Re: ADAM and the Reader Role



Oh, I see what you are saying. No, you can put as many users into an OU as
you have server resources to handle. I doubt you'll be able hit the max
size for ADAM. You would need a very very very large amount of disk space
to do that. :)

My guess is that your ADAM users don't actually have read permissions on
anything in ADAM, but they may not need that for your application to work.
You don't need read permissions to be able to authenticate.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
"jskalicky" <jskalicky@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:AAE1D081-6F5D-4AFB-9A2A-C086C8F3732C@xxxxxxxxxxxxxxxx
Joe,

Thanks for the reply. I may have misunderstood the problem I have read on
the internet. My situation is the following: I have one OU and am adding
users into it. I am not assigning users the reader role at all. Is there a
limitation as to how many users can be added to an OU with default
permissions?

Thanks,

Jeff

"Joe Kaplan" wrote:

Well, the issue is that if you want to assign each user directly to the
readers role and you have a lot of users, that group may become to large
to
manage practically. MS did some changes to the DS core in Win2K3 and
ADAM
such that there is no longer a 5000 member max limit on the size of a
particular group, but it could still get to be too big to deal with
unless
you start nesting groups.

In your situation, if you want all of your users to be readers, I'd just
add
the built in "authenticated users" group to the readers role and be done
with it. Any user that can bind to ADAM will have that SID in their
token
and would be in the readers role as a result. This will scale to
millions
of users and make your provisioning less complex. Of course, that
setting
may be too coarse for your security requirements.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services
Programming"
http://www.directoryprogramming.net
--
"jskalicky" <jskalicky@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F17DF85E-9A29-46B9-B6FD-4ABF9C603F2F@xxxxxxxxxxxxxxxx
I have seen some articles on the internet that suggest that if you use a
default install of ADAM without changing the permissions that once you
get
to
a large value of users that you have to directly assign the reader
permisson
to an OU in order to add a user.

I have tested out of the box permission and have successfully added
20,000
+
users to a single OU. Are there any limitations that anyone knows of
that
would support the argument discussed on the internet?

Thanks,

Jeff Skalicky





.



Relevant Pages

  • Re: ADAM and the Reader Role
    ... The number of objects you add to ADAM does not correlate with the permissions. ... Joe Richards Microsoft MVP Windows Server Directory Services ... MS did some changes to the DS core in Win2K3 and ADAM such that there is no longer a 5000 member max limit on the size of a particular group, but it could still get to be too big to deal with unless you start nesting groups. ... In your situation, if you want all of your users to be readers, I'd just add the built in "authenticated users" group to the readers role and be done with it. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM and the Reader Role
    ... readers role and you have a lot of users, that group may become to large to ... MS did some changes to the DS core in Win2K3 and ADAM ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... default install of ADAM without changing the permissions that once you get ...
    (microsoft.public.windows.server.active_directory)
  • Re: Granting permissions in ADAM
    ... only an ADAM user could update their own object. ... For an address book the standard permissions on the ADAM Readers role for ... group to the Readers role. ... Can you help with the proper command to give the users the proper ...
    (microsoft.public.windows.server.active_directory)
  • Re: Granting permissions in ADAM
    ... Thanks for the info about the ADAM account and WAB. ... Users to the Readers role makes use of the FSP container. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Granting permissions in ADAM
    ... Try creating a clean ADAM instance, ... "Lee Flight" wrote: ... Thanks for the info about the ADAM account and WAB. ... Users to the Readers role makes use of the FSP container. ...
    (microsoft.public.windows.server.active_directory)