolated VM servers for applications outside our ASP environment. For easy user management and control, as well as some application requirements, those servers are members of our global domain. In order to allow application administrators access to the server, we add them to the local administrators group, but we really don't want them to be able to roam and explore our AD as they please, and as such, the question above arose.

Thank you!
0
CatalinT
Asked:
CatalinT
1 Solution
 
Mike KlineCommented:
So by default authenticated users have read access to AD; you would have to remote that then assign permissions to what they need....test anything out before you do it....things can break if you do it wrong.

Some more info here   http://www.usercube.com/blog/lock-down-active-directory-account

Thanks

Mike
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now