Prevent users to check names from other OU's


we have multiple users in different ou's. when users edits permissions on local machine he's able see users other ou's.

is there way prevent users checking these names. user must stil able check names own ou.

any suggestion welcome

hi remco8888  ,

 

thanks posting here.

 

according mentioned , think going to disallow users not included in ou to see or list object of ou .

if misunderstand ,please let me know.

 

base on knowledge , can achieved set ou security permission ,here workaround reference:

i assume ou’s name is “people” , “hide”

 

1.       create security group called “visible”(can name) , make users of “people” ou member of group(this can done selecting users under “people” ou , right click “add group”)

2.       right click on “hide” ou go properties->security->advanced , click on add. add “visible” group , click ok open "permission entry” box. make sure “apply onto” been selected “ object , child objects”. check box of “deny” “list contents” , “ok”

3.       login 1 of user account of “people” ou , see if can see users of “hide” ou.

 

thanks.

 

tiger li


please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.


Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file