Educause Security Discussion mailing list archives
Re: Active Directory, Sensitive Data, Row Level Security
From: Brad Judy <Brad.Judy () COLORADO EDU>
Date: Mon, 11 Dec 2006 15:34:48 -0700
One of AD's strengths as an LDAP service is granular access control, although it can get complex and there can be ACL bloat if you go too far. To accomplish what you've suggested, one would change the permissions on user objects to allow "SELF" full read, but not grant that level of access to "domain users" or "everyone". Be careful messing with permissions as users will need some level of read access to each other for some processes/functions. As with my last e-mail, I recommend you bring the question to the Windows in Higher Education list. Brad Judy University of Colorado at Boulder -----Original Message----- From: William Custer [mailto:custerwl () MUOHIO EDU] Sent: Monday, December 11, 2006 12:57 PM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: [SECURITY] Active Directory, Sensitive Data, Row Level Security Miami University is evaluating a proposal to expand Active Directory service widely in support of Exchange e-mail. Unlike SunOne LDAP, information on all records in Active Directory appears to be available for query even when bound to an ordinary (unprivileged) user. Whereas SunOne LDAP displays to the ordinary user, only the rows associated with that user, Active Directory displays the rows for all users. Has anyone configured Active Directory to restrict queries by unprivileged users to return only the rows associated with that user?
Current thread:
- Active Directory, Sensitive Data, Row Level Security William Custer (Dec 11)
- <Possible follow-ups>
- Re: Active Directory, Sensitive Data, Row Level Security Brad Judy (Dec 11)
