Re: Prevent "Authenticated Users" from browsing Active Directory

From: Steven L Umbach (n9rou@nsattbi.com)
Date: 10/06/02


From: "Steven L Umbach" <n9rou@nsattbi.com>
Date: Sat, 05 Oct 2002 22:34:30 GMT


        On second though I would not recommend changing permissions at the
domain level because it probably would cause any user group policy settings
to not take effect, but I still believe that removing them at the user
container or individual object level is something that probably would
ork. -- Steve

"Steven L Umbach" <n9rou@nsattbi.com> wrote in message
news:lMIn9.50591$Pz.44229@rwcrnsc51.ops.asp.att.net...
> You could try this. In AD Users and Computers select the
domain
> properties/security and remove everyone and authenticated users from the
> security list. You can uncheck the read permissions for them, but my
> experience shows that they still may have read access in advanced
> permissions - that is why I recommend removing the whole group. That
should
> stop them from browsing AD. I do not think that will cause any operational
> properties, however I would recommend testing it first. You can always add
> these groups back - be sure to document their permissions before removing
> them. Another possibility is to remove the same groups from the individual
> object you do not want them to see. For instance you could remove everyone
> and authenticated users from security permissions for the domain admins,
> enterprise administrator, schema administrator, administrators, and
> administrator object. They would not appear then when someone browses the
> "user" container in AD. --- Steve
>
> "Lyle Homer" <lhomer@nospam.yahoo.com> wrote in message
> news:0n2upu4t9or71m11lvn8qr7e1n2dtercgg@4ax.com...
> > Is it possible to prevent Authenticated Users from browsing Active
> > Directory, without causing problems?
> >
> > We are planning to rename the domain administrator account but are
> > troubled by the fact that normal users in the domain can go to My
> > Network Places, Entire Network, Directory, domain, Built-in, and
> > double click on the Administrtors group and get the names of all the
> > accounts in the domain with admin rights.
> >
> > We moved the "Domain Admins" group to a new OU and removed the Read
> > permission from Authenticated Users and that made the OU disappera
> > from directory browsing, howerver if we remove the Read permission on
> > the Built-in folder for Authenticated Users, the folder still shows up
> > while browsing.
> >
> > Any advice on preventing directory browsing would be appreciated.
> >
> > Also, our testing has shown that if we remove the Read permission from
> > the OU for Authenticated users that also has a GPO assigned to it, the
> > GPO is no longer applied to the clients even though the GPO itself
> > still allows Read access for Authenticated Users.
> >
> > Is this by design?
> >
> > Lyle
> > lhomer@nospam.yahoo.com (remove nospam)
> >
>
>



Relevant Pages

  • Re: Restricted User Group
    ... Personally from what I have seen as where restricted is given permissions ... Authenticated users has it's place and can secure a domain or workstation ... The documentation I have seen about runas or secondary logon has ... >> what I can tell if I use runas and specify an administrator account the ...
    (microsoft.public.windows.server.security)
  • Re: Prevent "Authenticated Users" from browsing Active Directory
    ... properties/security and remove everyone and authenticated users from the ... permissions - that is why I recommend removing the whole group. ... enterprise administrator, schema administrator, administrators, and ... > Any advice on preventing directory browsing would be appreciated. ...
    (microsoft.public.win2000.security)
  • Rights and Effective Permissions in XP Pro
    ... control permissions on and am very perplexed at why thie following is ... CREATOR/OWNER is assigned Full Control to Subfolders and files ... But when I then check a specific-named Account (who *is* an Administrator ... that the same is also true for Authenticated Users (this s/b because it is ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EMERGENCY: Files lost
    ... Windows XP Home Edition, with SP2. ... or other folders and files at that level. ... Administrator, I do have normal access to all files and folders. ... You now need to edit the permissions of every file (step 6 on my page. ...
    (microsoft.public.windowsxp.configuration_manage)
  • Re: User Account Suddenly Unaccessable
    ... Revert to the original profile folder. ... Log on as administrator ... The Sharing tab has "Do not share this folder" checked, and the rest of the tab has no data. ... In the middle section none of the "permissions" categories have any checkmarks - no marks in allow, ...
    (microsoft.public.win2000.general)