Re: Windows Accounts added to group in ADAM

From: CAJazzMan (CAJazzMan_at_discussions.microsoft.com)
Date: 10/22/04


Date: Fri, 22 Oct 2004 10:49:05 -0700

Joe and Dmitri,
Thanks for the very useful information. In fact, Joe, I am trying to do
authorization as you mentioned. I am using groups in ADAM to manage
authorization, and relying on users authenticated in NT domains or AD to
assign membership to these ADAM groups. I am enumerating the group
memberships (memberOf) recursively to determine what the user is authorized
to do. It sounds that using tokengroups is a better approach.
Thanks



Relevant Pages

  • Re: Windows Accounts added to group in ADAM
    ... getting tokenGroups from ADAM may require some trickery. ... > authorization, and relying on users authenticated in NT domains or AD to ... > assign membership to these ADAM groups. ... It sounds that using tokengroups is a better approach. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM and Authorization and Profile Application Block
    ... I can say with certainty that Accenture isn't yet using ADAM for internal ... underlying group membership without getting too involved in higher level ... > but that is not using the Authorization and Profile Application Block. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM and Authorization and Profile Application Block
    ... Profile Application Block with ADAM). ... What I have see in my little research is also the Authorization ... Manager (azMan) present in Win2003. ... The problem now was for me integrate Authorization and Profile ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM - SSO and provisioning considerations
    ... ADAM and "custom" security principals and gives you ... for authentication, where you might ship some default providers (ADAM LDAP ... be used to link up to the authorization store. ... > customer's identity store is a non-MS directory, ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM and Authorization and Profile Application Block
    ... Profile Application Block with ADAM). ... What I have see in my little research is also the Authorization ... Manager (azMan) present in Win2003. ... The problem now was for me integrate Authorization and Profile ...
    (microsoft.public.windows.server.active_directory)