Restrict AD User and Local User access to AD LDS?

I have AD LDS installed on a domain joined server (2012 R2). By default, the instance allows AD LDS principal authentication, Windows principal (AD or local) authentication and, optionally, AD LDS proxy authentication. I want to configure proxy authentication, which is well documented, but I also want to prevent any Windows principal authentication. I can find no documentation on restricting those login mechanisms.

Could anyone point me in the right dire

March 10th, 2014 9:27pm

Go through below link which explains in details about :

administrating AD LDS Authentication and Access Control 

Hope, this helps you.

Free Windows Admin Tool Kit Click here and download it now
March 11th, 2014 10:08am

Hi,

According to your description, do you mean that you want to prevent AD users and local users from logging on this proxy server?

If that is the goal, I dont think it is possible.

We can assign Deny log on locally user right to domain user accounts, so that common domain users cannot log on from the local computer, but we cant deny this right for domain admins and local administrator, I have tested this.

Deny logon locally

http://technet.microsoft.com/en-us/library/cc957048.aspx

Please feel free to let us know if there are any further requirements.

Best Regards,

Amy Wang

March 13th, 2014 5:36am

No, I'm not trying to prevent local logon. I'm trying to prevent local accounts and AD accounts from binding to the LDAP service.
Free Windows Admin Tool Kit Click here and download it now
March 13th, 2014 3:15pm

No, I'm not trying to prevent local logon. I'm trying to prevent local accounts and AD accounts from binding to the LDAP service.
March 13th, 2014 3:15pm

Hi,

Sorry for my misunderstanding before.

I am trying to involve someone familiar with this topic to further look at this issue. There might be some time delay. Appreciate your patience.

Best Regards,

Amy Wang

Free Windows Admin Tool Kit Click here and download it now
March 18th, 2014 6:19am

Thanks for your continued efforts, Amy.
March 19th, 2014 10:52pm

Thanks for your continued efforts, Amy.
Free Windows Admin Tool Kit Click here and download it now
March 19th, 2014 10:52pm

Hi

Please try to connect to the ADLDS instance from ADSI EDIT on a DC, then grant users account deny permission on Read box and check if it works.

More information, please look through the article below:

http://technet.microsoft.com/en-us/library/cc816858(v=ws.10).aspx

Thanks.

March 21st, 2014 2:24pm

Thanks for the response. I'll try that in the next couple of days.
Free Windows Admin Tool Kit Click here and download it now
March 27th, 2014 2:00am

Hi,

Any updates?

Regards,

Amy

April 1st, 2014 5:50am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics