jwiang4u
asked on
Grant AD Service Accounts Read Access to All AD User Accounts
Our company is working on a SharePoint BI deployment and I need to give two AD service accounts read permission to all AD user objects. I can do this one AD user at a time but this would take a long time and I would have to do it for each new user. How do I grant read access to these two service accounts for all current and future AD user account objects?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
All domain users are part of the "Authenticated Users" group, and by default have full read permissions on the domain partition (users/groups/OUs/etc.) You should not have to do anything for READ-ONLY access.