Re: Windows Accounts added to group in ADAM

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Joe Kaplan \(MVP - ADSI\) (joseph.e.kaplan_at_removethis.accenture.com)
Date: 10/22/04


Date: Fri, 22 Oct 2004 14:19:20 -0500

Yep, it is definitely a better approach. Depending on the programming stack
you are using, getting tokenGroups from ADAM may require some trickery. I'd
suggest you follow up with more specifics of your code if you aren't already
succeeding with doing this.

Cheers,

Joe K.

"CAJazzMan" <CAJazzMan@discussions.microsoft.com> wrote in message
news:CA5FD2ED-B0B5-4C9B-80F6-A336FED2BF42@microsoft.com...
> Joe and Dmitri,
> Thanks for the very useful information. In fact, Joe, I am trying to do
> authorization as you mentioned. I am using groups in ADAM to manage
> authorization, and relying on users authenticated in NT domains or AD to
> assign membership to these ADAM groups. I am enumerating the group
> memberships (memberOf) recursively to determine what the user is
> authorized
> to do. It sounds that using tokengroups is a better approach.
> Thanks
>



Relevant Pages

  • Re: Windows Accounts added to group in ADAM
    ... Joe and Dmitri, ... authorization, and relying on users authenticated in NT domains or AD to ... assign membership to these ADAM groups. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM and Authorization and Profile Application Block
    ... I can say with certainty that Accenture isn't yet using ADAM for internal ... underlying group membership without getting too involved in higher level ... > but that is not using the Authorization and Profile Application Block. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM and Authorization and Profile Application Block
    ... Profile Application Block with ADAM). ... What I have see in my little research is also the Authorization ... Manager (azMan) present in Win2003. ... The problem now was for me integrate Authorization and Profile ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM schema design
    ... I've never played with groupOfNames, but I thought I'd point out that ADAM ... groups are not Windows security principals and have no effect on Windows ... might be able to get nested group membership via tokenGroups. ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD LDS - Available for Windows XP?
    ... recursive group membership expansion for users. ... Joe Kaplan-MS MVP Directory Services Programming ... We use ADAM extensively as ... since you can't install either on Vista. ...
    (microsoft.public.windows.server.active_directory)