Re: Urgent: Restrict LDAP Queries of a domain user




I can only set LDAP read permissions to all the tree? Not to some
portions (OUs) of the tree?

Joe Kaplan escreveu:
From the LDAP perspective, you can't restrict this. If the users can read
objects in the tree, then they can use the object as a base DN in a query
and can use subtree, one level or base for their query level.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
"Filipe" <clemente.filipe@xxxxxxxxx> wrote in message
news:1181905342.631608.6480@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi,

I want to have a Windows 2003 domain user performing LDAP queries only
to a certain scope (subtree) of the entire Active Directory tree. I
only have one Windows 2003 domain.

Is there a way to restrict LDAP queries of a particular user?

Is this possible? If yes, how?

TIA,

Clemente
Portugal


.



Relevant Pages

  • Re: Recommended strategy for providing access to web apps via Inte
    ... "Joe Kaplan" wrote: ... opened the firewall up for LDAP, the external entity can execute ANY LDAP ... These federated authentication protocols are designed to address these ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
    (microsoft.public.windows.server.active_directory)
  • Re: paged search control - how to
    ... "Joe Kaplan" wrote: ... hides the underlying LDAP page control stuff from you. ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... I heard paged search control will return pages in the limits. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active Directory and Logins
    ... "Joe Kaplan" wrote: ... special option that AD supports called "fast concurrent bind" that allows it ... The downside is that the LDAP connection state stays unauthenticated after ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ...
    (microsoft.public.windows.server.active_directory)
  • Re: Creating SID Manaully
    ... Those typically use LDAP under the hood to actually create the user ... you can't specify the GUID or SID. ... On Aug 31, 3:25 pm, "Joe Kaplan" ...
    (microsoft.public.windows.server.active_directory)
  • Re: Authenticate to local ADAM instance with local Windows credentials
    ... On Apr 11, 11:29 am, "Joe Kaplan" ... LDAP bind using the GSS-SPNEGO SASL mechanism. ... stack supports that depends on which one you are using. ...
    (microsoft.public.windows.server.active_directory)