Re: how to restrict users to search in their own Organizational Unit



Hi
By default evryone has read-access to AD.
To deny that right you must create a security group and deny read permission, then add the users to that security group.

--
*************************************************
I hope that the information above helps you
Good Luck

Jorge Silva

MCSA + Exchange + MSCE
*************************************************

<lao.nightwolf@xxxxxxxxx> wrote in message news:1165851126.530572.226750@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
We are currently implementing MOSS2007.
However if a user is trying to add users and he looks up users in
Active Directory, then he can see all users in Active Directory.
How can you limit a user within an Organizational Unit so he can only
search for users within his OU?

We have:

DC=domain, DC=com
OU=companyA, DC=domain, DC=com
OU=companyB, DC=domain, DC=com
OU=companyC, DC=domain, DC=com

Ideal scenario would be that users from OU=companyA can only search
within their OU=companyA, and cannot see users in the other OU's.


.



Relevant Pages

  • Re: how to restrict users to search in their own Organizational Unit
    ... Jorge Silva schreef: ... To deny that right you must create a security group and deny read ... permission, then add the users to that security group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Cant assign calendar permissions to a group
    ... to be able to use a security group so that I can manage membership of ... By testing I have verified that a resource calendar's permissions can ... integral concept within Active Directory. ... Only individual users can be granted membership. ...
    (microsoft.public.exchange.admin)
  • Re: can we remove a user from "EVERYONE" group
    ... > -Add an explicit deny to that security group on the folders they ... then stated that he couldn't logon locally as admin anymore. ... member of the domain users group. ...
    (microsoft.public.win2000.general)
  • Re: Filtering on a Security Group to Apply a Group policy
    ... an OU - I need to use the already created OU's to attach a new Group Policy ... to and make sure the Group Policy is only applied though to certain computers ... And I do this by creating a security group and adding the pc's ... break that are tied into Active Directory. ...
    (microsoft.public.windows.server.active_directory)
  • Re: New ISA 2004 Rule Not Working
    ... properties for both the deny and allow rules. ... It ignores the deny for the user and hits on the SBS protected network ... Limited Access Users is a User set made up of the AD security group I ...
    (microsoft.public.windows.server.sbs)