I want to stop Account Operators from being able to enable user accounts residing within a particular OU. I have tried to add the deny permission for the "Write userAccountControl" property for user objects for the Account Operators group. The effective permissions continue to show full control, however. Can anyone tell me what am I missing? Thanks.
Bookmarks