Hiding user information in Active Directory

I have a complex issue I need help resolving.  I have multi-domain organization with an account domain that has all the users (30,000) within that domain.  A 3rd party company is requesting we place a r/w DC in their data-center to access a Citrix application.  The problem is that this domain consists of multiple law enforcement agencies and we need to hide personal data not allowing non-law enforcement to be able to view their personal information.  The law enforcement personnel are very concerned with non-law enforcement having access to personal data.  I need to get this done in the most efficient way.

If you need more information please let me know.
Jim WobigSr. Network/Systems AnaylistAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Mike KlineCommented:
Definitely a complex issue and understandable request.    You can take advantage of the Filtered Attribute Set with the RODC.   You will need to make sure to test this and make sure you are filtering exactly what you want.  You can search for RODC and Filtered Attribute Set but some decent links:

http://technet.microsoft.com/en-us/library/cc753459%28v=ws.10%29.aspx

http://www.frickelsoft.net/blog/?p=202

http://blogs.msdn.com/b/canberrapfe/archive/2011/07/08/adding-attributes-to-the-rodc-filtered-attribute-set.aspx

Thanks

Mike
0
Jim WobigSr. Network/Systems AnaylistAuthor Commented:
Thanks for the response Mike.  The company that is hosting the Citrix application is telling us RODC is not an option.  They also wont let us authenticate over the WAN and claim that it causes them to reboot their servers daily.

Thanks again,

Jim
0
David Johnson, CD, MVPOwnerCommented:
Then obviously this 3rd party is not for your organization, either do it in house or find someone else.
0
Mike KlineCommented:
That is fine, you can hide with r/w DCs too.  Guido (DS MVP) has a great series on this

http://windowsitpro.com/active-directory/hiding-active-directory-objects-and-attributes

Other three parts are also there.  Again same as before...test test test.  

Thanks

Mike
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.