Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Grant AD Service Accounts Read Access to All AD User Accounts

Posted on 2013-01-09
2
Medium Priority
?
2,711 Views
Last Modified: 2013-01-11
Our company is working on a SharePoint BI deployment and I need to give two AD service accounts read permission to all AD user objects. I can do this one AD user at a time but this would take a long time and I would have to do it for each new user. How do I grant read access to these two service accounts for all current and future AD user account objects?
0
Comment
Question by:jwiang4u
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 15

Accepted Solution

by:
achaldave earned 2000 total points
ID: 38759194
By default domain users can read almost all objects in AD, you can use delegation wizard to provide any additional permissions

http://www.windowsecurity.com/articles/Implementing-Active-Directory-Delegation-Administration.html
0
 
LVL 17

Expert Comment

by:Tony Massa
ID: 38765931
All domain users are part of the "Authenticated Users" group, and by default have full read permissions on the domain partition (users/groups/OUs/etc.)  You should not have to do anything for READ-ONLY access.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A while back, I ran into a situation where I was trying to use the calculated columns feature in SharePoint 2013 to do some simple math using values in two lists. Between certain data types not being accessible, and also with trying to make a one to…
Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question