Anonymous LDAP on Windows 2003

G

Guest

I am in the position that I have to allow anonymous LDAP operations on our
2003 domain controllers. I know that this was allowed by default on Windows
2000, but has been changed on Windows 2003. I wonder what the consequences
are regarding security, and is there any other way of restricting anonymous
access to all objects in AD once it is allowed?

Thanks,
 
A

aaron

I was in this same situation. I enabled anonymous logon for the domain at
the domain level. Then I granted read access to "anonymous logon"to only
the OU's that I needed. We had to do this because the RADIUS servers are in
a different domain/forest and wouldn't authenticate users.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top