Active Directory permissions


hi,

is possible set permissions active directory service itself, no 3rd party scripts [powershell scripts] should able collect ad info ??

is there provision disable read permissions active directory ??

 

no. acls don't include stipulation regarding way individual objects accessed - consist of entries identify security principals , corresponding permissions each. if given user able read given attribute, applicable regardless of method used read it.

as far "hiding" individual objects/attributes in ad, possible - need proceed (and perform lot of testing) ensure not cause negative implications. more @ http://social.technet.microsoft.com/forums/en-us/winserverds/thread/b62dc2d1-3145-4a82-a7e7-58646253919e/

hth
marcin



Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group