RE: How do I set up Xaraya to authenticate against MS Active Directory?
"Jonn Beames" <jbeames-tp0iMJ/[email protected]>
| Newsgroups | gmane.comp.cms.xaraya.knowledge-base |
|---|---|
| Message-ID | <3E2029CC5EA57E498C7BB197F877EBDE926023@e2k-1.schwabfoundation.org> |
In regards to: the LDAP Admin ID does not need to be an Active Directory administrator. The "LDAP Admin ID" user account used to bind to the Active Directory LDAP service does not require any special privileges. As far as I can tell, its minimum requirements are that it is "enabled" and that it is not "locked out." I created an account, denied remote access and terminal service access, restricted delegation, restricted password changing, required Smart card for interactive logon (effectively disabling desktop logon), did not create an associated Exchange account, added it to the Domain Guests group, and removed it from the Domain Users group. This account could still be used with Authldap to authenticate other enabled Active Directory users, as long as it was itself enabled and not "locked out." I'm no Active Directory expert, so additional information on locking down an LDAP bind account would be welcomed. PS sorry about the previous post... don't know what happened to the text I had added.