<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>RO Windows Administrators Weblog &#187; Organizational Unit</title>
	<atom:link href="http://www.winadmin.ro/tag/organizational-unit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.winadmin.ro</link>
	<description>Weblogul adminilor de Windows din Romania.</description>
	<lastBuildDate>Mon, 06 Feb 2012 15:23:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Cum poti ascunde Organizational Unit-uri in Active Directory</title>
		<link>http://www.winadmin.ro/2011/06/03/cum-poti-ascunde-organizational-unit-uri-in-active-directory/</link>
		<comments>http://www.winadmin.ro/2011/06/03/cum-poti-ascunde-organizational-unit-uri-in-active-directory/#comments</comments>
		<pubDate>Fri, 03 Jun 2011 11:04:24 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Organizational Unit]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2011/06/03/cum-poti-ascunde-organizational-unit-uri-in-active-directory/</guid>
		<description><![CDATA[Pe vremuri raspundeam la intrebarea asta cu nu se poate, insa pe parcurs am aflat si eu cateva metode prin care ai putea sa faci anumite OU-uri invizibile pentru anumiti administratori. Atentie ca nu ma refer la Domain Admins. By default orice user din AD are drept de Read &#38; List Contents peste toate obiectele [...]]]></description>
			<content:encoded><![CDATA[<p>Pe vremuri raspundeam la intrebarea asta cu nu se poate, insa pe parcurs am aflat si eu cateva metode prin care ai putea sa faci anumite OU-uri invizibile pentru anumiti administratori. Atentie ca nu ma refer la Domain Admins.</p>
<p>By default orice user din AD are drept de Read &amp; List Contents peste toate obiectele din AD, asta fiind motivul pentru care toate obiectele sunt vizibile din ADUC.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb.png" width="370" height="468" /></a></p>
<p>Dar sa luam cazul in care vrem sa gazduim in AD-ul nostru doua companii iar administratorii delegati peste obiectele din AD nu au voie sa vada decat OU-ul companiei lor. Daca am lasa totul default, lucrurile ar arata asa:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image1.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb1.png" width="644" height="292" /></a></p>
<p>Iar daca am scoatem Authenticated Users din ACL-ul companiei B si ne conectam cu un user normal:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image2.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb2.png" width="644" height="326" /></a></p>
<p>Ii blocam cumva accesul user-ului la acel OU insa tot il va vedea, ca Unknown bineinteles pentru ca nu ii poate citi nici macar ACL-ul.</p>
<p>Ca sa facem sa dispara complet acel OU, e nevoie sa activam List Object Mode. Asta se face activand DsHeuristics pe 001 (mai exact al treilea bit trebuie setat pe 1; daca aveti si alti biti setati, lasati-i in pace). </p>
<p>Detalii la <a title="http://technet.microsoft.com/en-us/library/dd346510.aspx" href="http://technet.microsoft.com/en-us/library/dd346510.aspx">http://technet.microsoft.com/en-us/library/dd346510.aspx</a></p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image3.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb3.png" width="594" height="484" /></a></p>
<p>Setarea se aplica la nivel de forest. Nu este necesar reboot. </p>
<p>Imediat dupa modificare putem vedea ca in ACL-uri apare si List Object:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image4.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb4.png" width="368" height="468" /></a></p>
<p>Ca sa facem sa dispara un OU, de exemplu “Company B”, e nevoie sa scoatem List Contents de pe containerul Hosting:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image5.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb5.png" width="369" height="471" /></a></p>
<p>Iar pe containerul Company B, scoatem si List Contents si List Object (merge si daca scoatem List Object, insa List Contents va bloca si queryurile LDAP):</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image6.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb6.png" width="364" height="470" /></a></p>
<p>Iar rezultatul este urmatorul:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image7.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb7.png" width="644" height="256" /></a></p>
<p>Pe scurt: List Contents scos de pe containerul parinte, List Object si List Contents de pe child.</p>
