Home > Windows Security Tips > > Active Directory security concerns
Windows Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Active Directory security concerns


Serdar Yegulalp, Contributor
04.19.2006
Rating: -2.67- (out of 5)


Advice for securing Windows
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


The structure of Active Directory (AD) -- the formatting of records, the type of information stored in it, etc. -- is referred to as its schema. Since AD is basically a database, the default schema is not set in stone and it can in fact be changed if needed. That said, extending the AD schema is not something you want to do trivially. The presence of third-party products that do this can complicate the issue, especially as far as security is concerned.

The first thing to be conscious of when using these products is that any additions to the schema are typically available by default in a read-only fashion to everyone. If you extend the schema, you also need to take into account what kind of access to grant to the new schema elements -- who gets to add or change these new elements, whether or not they can be seen by most users, etc.
For more information
  • Create usable boundaries within AD
  • Active Directory admin tips
  • Likewise, if you're extending the schema to work with a custom or third-party application (or if the app itself is making the changes), you should regard those changes as a possible security hole unless they are explicitly dealt with by the app itself or by work you do.

    Also, schema changes cannot be undone without rolling back the AD store as a whole. You can modify or deactivate a given class or attribute, but changes cannot be deleted completely. If you can spare the time and resources, set up an isolated test forest (perhaps via Microsoft Virtual Server) where you can try out the results of your schema extensions in a controlled way. If the extensions you're considering are pretty major or may have an impact on the way AD is routinely accessed and changed, it will absolutely be worth the time and effort.

    About the author: Serdar Yegulalp is editor of the Windows Power Users Newsletter. Check it out for the latest advice and musings on the world of Windows network administrators -- and please share your thoughts as well!


    Rate this Tip
    To rate tips, you must be a member of SearchWindowsSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.


    Submit a Tip




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Configuration and Deployment
    How to use a GPO to improve Windows folder security
    Remote management for Windows system upgrades
    How to recover from lost BitLocker PINs and startup keys
    Deny access to Windows system properties with GPOs
    Rights management in Windows: Security expert roundup
    How to manage network access for single users in AD
    Windows server access management in Active Directory
    Securely manage Windows file sharing and folder permissions
    Windows Server 2008: Looking good on the security front
    Group Policy settings replace manual proxy settings
    Configuration and Deployment Research

    Active Directory security for Windows
    Managing Windows network access security tutorial
    Managing a single access pc in Windows network
    Proper procedure for locking down GPOs?
    Active Directory Security School
    Active Directory security school: Set up and configuration
    Active Directory security school: Management
    Active Directory security school: Maintenance and testing
    Permitting Ping: ICMP Exceptions
    Proper server settings in Windows Server 2003
    Should I give my access control group admin rights?
    Active Directory security for Windows Research

    Other Microsoft Tools
    Vista SP1 vs. XP SP3 -- upgrade or business as usual?
    Web security features of Internet Explorer 8
    Data encryption with EFS and BitLocker, step by step
    Windows Integrity Control (WIC) in Vista
    Prevent data loss with Encrypting File System (EFS)
    PatchGuard defends against rootkits in Windows Vista
    What's hot in Windows security: Ins and outs of Windows Server 2008
    Security tools that limit user logon in Windows
    Windows Vista's security features: One year later
    Cheap Microsoft licenses for security pros: Microsoft Action Pack

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    BitLocker  (SearchWindowsSecurity.com)
    Microsoft Antigen  (SearchWindowsSecurity.com)
    Next Generation Secure Computing Base  (SearchWindowsSecurity.com)
    WS-SecureConversation  (SearchSoftwareQuality.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsWebcastsWhite PapersIT DownloadsBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts