Re: Re: 'Read only' Admin privileges for Active Directory environment?



1. Query Active Directory

As a 'normal' user, anyone can query AD, you can install "AD Administration tool" on your machine and launch your query

There will be some properties that you will not be able to access, but i think this would be a good place to start


You can also look for other tools available to launch queries, if domain admin rights are required, you can request your admins to launch the query (you can sit next to him to male sure he is not tampering with the reports ;)

2. Trust the admins

Its true, we must trust our admins, but can we have full trust on them?

We can never really fully trust anyone, this is why we have sections like Internal Audit & Information Security to look for malpractices




---------------------------------------------------------------------------
This list is sponsored by: SensePost

Hacking, like any art, will take years of dedicated study and
practice to master. We can't teach you to hack. But we can teach you
what we've learned so far. Our courses are honest, real, technical
and practical. SensePost willl be at Black Hat Vegas in July. To see
what we're about, visit us at:

http://www.sensepost.com/training.html
---------------------------------------------------------------------------



Relevant Pages

  • Re: Multiple Domains
    ... delegated the necessary permissions to the account. ... I used an admin account and received 2 out of 218 users. ... Then we can eliminate domain (where the query originates), ... application to get a two way trust. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Multiple Domains
    ... delegated the necessary permissions to the account. ... I used an admin account and received 2 out of 218 users. ... Then we can eliminate domain (where the query originates), ... application to get a two way trust. ...
    (microsoft.public.windows.server.active_directory)
  • Re: User-level Restriction
    ... Also, to answer your question to #3, the form will launch based on the Username. ... > the criteria for the 'CreatedBy' field to CurrentUser. ... >> generating a report. ... >> their initials again at the query level. ...
    (microsoft.public.access.security)
  • Re: How can I?
    ... uncompressed file and in db does not consist ... "Michel Walsh" wrote: ... parameters and the query runs once the user click the ok button. ... launch the query that will refer to the form ...
    (microsoft.public.access.queries)
  • Re: How can I?
    ... "Michel Walsh" wrote: ... In Nothwind, have a new form, AskCategory, with one combo box with all the ... parameters and the query runs once the user click the ok button. ... launch the query that will refer to the form ...
    (microsoft.public.access.queries)