Grant AD Service Accounts Read Access to All AD User Accounts

Our company is working on a SharePoint BI deployment and I need to give two AD service accounts read permission to all AD user objects. I can do this one AD user at a time but this would take a long time and I would have to do it for each new user. How do I grant read access to these two service accounts for all current and future AD user account objects?
jwiang4uIT DirectorAsked:
Who is Participating?
achaldaveConnect With a Mentor Commented:
By default domain users can read almost all objects in AD, you can use delegation wizard to provide any additional permissions
Tony MassaCommented:
All domain users are part of the "Authenticated Users" group, and by default have full read permissions on the domain partition (users/groups/OUs/etc.)  You should not have to do anything for READ-ONLY access.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.