Educause Security Discussion mailing list archives

Re: Active Directory, Sensitive Data, Row Level Security


From: Brad Judy <Brad.Judy () COLORADO EDU>
Date: Mon, 11 Dec 2006 15:34:48 -0700

One of AD's strengths as an LDAP service is granular access control,
although it can get complex and there can be ACL bloat if you go too
far.  

To accomplish what you've suggested, one would change the permissions on
user objects to allow "SELF" full read, but not grant that level of
access to "domain users" or "everyone".  Be careful messing with
permissions as users will need some level of read access to each other
for some processes/functions.  

As with my last e-mail, I recommend you bring the question to the
Windows in Higher Education list.

Brad Judy

University of Colorado at Boulder 

-----Original Message-----
From: William Custer [mailto:custerwl () MUOHIO EDU] 
Sent: Monday, December 11, 2006 12:57 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Active Directory, Sensitive Data, Row Level Security

Miami University is evaluating a proposal to expand Active Directory
service widely in support of Exchange e-mail.  Unlike SunOne LDAP,
information on all records in Active Directory appears to be available
for query even when bound to an ordinary (unprivileged) user.  Whereas
SunOne LDAP displays to the ordinary user, only the rows associated with
that user, Active Directory displays the rows for all users.

Has anyone configured Active Directory to restrict queries by
unprivileged users to return only the rows associated with that user?

Current thread: