Delegation of Windows 2000 Active Directory has been
established for our technical staff and has limited their
access to a degree that allows them to function well.
However, they have access to disable/re-enable user
accounts, which we want to deny. I've searched through
the object classes on the user object, but cannot find the
specific setting that will prevent this access.
Any ideas?
Thanx