Click here to get back home

LDAP lookup based on a Security group?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
LDAP lookup based on a Security group? Transam388 05-23-2008
Posted by Transam388 on May 23, 2008, 10:42 am
Please log in for more thread options
Not sure if this belongs here but this is the question. We have a devie
which we would like to do an LDAP lookup against our 2003 AD. Now this is
the twist...is it possible to base the account that this is done on a
security group versus a specific account? Essentially looking for a way that
only the persons within that group can execute this LDAP but not have it
based only on one ID.

Thanks!!

Posted by Roger Abell [MVP] on May 24, 2008, 3:56 am
Please log in for more thread options
> Not sure if this belongs here but this is the question. We have a devie
> which we would like to do an LDAP lookup against our 2003 AD. Now this is
> the twist...is it possible to base the account that this is done on a
> security group versus a specific account? Essentially looking for a way
> that
> only the persons within that group can execute this LDAP but not have it
> based only on one ID.
>
> Thanks!!

Well, I am not quite sure I am guessing what you ask by saying

is it possible to base the account that this is done on a security group

Does that mean: can we limit the account(s) doing the LDAP query to
members of a security group ?

In general, any forest account can use LDAP to query just about anything.
You can limit what account(s) can execute some app/script your dev
comes up with, sure, and by groups too. But that does not mean that
only those accounts are able to run the query used in the app/script.
To control what accounts can get results for some specific LDAP query
you would have to control what accounts can read the AD objects/attributes
in AD via their permissions - something you should only do with awareness
of possible implications.

Roger



Similar ThreadsPosted
Role-based security from Windows Server 2003 Security Guide gives problems November 6, 2006, 8:00 am
Reverse Lookup - DNS February 1, 2008, 7:57 pm
LDAP authentication security ? December 3, 2007, 11:25 am
Lookup a "Caller Logon ID" November 29, 2006, 5:14 pm
Checking group security October 5, 2007, 10:31 am
"Self" security group - exposed? May 20, 2008, 4:07 pm
Create User and Auto Assign to Domain Security Group January 31, 2007, 12:27 pm
info on the National Information Security Group (NAISG) + an invitation February 4, 2008, 9:34 pm
Web based approval November 24, 2005, 4:07 pm
Access-based Enumeration September 8, 2005, 11:40 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap