Avatar of lianne143
lianne143
Flag for United States of America asked on

How to create a user account which has read only access to our Active Directory.

Hi

Our web filtering is hosted outside of our organisation I have been asked to create a user account which has read only access to our AD.

Not sure as how to create this account please post me tutorials to set up this read only access account.


Thanks
Windows Server 2012Active Directory

Avatar of undefined
Last Comment
Shaun Vermaak

8/22/2022 - Mon
Iamthecreator OM

All domain users have read-only access to the AD.
ASKER CERTIFIED SOLUTION
Shaun Vermaak

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Mahesh

by default standard user don't have any access apart from read only on Active directory objects

if you can tell exact where account will be used we can suggest
austin minor

Just create a user account that is member of the Domain users.

https://docs.microsoft.com/en-us/windows/desktop/ad/creating-a-user
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
lianne143

ASKER
As said our web filtering is hosted outside of our organisation and they have asked to create a user account, which has read only access to our AD.
This account will be used, so that filtering system can query the list of users in our AD to make sure it is up to date.
Iamthecreator OM

A domain user account with no special privileges should work fine.
Shaun Vermaak

Unless, like I mentioned, you added permissions incorrectly on other systems using domain users group or authenticated users group. If that is the case you have some permissions to fix or denies to implement to prevent data leakage
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
lianne143

ASKER
Hi

I have created  the user account and by default the user is member of domain users, will this be ok.

Thanks
SOLUTION
Mahesh

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Shaun Vermaak

By default when user authenticate with AD, it is considered as authenticated and get access to all resources in AD which are accessible to authenticated users group
Correct, my point is some setup their confidential document shares with "Authenticated Users"