Solved

Minimum LDAP Rights

Posted on 2011-09-30
4
281 Views
Last Modified: 2012-05-12
What are the minimum rights needed by an AD account to do LDAP lookups and Authentications.

We currently have a few applications set up to do lookups and authentication, but need to reduce the rights due to security concerns.
0
Comment
Question by:Octel-Node
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 125 total points
ID: 36893801
By default just a normal user account should do it

http://support.microsoft.com/kb/922836

In the Active Directory directory service for Microsoft Windows Server 2000 and for Microsoft Windows Server 2003, it is difficult to prevent an authenticated user from reading an attribute. Generally, if the user requests READ_PROPERTY permissions for an attribute or for its property set, read access is granted. Default security in Active Directory is set so that authenticated users have read access to all attributes. This article discusses how to prevent read access for an attribute in Windows Server 2003 Service Pack 1 (SP1).

Thanks

Mike
0
 
LVL 24

Accepted Solution

by:
Sandeshdubey earned 125 total points
ID: 36895620
It depends on how you have manipulated perms in AD but normal domain user should be fine.

Just a simple user as authenticated users have permissions all over the
place to read. (unless that was changed)

You also may wanna have a look at:
http://www.petri.co.il/anonymous_lda...ws_2003_ad.htm
http://support.microsoft.com/?id=320528

0
 
LVL 27

Expert Comment

by:Tolomir
ID: 37175646
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ADFS Help 7 48
DNS Replication 12 69
Problems creating account in AD with Powershell, data from SQL 57 47
SSSD - Automatic kerberos ticket initialization 1 14
This article shows how to deploy dynamic backgrounds to computers depending on the aspect ratio of display
Last week, our Skyport webinar on “How to secure your Active Directory” (https://www.experts-exchange.com/videos/5810/Webinar-Is-Your-Active-Directory-as-Secure-as-You-Think.html?cid=Gene_Skyport) provided 218 attendees with a step-by-step guide for…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question