Letting users search but not browse Active Directory?

S

Sam Lai

Hello all,

I found this on ntfaq.com on how to let users search but not browse Active
Directory:

Open Group Policy with the Group Policy Editor (GPE).
Navigate to User Configurations, Administrative Templates, Desktop, AD.
Double-click "Hide Active Directory folder."
Select the Policy tab.
Click Enabled, and click OK.
Close the policy.

I did this on one DC2 thinking that it would apply to all, but when I check
Network Neighborhood, I still see Active Directory. I check on the Net
Neighborhood on the DC and its not there. So I went to my other DC1 and
opened gpedit.msc and it appears that the changes I made to DC2 did not
propagate to DC1. So I had to 'enabled' the "Hide Active Directory folder."
again. Restarted my machine, and it is still there?
Am I doing something wrong?

Thanks!
 
M

Matjaz Ladava [MVP]

You have to setup this policy on OU that contains user accounts, not on
Domain Controlers OU. If you have users in Users container, then first
create a OU and move user accounts to that OU. Create new GPO for those
users with settings you found on ntfaq.com.
To see if your DC's are replicating properly run dcdiag, netdiag and
repladmin on your DC. Also check your EventLog.

--
Regards

Matjaz Ladava, MCSE (NT4 & 2000), MVP
(e-mail address removed)
http://ladava.com
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top