Re: LDAP attribute masking



Your realistic options are:

1. Use two attributes, one attribute has full id, the other has partial and then lock down who can see full ID. As JoeK mentioned, it generally isn't a good idea to lock down attribs in AD this way.

2. Keep the ID info in another store, SQL or ADAM, something like that that only admins have access to.

3. Look at Active Roles Server which has the idea of virtual attributes and extensive business rules and control. It is also costly.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


Dxdunbar@xxxxxxxxx wrote:
Hello, I'm in the process of building an application where help desk personnel will be able to query AD for a users employee id in order verify account modification request. I do not need for them to be able to see the entire id only the last five digits. I know i can do it within the app but the problem i have is if they were to use vbscript or Dsquery on there local machines to query ldap then they would be able to see the entire id. I would like to know if there is a way to mask an attribute in AD so that when non administrators query AD it only returns n number of digits. Any insight will be appreciated

.



Relevant Pages

  • Re: LDAP attribute masking
    ... isn't a good idea to lock down attribs in AD this way. ... Joe Richards Microsoft MVP Windows Server Directory Services ... personnel will be able to query AD for a users employee id in order ... AD it only returns n number of digits. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Xlocking with a select statement
    ... named query expression, order clause, update clause, lock option ... A result table or the underlying base tables are updateable if the query ... A lock can be requested for the ...
    (microsoft.public.sqlserver.programming)
  • Its working :-)
    ... The query results that I get is without using the single quotes. ... Each test REQUEST has a Lock, Key and Pattern Combination (sometimes ... "Ken Sheridan" wrote: ...
    (microsoft.public.access.queries)
  • RE: Using Multiple Combo Boxes as Criteria for Query
    ... I Believe the query works the way it is written to, ... In my results table I wanted to track which lock they were using, ... "Ken Sheridan" wrote: ... In such circumstances I'd usually leave the bound column for Null, ...
    (microsoft.public.access.queries)
  • Re: A new proof of the superiority of set oriented approaches: numerical/time serie linear interpola
    ... reduces the number of passes through the data required to answer a query. ... What kind of lock? ... The reduction in execution time improves response time. ... by a "sufficiently intelligent" optimizer. ...
    (comp.databases.theory)