Minimum ACL to see someone in a search?



Greetings,

I just recently removed Everyone from the Pre-Windows 2000 Compatible Access
group, in order to try and tighten security for unauthenticated users.
However, I have noticed that when someone who is authenticated does a
search, to add a user to a group or ntfs permission e.g., they only see
about 5 users, when we have a lot more. All 5 are administrators. When I
compare the ACLs of these users with regular users, I see that for the
administrators, the Authenticated Users group has Read permission, i.e. Read
All Properties. However on other users, only "Read General Infomation",
"Read Personal Information", "Read Public Information" and "Read Web
Information" are checked. Also on every OU users have Read All Properties
and List Contents. I don't want to grant read access to all properties on
every user if I don't have to. What permissions do I need to check so that
authenticated users can see everyone when they do a search?

Thanks,
Michael D'Angelo


.



Relevant Pages

  • Re: CDOSYS Send method fails first time
    ... Permission: Authenticated Users - Read Control, ... > fails on the Send method if I access the web page with a non-admin user. ...
    (microsoft.public.exchange.development)
  • RE: no read rights in sbs 2008
    ... You receive the error message "Authenticated Users' does not have 'Read' ... The Offline Address Book (OAB) is a copy of an address book that has been ... will be created in the IIS server pointing to this folder to publish the ... READ permission to enable users to download the address book. ...
    (microsoft.public.windows.server.sbs)
  • Re: Some policys do not apply to user
    ... The difference between Everyone and Authenticated Users is Everyone includes ... Does the group have AGP permission? ... >>sounds like there is ACL filtering configured on the GPO ... Make sure the ACL has Everyone ...
    (microsoft.public.win2000.group_policy)
  • RE: AD users and computers security
    ... I believe you can remove authenticated users from OU, however, please ... carefully grant the appropriate permission to OU. ... When responding to posts, please "Reply to Group" via your newsreader so ...
    (microsoft.public.windows.server.migration)