Re: Multiple Domains




"Ryan Hanisco" <RyanHanisco@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:10CAD1D2-4649-437A-8B2D-64177BAAE9D0@xxxxxxxxxxxxxxxx
The other possible problem could be the number of results returned. There
is
a default number of results that it returns in a query. Depending how you
are retrieving these results the number can be different (ADSI vs. outlook
vs. some other methods). Just as there are different queries, there are
different ways to change the threshold -- registry setting or search
string
criterion.

Good point but one would expect this will be the same for different users
(e.g., admin etc) using the same query method/program.

So by looking to see if you get the same number, but still incomplete
results
with different users should help track this down as the source of the
problem.


--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)

Hope this helps.
--
Ryan Hanisco
MCSE, MCTS: SQL 2005, Project+
Chicago, IL

Remember: Marking helpful answers helps everyone find the info they need
quickly.


"Herb Martin" wrote:


"EMan" <EMan@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:8F17E774-57C2-41B7-90ED-F708DAAA136D@xxxxxxxxxxxxxxxx
I have two Domains D1 and D2 where there is a one way trust between D1
and
D2
(D1 trusts D2).

Then users in D2 can (be granted) access (to) resources in D1.

I have an application using LDAP to read the AD in D2 from
D1 using a service account from D2.

Ok.

The service account is a user in the OU I am trying to read.

Doesn't matter. Membership in any particular OU has nothing to
do with access, except in the sense that you have chosen to delegate
there.

When the LDAP is executed I get some users, but not all
of the users and I can't understand the reason why all users are not
returned. What can I do to read all of the users?

Chances are the same results will be returned if you execute this as
any other user (e.g., and Admin) would get the same results -- IF
not then you likely have a permission problem where you have not
delegated the necessary permissions to the account.

Check you script locally, check it using another (admin) user, check
it remote with the admin until you can figure out what the specific
difference is if you have incorrect results.

Thanks,
EMan


--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)





.



Relevant Pages

  • Re: Multiple Domains
    ... D1 using a service account from D2. ... except in the sense that you have chosen to delegate ... not then you likely have a permission problem where you have not ... Check you script locally, check it using another (admin) user, check ...
    (microsoft.public.windows.server.active_directory)
  • + Trivantis CourseMill Enterprise Learning Management System - SQL Injection - CVE-20
    ... The username field on the login page is susceptible to SQL injection... ... Trivantis and CourseMill are registered trademarks of Trivantis. ... The logins are unencrypted and stored in the "Admin" table. ... Sample Query Logs from Exploiter Beta: ...
    (Bugtraq)
  • Re: Search sub-form without writing exactly what is contained in query field
    ... will this work if say I type 'Admin' and 'Finance' in the same ... firstly I want to search all staff who have 'finance' ... Is there a way of searching a sub-form (reading from a query) without ... Manager' and 'Finance Manager' appeared as part of the results? ...
    (comp.databases.ms-access)
  • Re: Queries & table locking
    ... as users do not use the database; it simply serves as a source for ... interprets the current user as admin. ... The query is a make-table query, ... If instead of running a make-table query, ...
    (microsoft.public.access.queries)
  • Unbound field results are different then Query w/the same criteria
    ... functions of the admin FE will be to use the "Questions Selection Form" ... In the Eval FE I have a form based on a query with both QL and Q ... There is an Unbound field for each Question, ...
    (microsoft.public.access.formscoding)