Solved

Hiding specific user contact fields from specific users

Posted on 2011-09-28
3
310 Views
Last Modified: 2012-05-12
I have been asked to update our users with all their info including home phone numbers etc.  However my company wants to restrict certain AD fields from being accessable by averyone.  For example, Cetain managers when querying the global directory will be able to view home cell numbers and emergency numbers.  The regular employees when doing a globals address lookup will not be able to see these home numbers.

Is there a way in AD or in group policies to do this
0
Comment
Question by:lthorup
3 Comments
 
LVL 3

Expert Comment

by:jrgcomputing
ID: 36716483
I don't think there is a way of doing this. You really need a seperate system that imports users from AD and then use that. You could try spiceworks

http://www.spiceworks.com
0
 
LVL 21

Accepted Solution

by:
snusgubben earned 250 total points
ID: 36718349
You could create Confidential Attributes and control the visibility of those, or you could change the searchFlag on the attribute you want to hide.

You can't mark Base attributes as confidential.

General (2003 SP1 and later):
http://blogs.dirteam.com/blogs/tomek/archive/2005/11/21/confidential-bit.aspx
http://support.microsoft.com/kb/922836

Win2008: http://blogs.dirteam.com/blogs/tomek/archive/2008/03/11/confidential-attributes-windows-2008-follow-up.aspx

I guess you understand that this should be tested in a test environment before touching the production :)

0
 

Author Closing Comment

by:lthorup
ID: 37337694
Unfortunately this solution deals with potentially damaging the AD schema. It is my understanding this ability may be added to another service pack in the unknown future
0

Featured Post

Courses: Start Training Online With Pros, Today

Brush up on the basics or master the advanced techniques required to earn essential industry certifications, with Courses. Enroll in a course and start learning today. Training topics range from Android App Dev to the Xen Virtualization Platform.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

[b]Ok so now I will show you how to add a user name to the description at login. [/b] First connect to your DC (Domain Controller / Active Directory Server) SET PERMISSIONS FOR SCRIPT TO UPDATE COMPUTER DESCRIPTION TO USERNAME 1. Open Active …
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question