Re: LDAP Security

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Follow Paul W's advice. AD is well protected but not prefect.

--

Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA

This posting is provided "AS IS" with no warranties, and confers no rights.

"Scott" <Scott@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F88B9CF9-E271-4C8B-817E-5453CDF63A36@xxxxxxxxxxxxxxxx
> Hello,
>
> Thanks for your response.
>
> Our Active Directory stores customer user accounts. With default
> permissions, any customer can query our Active Directory and obtain a list
> of
> ALL customers including full name, username, and email address. This
> opens
> the door to spam among other abuses.
>
> This seems like a major security problem. Are you sure there is no
> "clean"
> way to prevent this?
>
> Thanks,
> Scott
>
> "Paul Williams [MVP]" wrote:
>
>> Of course. But it's not recommended. You would have to remove the
>> default
>> permission of Authenticated Users: Read and replace with just your group.
>> When I say this isn't recommended, I really mean it mind. A lot of
>> things
>> take that permission for granted. Afterall, the purpose of a directory
>> is
>> to share information.
>>
>> For example, without read access to containers, GPOs won't process.
>>
>> What is the problem with the default permissions? Users can only read
>> select attributes of objects. They can't write or read sensitive
>> information.
>>
>> --
>> Paul Williams
>> Microsoft MVP - Windows Server - Directory Services
>> http://www.msresource.net | http://forums.msresource.net
>>
>>
>>


.



Relevant Pages

  • Re: LDAP Security
    ... He recommends against it for good reason. ... This is the kind of thing that is handled in a big long project, not a series of posts in a newsgroup because most places are not super simple and only using AD for an LDAP store of customer data. ... Our Active Directory stores customer user accounts. ... What is the problem with the default permissions? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Customer Contact List
    ... You can set the permissions any way ... > Outlook Categories to filter views, ... Obviously, setting up each customer ... >> with an Active directory user account is out of the question. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Customer Contact List
    ... You can set the permissions any way that seems effective ... Outlook Categories to filter views, ... > I need to have a customer contact list set up for my users to be able to ... > an Active directory user account is out of the question. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Delegation errors due to security Inheritance
    ... The parent Ou settings is not affecting the child object? ... "Paul Bergson" wrote: ... > reset security permissions and push to all down level objects. ... >> permissions has some how beeen unticked on all user accounts. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Problems with AdminCount bit, inheiratance, and email
    ... > same actions by delegating permissions to a new group of your creating. ... > best practices, or will take a long time to achieve. ... > set globally to the adminSDHolder object. ... > Paul Williams ...
    (microsoft.public.windows.server.active_directory)