Re: How do I reset access rights to use/view ADUC?



Ok... Gotcha...

Thanks a lot for the info and the feedback, Paul.


On Mar 27, 11:55 am, "Paul Bergson [MVP-DS]"
<pbergson@xxxxxxxxxxxxxxxxx> wrote:
This isn't something you want to do, unless you have a specific set of ou's
that contain certain elevated accounts or something similar. before you
have been authenticated at logon you need to be able to gain access to AD,
you can mess things up if you start doing to much restriction.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"islanman" <islan...@xxxxxxxxx> wrote in message

news:1175006783.364192.149090@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Thanks for your help Paul.

Given the fact that you can use LDAP browsers to look through AD
anyways, is there anyway one can secure the domain from illicit AD
browsing/access from anyone else except domain computers and
administrators?

.



Relevant Pages

  • Re: logon/power-users group question
    ... users to the power users group (via My computer>Properties>Computer ... and then logon to the computer with that account to bypass domain ... > You can limit logon to domain computers in a couple of ways. ...
    (microsoft.public.windows.server.security)
  • Re: Authenicated Users Query
    ... If the account that the user is logged onto on the non domain computer has ... If you have auditing of logon events enabled ... use ipsec AH/ESP for communications with domain computers but otherwise it ...
    (microsoft.public.windows.server.security)
  • Re: Restrict Logon Location
    ... they can logon to all domain computers but domain controllers. ... User rights are located in security ... Local policy can also ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active AD users?
    ... users/table you can add attributes for last logon time and logon server. ... local accounts on domain computers and are not in the local administrators group ... are finding "account logon" events in the security log on domain computers, ...
    (microsoft.public.win2000.networking)
  • Re: Restrict Logon Location
    ... they can logon to all domain computers but domain controllers. ... User rights are located in security ... Local policy can also ...
    (microsoft.public.windows.server.security)