Re: AD permissions

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 03/03/04


Date: Wed, 03 Mar 2004 16:22:58 GMT

It could. For instance I believe read is needed for user to domain, domain
controllers, and users container in order to be able to change passwords and if the
users are in a container that they do not have read permissions then Group Policy
settings for that container will not apply. However if the container is not a default
OU and the user is not in that container nor needs access to anything in that
container via AD search, I believe it will work [assuming you give permissions to
needed groups] but test it out first. You may also want to post in the
win2000.active_directory newsgroup. --- Steve

"Igor Derbyshev" <derbyshev@mail.ru> wrote in message
news:u9Cth8RAEHA.448@TK2MSFTNGP11.phx.gbl...
> Hello. I want to restrict permissions on some of AD OU containers
> by removing Authenticated Users (Read) permission.
> Will everything be ok, or it will produce any unexpected side effect?
>
> --
> Sincerely yours,
> Igor Derbyshev
> MCSA (W2k)
>
>



Relevant Pages

  • Re: how to stop giving out account info?
    ... do you hold any certifications? ... > managing the read permissions in their security properties. ... > container, the container their account resides in, and I believe the ... > able to change their password and Group Policy user configuration will not ...
    (microsoft.public.win2000.security)
  • Re: Domain Users with 2003 adminpak can see AD!
    ... All AD objects have permissions to them somewhat like ntfs ... to access objects in that container via AD. ... > ADUC containers. ... > tool within the administrator tools console. ...
    (microsoft.public.win2000.security)
  • Re: Want to stop sharing Outlook Today folders
    ... node, that's the container whose permissions you'll want to examine, as well ... I just never realized that a User Account profile is referred to ...
    (microsoft.public.exchange.clients)
  • Re: How to set permissions to allow user to edit AD
    ... Drill down to the Container which holds the accounts you want the user to ... the username you wish to give control to manage user accounts and change ... Create a custom taskpad. ... the container you delegated permissions to. ...
    (microsoft.public.windows.server.sbs)
  • Re: CRL failing to publish to AD
    ... went through the permissions on all the container and object permissions ... Services container. ... "Brian Komar " wrote: ... CDP Container tab listed both the Base CRL and Delta CRL, ...
    (microsoft.public.windows.server.security)