RE: [ActiveDir] Deny Read Permissions to Group Policy

2006-05-31 Thread Darren Mar-Elia
Anthony- Unfortunately, the GPMC does not expose Deny ACEs in the same neat way that it exposes Allow. What you have to do is go into the Advanced view on Security Filtering, and essentially add the Deny ACE manually for that group using the good old ACL Editor. The easiest way to do a GP deny is t

RE: [ActiveDir] Deny Read Permissions to Group Policy

2006-05-31 Thread Crawford, Scott
Why not just create a sub OU and put the 55 people in there? To deny rights to apply, you need to be on the Delegation tab and click on Advanced. Add a group and deny them the right to Apply Group Policy. Deny permissions tend to make things difficult to understand, so I think a better option wou

RE: [ActiveDir] Deny Read Permissions to Group Policy

2006-05-31 Thread Tony Murray
On the Scope tab of the GPO in the GPMC look at the Security Filtering section. The default is to have the policy applied to "Authenticated Users". Probably the easiest option for you is to: - Create a group and add the 55 users as members. - Remove "Authenticated Users" from the Security Filter