Solved

Hiding user information in Active Directory

Posted on 2014-10-07
4
109 Views
Last Modified: 2014-10-14
I have a complex issue I need help resolving.  I have multi-domain organization with an account domain that has all the users (30,000) within that domain.  A 3rd party company is requesting we place a r/w DC in their data-center to access a Citrix application.  The problem is that this domain consists of multiple law enforcement agencies and we need to hide personal data not allowing non-law enforcement to be able to view their personal information.  The law enforcement personnel are very concerned with non-law enforcement having access to personal data.  I need to get this done in the most efficient way.

If you need more information please let me know.
0
Comment
Question by:Jim Wobig
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 40367095
Definitely a complex issue and understandable request.    You can take advantage of the Filtered Attribute Set with the RODC.   You will need to make sure to test this and make sure you are filtering exactly what you want.  You can search for RODC and Filtered Attribute Set but some decent links:

http://technet.microsoft.com/en-us/library/cc753459%28v=ws.10%29.aspx

http://www.frickelsoft.net/blog/?p=202

http://blogs.msdn.com/b/canberrapfe/archive/2011/07/08/adding-attributes-to-the-rodc-filtered-attribute-set.aspx

Thanks

Mike
0
 

Author Comment

by:Jim Wobig
ID: 40367118
Thanks for the response Mike.  The company that is hosting the Citrix application is telling us RODC is not an option.  They also wont let us authenticate over the WAN and claim that it causes them to reboot their servers daily.

Thanks again,

Jim
0
 
LVL 81

Expert Comment

by:David Johnson, CD, MVP
ID: 40367331
Then obviously this 3rd party is not for your organization, either do it in house or find someone else.
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 40367404
That is fine, you can hide with r/w DCs too.  Guido (DS MVP) has a great series on this

http://windowsitpro.com/active-directory/hiding-active-directory-objects-and-attributes

Other three parts are also there.  Again same as before...test test test.  

Thanks

Mike
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Recover from a ISCSI Share In Windows 2 61
User Account Question 6 46
Office 365:  Hybrid without everyone DirSync 5 58
is a device online 4 30
This article runs through the process of deploying a single EXE application selectively to a group of user.
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question