Hello All,
I would like to know if any of you have tried and succeeded at locking down access for authenticated users to Active Directory content. One of our clients has a need to restrict read access to certain Organizational Units.
They have the standard Active Directory integrated applications (MS Exchange, SQL databases, IIS) etc. running and have a few in-house developed web applications that too rely on access to Active Directory content.
They would like to take away read access for all Authenticated Users except the users and delegated admins of those OUs, but are hesitant to try it because they’re not sure of what all might get impacted (; it being a production domain, its hard to actually try it, and its hard to repro the whole production environment into a test environment.)
If you too have encountered this problem, it would be helpful to hear of how you may have accomplished such a thing, and if there were any things to look out for.
Thanks,
- CF