Re: ADAM Question: Windows users cannot login unless they are member of local admins

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Windows users can bind to ADAM as long as the user represents a security principal trusted by the ADAM server (a local user or a domain user from a trusted domain).

That said, by default users who are not in the readers role may not have permissions to see any objects in the directory. Is this what you meant by "log in"? There is a difference between successful authentication and authorization to perform an operation like a search to read something.

You can use ADAM ADSI Edit to add Windows users to a group. In some cases, it is easier to add a built in security principal like Authenticated Users or the local Users group on the server so that you don't have to constantly add new Windows users to ADAM to grant read access.

Joe K.
--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
"Max2006" <alanalan1@xxxxxxxxxxxxxxxx> wrote in message news:65BDEF1B-2E36-4514-8341-5309F7C18992@xxxxxxxxxxxxxxxx
Hi,

I made a local machine user part of ADAM's Reader role; however, the user cannot login through ADSIEdit.

Basically I found that unless a windows user is not part of local admins, it cannot login into ADAM.

Not sure what I am missing here. Is there any procedure explains how to add a normal windows user part of ADAM's Reraders Role?

Any help would be appreciated,
Max



.



Relevant Pages

  • Re: Adam Sync Issue
    ... So If i am using ADAM only as a role store for windows users, ... Joe Kaplan wrote: ... The FSP is just a pointer to the AD object. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Heimdal KDC, Windows XP and local users
    ... All existing Windows users can authenticate against the KDC, ... Windows does not create a new local user with the same name ... however LDAP seems superfluous for my purpose. ...
    (comp.protocols.kerberos)
  • Re: Adam Sync Issue
    ... Like Dmitri said, if you really want to remove stale FSP objects from ADAM, ... So If i am using ADAM only as a role store for windows users, ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD/AM User proxy and certificates
    ... do you know anything about client cert auth for ADAM users? ... or does it only work for Windows users as a pass through? ... Joe Kaplan-MS MVP Directory Services Programming ...
    (microsoft.public.windows.server.active_directory)
  • Re: Is AD a good fit for an app?
    ... ADAM can authenticate windows users even without ... That is, you can come and bind to ADAM as a windows user, and ADAM ... >> We will have external users, and internal users. ...
    (microsoft.public.windows.server.active_directory)