Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I want to delegate control and hide some OU's from users who browse the AD,
mainly the Builtin OU as it as the members of admin groups and so forth.By removing the list content attributes for Authenticated Users, the OU is
invisible but I saw some problems; users are unable to authenticate via a
firewall because it does not have access to the SAM_USER and SAM_DOMAIN
object types which are accessed through the Builtin OU. I suspect that by
rendering the OU invisible other problems could arise.All my admin accounts (SYSTEM, etc..) have Full Control on the OU.
How can I go around this problem and still prevent users from browsing the
OU?

![]() |
w2k clustering
|
buying new server!!
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |