Re: Access Control to LDAP on AD?

From: Roger Abell [MVP] (mvpNoSpam_at_asu.edu)
Date: 10/15/05


Date: Fri, 14 Oct 2005 22:17:54 -0700

I believe you can not realistically do that as an account will at times
be issuing Ldap queries, behind the scenes, sometimes against
the GCs, just to function as a domain client. Also, not all Ldap
queries are authenticated queries so if your objective is to
avoid a potential DoS from malicious queries they may try to
side-step your efforts using unauthenticated binds if they are
allowed to communicate with the ldap and gc ldap ports.

-- 
Roger Abell
Microsoft MVP (Windows Server : Security)
MCDBA,  MCSE W2k3+W2k+Nt4
<-> wrote in message news:uL$IzaS0FHA.3188@TK2MSFTNGP14.phx.gbl...
> Is there a way to block certain user accounts from performing LDAP queries 
> on Active Directory?
>
> If anyone could let me know I would be most appreciative.
> 


Relevant Pages

  • Re: Turning off secured LDAP on Win2K domain controllers?
    ... You are trying to performa LDAP queries anonymously, ... Setting Directory Permissions The following ... > user name and "use secure password authentication" in order to pull LDAP ...
    (microsoft.public.win2000.security)
  • Re: Access Control to LDAP on AD?
    ... >I believe you can not realistically do that as an account will at times ... > be issuing Ldap queries, behind the scenes, sometimes against ... Also, not all Ldap ...
    (microsoft.public.windows.server.security)
  • Re: Access Control to LDAP on AD?
    ... >I believe you can not realistically do that as an account will at times ... > be issuing Ldap queries, behind the scenes, sometimes against ... Also, not all Ldap ...
    (microsoft.public.platformsdk.security)
  • Re: Access Control to LDAP on AD?
    ... >I believe you can not realistically do that as an account will at times ... > be issuing Ldap queries, behind the scenes, sometimes against ... Also, not all Ldap ...
    (microsoft.public.security)
  • Avoid using DNS for hostname name resolution in ldap_bind_s
    ... perform LDAP queries with LDAP directories (Active Directory, ... host.domain.com) the LDAP API is trying to perform DNS queries to ... I have the relevant hostname & ip in a local hosts file and I would ...
    (microsoft.public.windows.server.active_directory)