Re: Permissions to do AD Lookups?
- From: "Paul Williams [MVP]" <ptw2001@xxxxxxxxxxx>
- Date: Fri, 5 May 2006 15:41:08 +0100
Give them no additional permissions. A user or inetOrgPerson object is a
member of domain users, and the well known security principal Authenticated
Users. Authenticated Users has all the permissions you need. If it
doesn't, and you need specific read access to non-standard attributes, you
grant accordingly.
--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net
.
- Follow-Ups:
- Re: Permissions to do AD Lookups?
- From: Chris Sdonka
- Re: Permissions to do AD Lookups?
- References:
- Permissions to do AD Lookups?
- From: Chris Sdonka
- Permissions to do AD Lookups?
- Prev by Date: Re: Inbound Forest Trust creates authentication problems
- Next by Date: Replication Issue - LDAP stops responding after a day or so.
- Previous by thread: Permissions to do AD Lookups?
- Next by thread: Re: Permissions to do AD Lookups?
- Index(es):
Relevant Pages
|