Re: LDAP attribute masking

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



On Jan 30, 1:40 pm, "Joe Kaplan"
<joseph.e.kap...@xxxxxxxxxxxxxxxxxxxxxxxx> wrote:
No, you can't do that. Attributes are "all or nothing" for read privileges.
It is possible to change the permissions on attributes to prevent people
from seeing certain data, but it is difficult and generally not a good idea
to do unless it is very important. Typically, it is best to avoid putting
confidential data in the directory in the first place if you can avoid it.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"http://www.directoryprogramming.net
--<Dxdun...@xxxxxxxxx> wrote in message

news:1170184396.768047.322710@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Hello, I'm in the process of building an application where help desk
personnel will be able to query AD for a users employee id in order
verify account modification request. I do not need for them to be
able to see the entire id only the last five digits. I know i can do
it within the app but the problem i have is if they were to use
vbscript or Dsquery on there local machines to query ldap then they
would be able to see the entire id. I would like to know if there is
a way to mask an attribute in AD so that when non administrators query
AD it only returns n number of digits. Any insight will be appreciated

Thanks for your response. Do you know of encoding function i could
use to populate the attributes?

.



Relevant Pages

  • Re: Querying AD
    ... Querying AD is all new to me so, of course, I didn't have my query right. ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: LDAP attribute masking
    ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... personnel will be able to query AD for a users employee id in order ... AD it only returns n number of digits. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Help encrypt conn string - no ASP, no server, cant protect keys, cant use Windows Authentica
    ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... I also considered putting it in the normal location in the registry as ... Installer property with the result and your installer can then just ...
    (microsoft.public.dotnet.security)
  • Re: Help encrypt conn string - no ASP, no server, cant protect keys, cant use Windows Authentica
    ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... also considered putting it in the normal location in the registry as you ... Installer property with the result and your installer can then just ...
    (microsoft.public.dotnet.security)
  • Re: Getting GROUPS from Active Directory by inputing an AD username
    ... Joe Kaplan-MS MVP Directory Services Programming ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... DirectoryEntry searchRoot = new DirectoryEntry( ... WindowsIdentity for a user and get their groups. ...
    (microsoft.public.dotnet.framework.aspnet.security)