Re: AzMan & ADAM



AzMan must be writing something somewhere. I don't know where, sorry. To
find out what it is writing, you can enable auditing in the tree, and
examine security logs to see which LDAP operations it is performing. In ADAM
V1, you need to write script to modify SACLs. However, if you download R2
Beta2, then you can use LDP.exe from R2 ADAM package -- this one has a
builtin ACL editor.

Another option is to set DirectoryAccess logging to 4 or 5 -- you should
then see an event in the ADAM evenlog corresponding to each ldap operation
being performed.

--
Dmitri Gavrilov
SDE, DS Admin eXperience

This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm

"Robert Rolls" <implatform@xxxxxxxxxxxxxxx> wrote in message
news:ez6$PvlcFHA.720@xxxxxxxxxxxxxxxxxxxxxxx
> The only way I can get AzMan to check operations / Roles is if the account
> that access the store is defined as administratoir within ADAM is there
> any way I can make him a reader than an administrator?
>
> Robert.
>


.



Relevant Pages

  • Re: ADAM : Beginner and need help
    ... AzMan probably isn't a good solution for Java, but the AzMan design might be ... ADAM also supports the AD "tokenGroups" attribute which can be used to ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... ADAM can also support lots of password policy features that Windows ...
    (microsoft.public.windows.server.active_directory)
  • ADAM with Azman
    ... activedirectory membership provider to speak to one ... Ideally ADAM will be the user/group repository and Azman ... construct a clientContext using the SID of the authenticated ADAM user. ...
    (microsoft.public.windows.server.active_directory)
  • nightmare with ADAM ldap and roleprovider
    ... activedirectory membership provider to speak to one ... Ideally ADAM will be the user/group repository and Azman ... ActiveDirectoryMemberShipProvider based code to ...
    (microsoft.public.dotnet.security)
  • Re: Bug in ADAM/AzMan integration? Roles placed in AzTaskObjectContain
    ... > in an ADAM partition. ... AzMan MMC and the role was created in the AzRoleObjectContainer ... > an AzMan store in ADAM. ...
    (microsoft.public.windows.server.active_directory)
  • Re: nbc: favorite book of all time
    ... What do you suggest as motivation for getting ... Writing should be its own intrinsic reward -- there ... but things like that post by Adam do serve to motivate one. ...
    (rec.music.artists.springsteen)