Re: restrict access to view ad

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hello Altria,

The article is about delegating control/permissions in AD, which for you is not the solution i think.

The next step you should: !!!FIRST TRY IN A SEPARATED TEST ENVIRONMENT!!!

What you can try is, remove the Read permisssions for Authenticated users in AD. I will not know the effect of this on OU level or either domain level. Make sure all other configured groups are still in there.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Thanks Meinolf for your fast reply!

Users with admin rights on thier local ws do have rights to install
what
they like but I would just like a way to restrict users from viewing
ADUC.
The GPO can forbid snap-in but the user also has access of viewing
user
properties via address book (keep in mind my supervisor does not want
to
include GPOs). I came acorss this link which obviously has been a
major
concern for alot of system administrators but I think it is quite a
lengthy
process to adopt and was hoping there was a much easier way for this
to get
done.
http://redmondmag.com/columns/article.asp?EditorialsID=617
Does anyone know where I can get a detailed list of all the property
permissions so that I can start testing what impact to the user will
occur based on changing settings on a particular OU. I know for
certain there are some attributes that are required for proper
operation, such as user login which require those read permissions
nestled within ADUC. For heaveans sake I do not want to modify the
schema as well.

Thanks,
Altria
"Meinolf Weber" <meiweb(nospam)@gmx.de> wrote in message
news:ff16fb66d72f8cb11635e6729e1@xxxxxxxxxxxxxxxxxxxxxxx

Hello Altria,

Without using Group policies this will be not possible i think. If
they are able to install the admin tools, you have also an open door.
You should really think about using GPO's for this.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Hello All,
How can I restrict users from viewing AD properties and contents,
such
as in
Administrative tools
I am not runnning GP.
Thanks
Altria


.



Relevant Pages

  • Re: Delegation of rights not providing rights to edit GPOs
    ... Just to be clear, to set the permissions on an existing GPO, select the GPO ... Mike Aubert ... This posting is provided "AS IS" with no warranties, and confers no rights. ...
    (microsoft.public.win2000.group_policy)
  • Re: GPO for a user.
    ... You can just make sure you set the permissions so that only this user can ... read and apply the policy and it will only apply to them. ... This posting is provided "AS IS" with no warranties, and confers no rights. ... Can i create a GPO for a one user only? ...
    (microsoft.public.windows.server.active_directory)
  • Re: SCW question.
    ... Created a new Server and installed IIS. ... and saw that the default rights for IUSR and IWAM users are there. ... Server to the domain without and GPO's applied...Local Security policy ... rights (which coincides with my Member server GPO settings). ...
    (microsoft.public.windows.server.security)
  • Re: Prevent changes to Administrator password
    ... What I am trying to do is give Taz1972 some options to minimize the risk or make it harder for a lower-level DA to reset the password for the EA account. ... Restricted Admins group to mitigate against what you propose Deji. ... also need to make sure the DAs in question cannot elevate their rights to EA, ... > By adding the Deny Write Permissions ACE, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Prevent changes to Administrator password
    ... What I am trying to do is give Taz1972 some options to minimize the risk or make it harder for a lower-level DA to reset the password for the EA account. ... * This posting is provided "AS IS" with no warranties and confers no rights! ... > By adding the Deny Write Permissions ACE, ... > permission to modify the ACL on AdminSDHolder. ...
    (microsoft.public.windows.server.active_directory)