Re: hiding contacts from directory search (LDAP)
- From: tractng@xxxxxxxxx
- Date: 4 Sep 2006 15:20:26 -0700
Jorge,
I tried it and it works.
Joe,
You recommended to remove the default groups and add the group that I
like to give access to doesn't work. The concept only works for
sharing a file using share permission/ntfs security. If you deny
authenticated users you will be locked out of the OU. Passive denying
will be more a hassle in this situation. Users still are able to query
ldap if you don't explicitly deny access to it.
Thanks anyways!!!
~tnt
tractng@xxxxxxxxx wrote:
Thanks Joe & Jorge.
I will give it a try the coming week (was busy at work).
I tried removing the authenticated users the last time and was locked
out of the OU. Can't even see the contacts too (how scary). So
basically I lost all of the contacts, but it was just my test lan.
Thanks again,
Tony
Joe Richards [MVP] wrote:
What you want to do is remove the default, then add a group for who
should be able to see the objects. Then you are passively denying
access. Active deny is a pain in the ass and should be used sparingly if
at all.
--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net
---O'Reilly Active Directory Third Edition now available---
http://www.joeware.net/win/ad3e.htm
Jorge de Almeida Pinto [MVP - DS] wrote:
policy?
if you leave the default (auth users) and add a DENIED group
everyone has access except the group
if you change the default (auth users) to DENY and add a ALLOWED group
nobody has access
be carefull with removing authenticated users or changing the permissions
for it. make sure you test things!
remember that authenticated users is EVERYONE that has been authenticated
(users AND computers) (for computers think exchange servers)
.
- Follow-Ups:
- Re: hiding contacts from directory search (LDAP)
- From: Joe Richards [MVP]
- Re: hiding contacts from directory search (LDAP)
- References:
- Re: hiding contacts from directory search (LDAP)
- From: tractng
- Re: hiding contacts from directory search (LDAP)
- Prev by Date: Re: AD Replication fails with RPC error
- Next by Date: Re: Windows 2003 relation trust with 2 DC
- Previous by thread: Re: hiding contacts from directory search (LDAP)
- Next by thread: Re: hiding contacts from directory search (LDAP)
- Index(es):
Relevant Pages
|