Re: Small company Best Way to allow customers AD logon



As I read you post, they are telling you to place your AD infrastructure
into an unneeded exposure to risk (of data privacy at least) all for the
sake of convenience in maintaining accounts for externals.
If that is true, tell them they are crazy, or at least very short sighted.
Suggest ADAM, or an ADFS implementation if these corporate externals.

"jremmc" <jremmc@xxxxxxxxxxxxxx> wrote in message
news:uUxx7UWvGHA.2260@xxxxxxxxxxxxxxxxxxxxxxx
Small company. W2K3 SP1. Empty root with 2 DCs and one child domain with 2
DCs. No DMZ. (public site hosted elsewhere). No customer access up to now,
but now find need for it.

Customers need to access a 3rd party application on a member server. That
app now uses own database for authentication. It can use LDAP queries to
AD for authentication (different app than posted about few days ago but
same mfgr), which is what app manager wants to do, as maintaining db is
time consuming. But if app switches to AD for authentication it must use
AD for all authentication (i.e. can't use AD to validate employees and
also use own db for customers.)

I of course do not want to add any non-employees to AD. But...

Any suggestions on ways to set up customers in AD appreciated. (i.e.
separate OU, separate domain, ???, deny read rights to all containers
except ?)

Thanks,
jremmc



.



Relevant Pages

  • Re: Small company Best Way to allow customers AD logon
    ... Customers need to access a 3rd party application on a member server. ... app now uses own database for authentication. ... separate OU, separate domain, ???, deny read rights to all containers ...
    (microsoft.public.windows.server.security)
  • Small company Best Way to allow customers AD logon
    ... No customer access up to now, ... Customers need to access a 3rd party application on a member server. ... app now uses own database for authentication. ...
    (microsoft.public.windows.server.security)
  • RE: Beginners Questions
    ... We do use Windows form on the presentation layer which is on ... terminal server and call web services on the business logic side. ... of using "proxy" authentication on SQL Server. ... > I have written an app with a Windows Forms UI that is deployed to clients ...
    (microsoft.public.dotnet.distributed_apps)
  • Re: Function name not found
    ... are casual canned-software-only customers? ... I have an app that has just ... certain Reference changes from version to version in MDBs, ... Looking at you Startup function, the first thing I see is a DFirst ...
    (microsoft.public.access.modulesdaovba)
  • Authentication Sharing Across Apps
    ... For my part "B" question that I had (Login App was not returning ... authentication to calling app), I found the solution. ... Basically, in both the Login App and Calling App Web.Config, I did ... authenticated connection with SQL server. ...
    (microsoft.public.dotnet.framework.aspnet.security)