Windows 2000 Active Directory reveals too much information.

From: news.tamu.edu (andrerojde2004_at_gmail.com)
Date: 11/11/04

  • Next message: Andrea: "Re: File permission: none!"
    Date: Thu, 11 Nov 2004 09:57:30 -0600
    
    

    I installed the Windows 2000 Administration Pack on a desktop and launched
    it as a regular user (no admin rights on the domain), and I was able to see
    just about everything in Active Directory, like what groups exist, what the
    individual settings are for all users, groups, objects. Basically
    everything was visible, but actions such as reset password and create new
    user were not enabled.

    I looked at individual security settings for each user and seems like the
    group "Everyone" and "Authenticated Users" has Read access. I read up on
    Active Directory security and Microsoft says to keep the default settings.
    These are the default settings.

    So how do I make Active Directory not reveal so much information?


  • Next message: Andrea: "Re: File permission: none!"

    Relevant Pages

    • Re: After W2k SP4 installation Active Directory not accessible
      ... Neither of the registry settings you mentioned have been ... been added to any of the XP machines. ... messages in the system log for the DCHP Server he had me ... Controller and using Active Directory. ...
      (microsoft.public.win2000.active_directory)
    • Re: Changing a users name in Active Directory
      ... login name, and by clicking on the Exchange tab you should be able to change ... I would additionally suggest setting up another mailbox with the user's old ... don't forget to change her account settings within ... If you're not using active directory, similar changes will have to be made ...
      (microsoft.public.windows.server.active_directory)
    • Re: Automatically locking desktop after a certain period of time
      ... Since you're on Active Directory, force the use of a screen saver and a timeout and password requirement via Group Policies. ... These settings are in User Configuration, Administrative Templates, Control Panel, Display. ... > the computer automatically lock after a certain amount of time (like some ...
      (microsoft.public.windowsxp.security_admin)
    • RE: CANT CONNECT TO AD (VERY URGENT!!)
      ... If you can ping the gateway and DC, it may be your settings. ... DNS that is provided points to you primary and secondary DNS servers. ... "Tom B" wrote: ... to fix the active directory. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Cant get LDAP to work
      ... I've certainly played around in Directory Access enough... ... Active directory ... These settings are not so obvious and even on our Network, ... MVP: http://mvp.support.microsoft.com/ MVPs.org: http://www.mvps.org/ Retirez NoSpam de mon adresse pour m'écrire/Remove NoSpam to e-mail me ...
      (microsoft.public.mac.office.entourage)