    A new version of an application we use can LDAP query AD to use AD to
    authenticate user logons. But it needs a user account at the root of our
    child domain (we have an empty root domain) with read-only access to the
    entire child level -- the app would use this account to search AD. (The old
    version maintained its own database)

    Is this ok security-wise?

  2. Any normal userid in any domain of the forest by default can search all
    userids of AD. The viewability of various attributes will depend
    specifically on your current security configuration.

