J
Josh Messerschmitt
I'm trying to create a setup in AD where each OU from the root represents a
location and under each OU (location) there will be 3 other specific OU's.
I've made groups to represent each site and given them Full Control to their
respective site. I don't want the users in that group to delete any of the
OU's I've created by default, so I set explicit deny 'Delete' rights to each
OU. However, this only works for the OU from the root, not the 3 under that
OU. This doesn't make sense to me - shouldn't deny take precedence? Am I
missing something?
Any ideas?
location and under each OU (location) there will be 3 other specific OU's.
I've made groups to represent each site and given them Full Control to their
respective site. I don't want the users in that group to delete any of the
OU's I've created by default, so I set explicit deny 'Delete' rights to each
OU. However, this only works for the OU from the root, not the 3 under that
OU. This doesn't make sense to me - shouldn't deny take precedence? Am I
missing something?
Any ideas?