<p>Ce am facut eu pana acum a fost doar sa restrictionez vizibilitatea acestui OU pentru Authenticated Users, mai departe puteti asigna permisiuni de Read/List Contents/List Object pentru userii/grupurile ce vor avea access.</p>
<p><strong>ATENTIE</strong> la grupul Pre-Windows 2000 Compatible Access. Daca aveti activata aceasta optiune, atunci Authenticated Users o sa faca parte din acest grup. Ori dati remove ori modificati permisiunile si pentru Pre-Windows 2000 pentru ca altfel nu o sa mearga.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2011/06/image8.png"><img style="border-bottom: 0px;border-left: 0px;margin: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2011/06/image_thumb8.png" width="406" height="469" /></a></p>
<p>Si cam asta e tot, pentru intrebari va astept pe forum.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2011/06/03/cum-poti-ascunde-organizational-unit-uri-in-active-directory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protecting AD OUs from accidental deletion</title>
		<link>http://www.winadmin.ro/2010/01/28/protecting-ad-ous-from-accidental-deletion/</link>
		<comments>http://www.winadmin.ro/2010/01/28/protecting-ad-ous-from-accidental-deletion/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 12:59:11 +0000</pubDate>
		<dc:creator>Andrei Ungureanu</dc:creator>
				<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[ACL]]></category>
		<category><![CDATA[Organizational Unit]]></category>
		<category><![CDATA[Permissions]]></category>

		<guid isPermaLink="false">http://www.winadmin.ro/2010/01/28/protecting-ad-ous-from-accidental-deletion/</guid>
		<description><![CDATA[&#160; Incepand cu Windows 2008, in consola Active Directory Users and Computers exista o optiune care protejeaza OU-urile de la stergerea accidentala: Iata ce se intampla cand vrem sa-l stergem: Ca sa puteti sterge un OU, trebuie sa debifati&#160; “protect object from accidental deletion”. E bine gandita optiunea; am intalnit cazuri in care unii admini [...]]]></description>
			<content:encoded><![CDATA[<p>&#160;</p>
<p>Incepand cu Windows 2008, in consola Active Directory Users and Computers exista o optiune care protejeaza OU-urile de la stergerea accidentala:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/01/image51.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/01/image_thumb43.png" width="439" height="484" /></a></p>
<p>Iata ce se intampla cand vrem sa-l stergem:</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/01/image52.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/01/image_thumb44.png" width="644" height="453" /></a> </p>
<p>Ca sa puteti sterge un OU, trebuie sa debifati&#160; “protect object from accidental deletion”. E bine gandita optiunea; am intalnit cazuri in care unii admini au sters containere intregi cu toate obiectele din ele si a trebuit sa apelez la restore din backup.</p>
</p>
<p>&#160;</p>
<p>Dar ce facem daca folosim Windows 2003? Nici o problema, exista solutie si aici.</p>
<p>Setam Deny pe Delete si Delete Subtree in Advanced security settings.</p>
<p><a href="http://www.winadmin.ro/wp-content/uploads/2010/01/image53.png"><img style="border-bottom: 0px;border-left: 0px;border-top: 0px;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/01/image_thumb45.png" width="644" height="454" /></a> </p>
<p>Iar pe containerul parinte (in cazul meu e domain root) setam Deny pe Delete All Child Objects.</p>
<p align="left">&#160;</p>
<p align="left"><a href="http://www.winadmin.ro/wp-content/uploads/2010/01/image54.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/01/image_thumb46.png" width="644" height="454" /></a></p>
<p align="left">Iata ce se intampla cand incercam sa stergem Organizational Unit-ul.</p>
<p align="left"><a href="http://www.winadmin.ro/wp-content/uploads/2010/01/image55.png"><img style="border-bottom: 0px;border-left: 0px;float: none;margin-left: auto;border-top: 0px;margin-right: auto;border-right: 0px" border="0" alt="image" src="http://www.winadmin.ro/wp-content/uploads/2010/01/image_thumb47.png" width="644" height="450" /></a></p>
<p align="left">Operatiunea afecteaza doar OU-ul Test_Delete, fara a afecta obiectele din el (inclusiv OU-uri) si recomand a fi setat pe containerele top level cu foarte multe obiecte.&#160; </p>
]]></content:encoded>
			<wfw:commentRss>http://www.winadmin.ro/2010/01/28/protecting-ad-ous-from-accidental-deletion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

