Re: Permissions to do AD Lookups?



so with only authenticated user access they should be able to query the
entire domain, all the OUs, etc?


"Paul Williams [MVP]" <ptw2001@xxxxxxxxxxx> wrote in message
news:1146840071.980475@xxxxxxxxxxxxxxxxxxxxxx
Give them no additional permissions. A user or inetOrgPerson object is a
member of domain users, and the well known security principal
Authenticated
Users. Authenticated Users has all the permissions you need. If it
doesn't, and you need specific read access to non-standard attributes, you
grant accordingly.

--
Paul Williams
Microsoft MVP - Windows Server - Directory Services
http://www.msresource.net | http://forums.msresource.net




.



Relevant Pages

  • Re: Authenticated Users/Domain Users Question
    ... network. ... It would seem that Domain Users ARE Authenticated users, ... Authenticated User that is NOT a Domain User in a W2K3 DC world? ... > Authenticated user also includes authenticated machines. ...
    (microsoft.public.windows.group_policy)
  • VS.Net config
    ... IIS 5 ... Logged as an authenticated user (not member of any admin groups but member of Debugger Users and VS Developers). ... I'm asking this because it's the setup students have to work with and after googling and reading posts in this forum i'm still having a hard time getting VS.Net to work properly. ...
    (microsoft.public.dotnet.general)
  • Re: ASP.NET with ADirectory role based authentication
    ... I have used the article below thx for the link. ... But when i want to see the list of groups the authenticated user is a ... member of,and my adding the code ... Active Directory). ...
    (microsoft.public.dotnet.framework.aspnet.security)