Access Control to LDAP on AD?

Access Control to LDAP on AD?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Access Control to LDAP on AD? <-> 10-14-2005
Posted by on October 14, 2005, 9:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Is there a way to block certain user accounts from performing LDAP queries
on Active Directory?

If anyone could let me know I would be most appreciative.



Posted by Roger Abell [MVP] on October 15, 2005, 1:17 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I believe you can not realistically do that as an account will at times
be issuing Ldap queries, behind the scenes, sometimes against
the GCs, just to function as a domain client. Also, not all Ldap
queries are authenticated queries so if your objective is to
avoid a potential DoS from malicious queries they may try to
side-step your efforts using unauthenticated binds if they are
allowed to communicate with the ldap and gc ldap ports.

--
Roger Abell
Microsoft MVP (Windows Server : Security)
MCDBA, MCSE W2k3+W2k+Nt4
> Is there a way to block certain user accounts from performing LDAP queries
> on Active Directory?
>
> If anyone could let me know I would be most appreciative.
>



Similar ThreadsPosted
Access Control to Drives September 24, 2005, 3:03 am
Access Control Models August 24, 2006, 2:26 pm
Cut Security Costs - Access Control June 14, 2008, 1:23 am
Remote User "Quarantine" and access control May 18, 2006, 11:24 am
Parental Internet-access Control Software October 28, 2006, 1:03 pm
LDAP December 15, 2005, 11:56 am
ldap security October 6, 2005, 8:16 pm
Ldap validate October 10, 2005, 6:11 am
CRL LDAP question... June 27, 2006, 12:35 pm
CRL CDP LDAP question... July 10, 2006, 9:20 am

The site map in XML format XML site map

Contact Us | Privacy Policy