remote access permission --
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
remote access permission --

 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory
Author Message
ray
Guest





Posted: Thu Nov 10, 2005 8:20 am    Post subject: remote access permission -- Reply with quote

I have a client with 500 users and we need to search active directory for the
value of the remote access permission (so that they can monitor who has allow
and who has deny access). I am unable to find a way to do this. I have
tried dumping active directory via csvde.ex and ldifde.exe and perfroming a
search for the msNPAllowDialin property without success...

1) how can we search AD for the status of users remote access permission
2) is there a way to set the remote access permission to allow/deny using
GPO -- if not, how would we do this (like maybe allow the right depending on
a group membership...)

thanks

//RB
Back to top
Herb Martin
Guest





Posted: Thu Nov 10, 2005 9:51 am    Post subject: Re: remote access permission -- Reply with quote

"ray" <ray@discussions.microsoft.com> wrote in message
news:653B5BD2-70DF-4D65-9D8E-976517E26361@microsoft.com...
Quote:
I have a client with 500 users and we need to search active directory for
the
value of the remote access permission (so that they can monitor who has
allow
and who has deny access). I am unable to find a way to do this. I have
tried dumping active directory via csvde.ex and ldifde.exe and perfroming
a
search for the msNPAllowDialin property without success...

1) how can we search AD for the status of users remote access permission

DSQuery perhaps? (try /help)

ADSI script? (Or ldap) Search Microsoft for "ADSI script-o-matic" if you
need initial help with scripts....


Quote:
2) is there a way to set the remote access permission to allow/deny using
GPO -- if not, how would we do this (like maybe allow the right depending
on
a group membership...)

1) Set all users to "control access through policy" (using AD Users and
Computers).
Domain must be in "native or Win2003 server native mode".
(Multiple selection works for this, so many users can be set in GUI at
once or
use a script...)

2) Use an RRAS policy based on Group membership (RRAS Polices in the RRAS
MMC)

--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]
Back to top
 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB