Pokazywanie postów oznaczonych etykietą ADAM. Pokaż wszystkie posty
Pokazywanie postów oznaczonych etykietą ADAM. Pokaż wszystkie posty
2022-11-18
ADAM - LDS - how to authenticate/create accounts
Just for remember - every account created in ADAM/LDS is disabled by default. There is the dedicated attribute ms-DS-User-Account-Disabled which should be - if we want to use this account to login/authenticate - switch from default 'true' to 'false'. I spent too many hours to guess why I've got strange LDAP errors 49 with strange codes and sometime message said that is something wrong with account.
2018-11-04
to use AD LDS (previously ADAM) or not?
Why to use (in 2018/2019) LDS service if we have ADFS, Active Directory and clouds? From my experience in IT:
- it is much easier (mentally) to extend schema in dedicated directory service nor in Active Directory
- there are many older applications or they want just use LDAP not ADFS and You want do it more secure than giving access to production directory service
- you can have multiple instances of the same data or with different settings and scopes of attributes, for example You can give only login names and phone numbers for company A and the same data with group membership for company B without access to not needed data
- it is very lightweight - of course - if You will create application with wrong long queries You can kill every server - I saw it at one company - they didn't use group membership info and they try to find membership by browsing groups - one by one to find in which groups user is a member of. They have 20-40k users and 25k groups so please, imagine, how can it work. After my review I pointed them, that memberof property is available in OpenLDAP, AD LDS and almost in every modern directory service.
- it can be fully separated from main domain in scenario with publishing data in not secure environment - passwords can be sychronized as well
Subskrybuj:
Posty (Atom)