No announcement yet.

AD object permissions

  • Filter
  • Time
  • Show
Clear All
new posts

  • AD object permissions

    Anyone knows how to prevent a Security Group to be a part of other Groups through AD Object permissions?

    During the new Group creation process, all new groups are made "member of' the that one Group. Where we can potentially get into some big trouble is when the members exposed to othe databases to all other users on the system. Is it possile to structure AD in some way so that Group-A can *never* be included under the other group's tab? I heard something can be done with AD Object permissions.

  • #2
    Re: AD object permissions

    you should use Group Policy for this, insted of Object permissions.

    The GPO you want is "Restricted groups"
    Please do show your appreciation to those who assist you by leaving Rep Point