We have an LDAP server set up with our Active Directory. When users login to a Linux machine with LDAP client installed as root, they are able to su - into any Active Directory account without needing that users password. This is a big security risk, does anyone know why this is or how to prevent this?
Preventing root access is not an option unfortunately as it is required by some users in some cases.