G
Guest
Hello All,
I was wondering, I'm trying to change the ACL's on an OU to block casual
browsing of the contents, but it is also the same top-level OU that will
house our user accounts shortly (that's why I want to block casual
browsing). If I block read access to the OU, then policy doesn't apply
because it can't enumerate the policies attached to that OU. I half solved
it by adding Domain Computers to "Read" but obviously that doesn't help for
user policies. I've tried every configuration of User ACL's that I can
think; of on all the little sub-object types, to no avail. Is this doable
or will I have to live with just having them able to browse the structure?
Any ideas appreciated.
Thanks!
I was wondering, I'm trying to change the ACL's on an OU to block casual
browsing of the contents, but it is also the same top-level OU that will
house our user accounts shortly (that's why I want to block casual
browsing). If I block read access to the OU, then policy doesn't apply
because it can't enumerate the policies attached to that OU. I half solved
it by adding Domain Computers to "Read" but obviously that doesn't help for
user policies. I've tried every configuration of User ACL's that I can
think; of on all the little sub-object types, to no avail. Is this doable
or will I have to live with just having them able to browse the structure?
Any ideas appreciated.
Thanks!