<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Florian's Blog</title>
	<link>http://www.frickelsoft.net/blog</link>
	<description>Words on Group Policy, Active Directory and Infrastructure stuff</description>
	<pubDate>Sat, 12 May 2012 11:31:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.1</generator>
	<language>en</language>
			<item>
		<title>Hiding information in AD</title>
		<link>http://www.frickelsoft.net/blog/?p=288</link>
		<comments>http://www.frickelsoft.net/blog/?p=288#comments</comments>
		<pubDate>Sat, 12 May 2012 11:31:39 +0000</pubDate>
		<dc:creator>florian</dc:creator>
		
		<category><![CDATA[Active Directory]]></category>

		<category><![CDATA[Active Directory administration]]></category>

		<category><![CDATA[Active Directory attributes]]></category>

		<guid isPermaLink="false">http://www.frickelsoft.net/blog/?p=288</guid>
		<description><![CDATA[I’m still reading the Forums now and then, although I am not posting as much there as I have in the past. Reasons being, time, motivation and the overall quality of the Forums – but that is a different topic.
What I’ve come across lately at least twice, is a question that can be summed up [...]]]></description>
			<content:encoded><![CDATA[<p>I’m still reading the Forums now and then, although I am not posting as much there as I have in the past. Reasons being, time, motivation and the overall quality of the Forums – but that is a different topic.<br />
What I’ve come across lately at least twice, is a question that can be summed up to:<br />
“<em>How can I hide information in Active Directory (from specific users)</em>?”</p>
<p>Since we’re a technical blog here, let’s discuss the technical possibilities first. There are</p>
<ul>
<li>The Active Directory confidentiality bit</li>
<li>Permission assignment to objects/attributes in Active Directory.</li>
</ul>
<p>As for (1), the confidentiality bit is a bit set for these attributes in the Schema, so that they are no longer readable to “normal” users. You essentially modify the searchFlags attribute. More on the confidentiality bit: <a href="http://blogs.dirteam.com/blogs/tomek/archive/2005/11/21/confidential-bit.aspx">http://blogs.dirteam.com/blogs/tomek/archive/2005/11/21/confidential-bit.aspx</a>. If you have read the article and comments below, you’ll notice that the confidentiality bit is only half-way through a good idea. Admins and “Account Operators” still can read. And it won’t work for “Category 1” attributes (<a href="http://www.frickelsoft.net/blog/?p=227">http://www.frickelsoft.net/blog/?p=227</a>). If you have extended the Schema and store the secret stuff in your own attribute, this may be a way to go – granted that you have a very controlled Administrators League and know who “Account Operators” are and that they are OK to handle the information in there.</p>
<p> <a href="http://www.frickelsoft.net/blog/?p=288#more-288" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.frickelsoft.net/blog/?feed=rss2&amp;p=288</wfw:commentRss>
		</item>
		<item>
		<title>Group Policy Settings Excel update</title>
		<link>http://www.frickelsoft.net/blog/?p=287</link>
		<comments>http://www.frickelsoft.net/blog/?p=287#comments</comments>
		<pubDate>Thu, 10 May 2012 08:10:34 +0000</pubDate>
		<dc:creator>florian</dc:creator>
		
		<category><![CDATA[Group Policy]]></category>

		<guid isPermaLink="false">http://www.frickelsoft.net/blog/?p=287</guid>
		<description><![CDATA[I am sure some of you are already playing with Windows 8 and Windows Server 2012.
Microsoft Download has an updated Excel spreadsheet of the well-known Group Policy Settings Excel - it contains Windows 8 and Windows Server 2012 beta settings:
http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&#38;id=25250
The Azure-based online search tool Group Policy Search http://gps.cloudapp.net has not been updated yet.
]]></description>
			<content:encoded><![CDATA[<p>I am sure some of you are already playing with Windows 8 and Windows Server 2012.</p>
<p>Microsoft Download has an updated Excel spreadsheet of the well-known Group Policy Settings Excel - it contains Windows 8 and Windows Server 2012 beta settings:</p>
<p><a href="http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&amp;id=25250">http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&amp;id=25250</a></p>
<p>The Azure-based online search tool Group Policy Search <a href="http://gps.cloudapp.net">http://gps.cloudapp.net</a> has not been updated yet.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.frickelsoft.net/blog/?feed=rss2&amp;p=287</wfw:commentRss>
		</item>
		<item>
		<title>Setting &#8216;Block Inheritance&#8217; on the domain level? WTF!?</title>
		<link>http://www.frickelsoft.net/blog/?p=286</link>
		<comments>http://www.frickelsoft.net/blog/?p=286#comments</comments>
		<pubDate>Wed, 07 Mar 2012 22:09:54 +0000</pubDate>
		<dc:creator>florian</dc:creator>
		
		<category><![CDATA[Group Policy]]></category>

		<category><![CDATA[GPMC]]></category>

		<category><![CDATA[Group Policy Application]]></category>

		<guid isPermaLink="false">http://www.frickelsoft.net/blog/?p=286</guid>
		<description><![CDATA[Hey ho - long time no hear. I won&#8217;t make any promises any more and just go on with the blog posting :-)
I got an email from a fellow AD/GPO/Exchange big brain (where &#8220;fellow&#8221; relates to AD/GPO, I am no Exchange big brain). He was sending a screenshot of GPMC with essentially the following information [...]]]></description>
			<content:encoded><![CDATA[<p>Hey ho - long time no hear. I won&#8217;t make any promises any more and just go on with the blog posting :-)</p>
<p>I got an email from a fellow AD/GPO/Exchange big brain (where &#8220;fellow&#8221; relates to AD/GPO, I am no Exchange big brain). He was sending a screenshot of GPMC with essentially the following information on it:</p>
<p><img hspace="-1" vspace="0" border="0" src="http://www.frickelsoft.net/blog/pictures/block-inheritance-domain-level.jpg" height="380" width="510" /></p>
<p> <a href="http://www.frickelsoft.net/blog/?p=286#more-286" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.frickelsoft.net/blog/?feed=rss2&amp;p=286</wfw:commentRss>
		</item>
	</channel>
</rss>

