Improve company productivity with a Business Account.Sign Up

x
?
Solved

How prevent AD account from logging on but allow ldap query of AD

Posted on 2014-02-03
2
Medium Priority
?
526 Views
Last Modified: 2014-02-03
We're creating a role account to be used by a 3rd party system on our network that needs to be able to query AD but we'd like to prevent anyone from using that role account to actually log in to AD.  Is that possible?

If so, how?

Our AD domain functional level is 2003, but we have a mix of Server 2008 and Server 2003 DC's.  We're trying to get to a place where we can retire our Server 2003 DC but we're not there yet.

Thanks!
0
Comment
Question by:RhoSysAdmin
2 Comments
 
LVL 41

Accepted Solution

by:
Mahesh earned 1000 total points
ID: 39830177
Just go to user ad properties, navigate to accounts tab \ log on to and select the following computer and click OK.
Do not add any computer there, or add any disabled computer account there
Now user will able to make LDAP query but could not be logon to any computers in domain

Mahesh
0
 

Author Closing Comment

by:RhoSysAdmin
ID: 39830993
Perfectly simple solution.
0

Featured Post

Get 10% Off Your First Squarespace Website

Ready to showcase your work, publish content or promote your business online? With Squarespace’s award-winning templates and 24/7 customer service, getting started is simple. Head to Squarespace.com and use offer code ‘EXPERTS’ to get 10% off your first purchase.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

In this article, we will discuss how you can secure Active Directory using free tools, and how you can choose a safe and secure Active Directory security auditing tool.
One thing I've always found frustrating is no matter how many times one asks the end users to not save things on their local machines, they do it anyway.  Forget that we don't back up the desktops - only the servers.  Well, let's sneak their data on…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question