Re: LDAP attribute masking



Thank you guys for your help.


On Jan 30, 9:32 pm, "Joe Richards [MVP]" <humorexpr...@xxxxxxxxxxx>
wrote:
Your realistic options are:

1. Use two attributes, one attribute has full id, the other has partial
and then lock down who can see full ID. As JoeK mentioned, it generally
isn't a good idea to lock down attribs in AD this way.

2. Keep the ID info in another store, SQL or ADAM, something like that
that only admins have access to.

3. Look at Active Roles Server which has the idea of virtual attributes
and extensive business rules and control. It is also costly.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Editionwww.joeware.net

---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm

Dxdun...@xxxxxxxxx wrote:
Hello, I'm in the process of building an application where help desk
personnel will be able to query AD for a users employee id in order
verify account modification request. I do not need for them to be
able to see the entire id only the last five digits. I know i can do
it within the app but the problem i have is if they were to use
vbscript or Dsquery on there local machines to query ldap then they
would be able to see the entire id. I would like to know if there is
a way to mask an attribute in AD so that when non administrators query
AD it only returns n number of digits. Any insight will be appreciated


.



Relevant Pages

  • Re: LDAP attribute masking
    ... Use two attributes, one attribute has full id, the other has partial and then lock down who can see full ID. ... Joe Richards Microsoft MVP Windows Server Directory Services ... I know i can do it within the app but the problem i have is if they were to use vbscript or Dsquery on there local machines to query ldap then they would be able to see the entire id. ... I would like to know if there is a way to mask an attribute in AD so that when non administrators query AD it only returns n number of digits. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Xlocking with a select statement
    ... named query expression, order clause, update clause, lock option ... A result table or the underlying base tables are updateable if the query ... A lock can be requested for the ...
    (microsoft.public.sqlserver.programming)
  • Its working :-)
    ... The query results that I get is without using the single quotes. ... Each test REQUEST has a Lock, Key and Pattern Combination (sometimes ... "Ken Sheridan" wrote: ...
    (microsoft.public.access.queries)
  • RE: Using Multiple Combo Boxes as Criteria for Query
    ... I Believe the query works the way it is written to, ... In my results table I wanted to track which lock they were using, ... "Ken Sheridan" wrote: ... In such circumstances I'd usually leave the bound column for Null, ...
    (microsoft.public.access.queries)
  • Re: A new proof of the superiority of set oriented approaches: numerical/time serie linear interpola
    ... reduces the number of passes through the data required to answer a query. ... What kind of lock? ... The reduction in execution time improves response time. ... by a "sufficiently intelligent" optimizer. ...
    (comp.databases.theory)