允许用户仅在Active Directory中的自己的OU中枚举帐户的策略

时间:2022-06-06 02:57:41

Is it possible to define a policy which restricts a user to enumerate only accounts in his own OU?

是否可以定义限制用户仅枚举其自己的OU中的帐户的策略?

For example lets consider a domain Contosos and OUs Sales and HR.The Sales OU has two users A and B and the HR OU has users C and D.

例如,我们考虑域Contosos和OU Sales和HR。Sales OU有两个用户A和B,HR OU有用户C和D.

Is it possible to define a policy so that A can only enumerate accounts A and B and C can only enumerate C and D and not the accounts not in their OU?

是否可以定义一个策略,以便A只能枚举帐户A和B,C只能枚举C和D,而不能枚举不在其OU中的帐户?

2 个解决方案

#1


Don't do That!

不要那样做!

But, you can create a group for each OU and put the ou users inside the group. Than you can change the permission on every other OU to deny this group the "list content" permission. I don't think that there is a way to configure this without scripting. But as the rule is simple it can be scripted.

但是,您可以为每个OU创建一个组,并将ou用户放入组中。您可以更改每个其他OU的权限,以拒绝该组的“列表内容”权限。我不认为有一种方法可以在没有脚本的情况下配置它。但由于规则很简单,因此可以编写脚本。

That said. I would advise you not to dare and change the active directory default permission without having a dedicated group of experts on this specific subject. You can quite easily render your network useless with just a few clicks. And even if you don't, there is a chance that programs that have expectation from active directory security ( without even realizing this ) will suffer from subtle errors.

那就是说。我建议你不要在没有关于这个特定主题的专家组的情况下不敢更改活动目录默认权限。只需点击几下,您就可以轻松渲染网络。即使你不这样做,有可能从活动目录安全性(甚至没有意识到这一点)期望的程序将遭受微妙的错误。

So the rule is. If you have to ask, don't do it. if you need to become an expert, then:

所以规则是。如果你不得不问,不要这样做。如果你需要成为专家,那么:

http://www.google.com/search?hl=en&q=active+directory+permission+site:microsoft.com&btnG=Search

Update: The "If you need to ask" rule refers to asking on a public site like this. Where non-experts, like me, can give you potentially misleading information, as mine can be( I hope not, but...). I am not sure that your requirement don't have a simple solution. But as far as I know, this is a path that burned more than few brave souls.

更新:“如果您需要询问”规则是指在这样的公共网站上询问。像我这样的非专家可以给你潜在的误导性信息,就像我的一样(我希望不是,但......)。我不确定您的要求没有简单的解决方案。但据我所知,这条道路焚烧的勇敢灵魂不止于此。

#2


Good point! I myself have no idea about how to do it, however Igal Serban's answer touched me. He is right, in public forum, if you take immature suggestions you will pay much for it. I was bite for such reason once.

好点子!我自己也不知道怎么做,不过Igal Serban的回答让我感动。他是对的,在公共论坛上,如果你采取不成熟的建议,你会为此付出很多。我曾经因为这样的原因而咬了一口。

Read some books or consult some experts!

阅读一些书籍或咨询一些专家!

#1


Don't do That!

不要那样做!

But, you can create a group for each OU and put the ou users inside the group. Than you can change the permission on every other OU to deny this group the "list content" permission. I don't think that there is a way to configure this without scripting. But as the rule is simple it can be scripted.

但是,您可以为每个OU创建一个组,并将ou用户放入组中。您可以更改每个其他OU的权限,以拒绝该组的“列表内容”权限。我不认为有一种方法可以在没有脚本的情况下配置它。但由于规则很简单,因此可以编写脚本。

That said. I would advise you not to dare and change the active directory default permission without having a dedicated group of experts on this specific subject. You can quite easily render your network useless with just a few clicks. And even if you don't, there is a chance that programs that have expectation from active directory security ( without even realizing this ) will suffer from subtle errors.

那就是说。我建议你不要在没有关于这个特定主题的专家组的情况下不敢更改活动目录默认权限。只需点击几下,您就可以轻松渲染网络。即使你不这样做,有可能从活动目录安全性(甚至没有意识到这一点)期望的程序将遭受微妙的错误。

So the rule is. If you have to ask, don't do it. if you need to become an expert, then:

所以规则是。如果你不得不问,不要这样做。如果你需要成为专家,那么:

http://www.google.com/search?hl=en&q=active+directory+permission+site:microsoft.com&btnG=Search

Update: The "If you need to ask" rule refers to asking on a public site like this. Where non-experts, like me, can give you potentially misleading information, as mine can be( I hope not, but...). I am not sure that your requirement don't have a simple solution. But as far as I know, this is a path that burned more than few brave souls.

更新:“如果您需要询问”规则是指在这样的公共网站上询问。像我这样的非专家可以给你潜在的误导性信息,就像我的一样(我希望不是,但......)。我不确定您的要求没有简单的解决方案。但据我所知,这条道路焚烧的勇敢灵魂不止于此。

#2


Good point! I myself have no idea about how to do it, however Igal Serban's answer touched me. He is right, in public forum, if you take immature suggestions you will pay much for it. I was bite for such reason once.

好点子!我自己也不知道怎么做,不过Igal Serban的回答让我感动。他是对的,在公共论坛上,如果你采取不成熟的建议,你会为此付出很多。我曾经因为这样的原因而咬了一口。

Read some books or consult some experts!

阅读一些书籍或咨询一些专家!