Opinion on using external secure LDAP for SSO authentication?


hi guys,

we 2008r2 forest , domain levels.  have adfs setup , try use kind of stuff, wanting business vendor wants external secure ldap.  have put in firewall rule keep exposing our ad internet, , have put dc out in our dmz.  guessing make rodc.  have give them account query with, passwd not change.  thinking that and could probably limit exposure using "log on to" tab include the dmz dc, , we could deny interactive logins.  have them certificate(not sure if use internal , have them trust it, or go public one.  can tell not big fan of this, have never done before , not sure how large corporations go down road.  guess can work fine, suggestions or opinions on security perspective appreciated.

thanks,

dan


dan heim

hi,

hi,

thanks posting in microsoft technet forums.

i trying involve familiar topic further @ issue. there might time delay. appreciate patience.

thank understanding , support.


vivian wang
technet community support



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...