Re: Hide group membership?

From: Stefan Buchman (stefan2002b_at_yahoo.com)
Date: 04/23/04


Date: Fri, 23 Apr 2004 12:54:27 -0400

The users themselves are not checking to see if they are members of the
group it would be the remote system (File Server, Web Server, etc...)
that would be checking that users access if using NTLM otherwise it
would be the Domain Controller if using Kerberos V5.

Either way the user is never responsible for checking it's own group
memebership so you would not be able to deny access to the KDC / LSA to
read this group.

- Stefan

A.J. Fried wrote:

> I have a group that I would like to temporarily disable without actually
> deleting it. I'm trying to find out what (if anything) it's used for so my
> thought it to disable or hide it somehow so that members don't "know" that
> they are members and so they wont get whatever permissions are normally
> afforded via membership in that group.
>
> I have played with the permissions on the group object in AD but it doesn't
> seem to work.
>
> Specifically, I set authenticated users to deny read on the group object in
> AD. However, members still "know" they are members - eg - if I log in as a
> member of the group and run GPResult.exe it still tells me that I am a
> member.
>
> Is there a way to do this? Am I thinking about this correctly?
>
> TIA.
>
> --> A.J. Fried



Relevant Pages

  • Hide group membership?
    ... deleting it. ... they are members and so they wont get whatever permissions are normally ... I have played with the permissions on the group object in AD but it doesn't ...
    (microsoft.public.win2000.active_directory)
  • Re: Users having trouble accessing file server
    ... >I want to figure out why these users have having inconsistant access to ... The clients are members of the domain, ... > (exchange 2003, which like the file server, requires users to be ... Check errors into the event viewer on clients and server. ...
    (microsoft.public.windows.server.general)
  • Re: Users having trouble accessing file server
    ... I want to figure out why these users have having inconsistant access to ... The clients are members of the domain, ... (exchange 2003, which like the file server, requires users to be ...
    (microsoft.public.windows.server.general)
  • [UNIX] Privilege Escalation Vulnerability on phpBB
    ... permissions), so although admin rights are needed to view the page, anyone ... Goto the board you wish to change the permissions for in the normal way ... Find the base directory location of the board for the script, ... This bulletin is sent to members of the SecuriTeam mailing list. ...
    (Securiteam)
  • RE: Send As permissions getting overwritten
    ... The issue should be caused that the users are members of the 'Domain ... Apply the 'Users' template to the existing power users using the Change ... User Permissions Wizard. ... >I've set up the security auditing as you've specified, ...
    (microsoft.public.windows.server.sbs)