Active Directory permissions
hi,
is possible set permissions active directory service itself, no 3rd party scripts [powershell scripts] should able collect ad info ??
is there provision disable read permissions active directory ??
no. acls don't include stipulation regarding way individual objects accessed - consist of entries identify security principals , corresponding permissions each. if given user able read given attribute, applicable regardless of method used read it.
as far "hiding" individual objects/attributes in ad, possible - need proceed (and perform lot of testing) ensure not cause negative implications. more @ http://social.technet.microsoft.com/forums/en-us/winserverds/thread/b62dc2d1-3145-4a82-a7e7-58646253919e/
hth
marcin
Windows Server > Directory Services
Comments
Post a Comment