Re: Possible to hide/secure Attributes on an User Object in LDAP?



After digging around in there with ADSIEDIT, it looks like the Schema part
is where you could set specific rights for an Attribute? Am I on the right
track here?

Also, if that's the right place to change it, are these Attributes "safe" to
change the security on, plus populate with our own data? (employeeID,
employeeNumber, employeeType)

If not, I guess I could create completely new Attributes within the Schema?

I haven't messed much with this before, so any advice would be much
appreciated!

TIA!

/ Per


"Per Hagstrom" <poh@xxxxxxxxxxxxxxxxx> wrote in message
news:e545EtmPHHA.5012@xxxxxxxxxxxxxxxxxxxxxxx
We have a 2003 domain and we are trying to use some fields normally not
populated in Active Directory that are available if you use ADSIEDIT. For
example employeeID is available. If we fill this field out, is there any
way we can hide this field from anyone that is authenticated, to only let
say Domain Admins?

If I use ADSIEDIT I can see I can set the security on the User Object, but
I don't know if there is a way to set security only on an attribute, like
employeeID?

TIA!!

/ Per





.



Relevant Pages

  • Re: Possible to hide/secure Attributes on an User Object in LDAP?
    ... Improved security to protect confidential attributes. ... plus populate with our own data? ... example employeeID is available. ... If I use ADSIEDIT I can see I can set the security on the User Object, ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADPrep /Forestprep - Schema Version - Maybe Not Incremented to 30?
    ... Open your Config NC in ADSIEdit. ... Windows Server MVP ... > step of verifying that the schema version was now 30. ... > "The large print giveth, and the small print taketh away." ...
    (microsoft.public.win2000.active_directory)
  • ADPrep /Forestprep - Schema Version - Maybe Not Incremented to 30?
    ... step of verifying that the schema version was now 30. ... ADSIEdit, I thought I found it, but perhaps not, looks like ADSIEdit only ... can anyone direct me in how I might verify that the schema version did ... "The large print giveth, and the small print taketh away." ...
    (microsoft.public.win2000.active_directory)
  • Re: adam- creation of forwad/back links in ADAM
    ... > ADAM Schema snapin? ... Yes you can certainly use ADSIedit, not sure if you can do this with the ... the linkId needs to be set. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Help Extending Schema
    ... this already and I'm not a strong script writer by any means so hoping ... If you have found the fields you need (employeeID) then you do NOT ... need to extend the schema. ... DLLs to add to the ADUC, and those will have a practical need to be ...
    (microsoft.public.windows.server.active_directory)

Loading