How do I restrict users from using the 'Active Directory Users and Computers MMC' snap-in?
NetIQ Group Policy Administrator 5.0
Directory and Resource Administrator 6.x
Directory and Resource Administrator 7.x
Group Policies allow the means to limit which Microsoft Management Console (MMC) snap-in can be executed. This is found in a Group Policy Object (GPO) for any given Organizational Unit (OU) in the following location and is called Restricted/Permitted Snapins:
- User Configuration\Administrative Templates\Windows Components\Microsoft Management Console
The following Microsoft Documentation details how to restrict access to a permitted list of snap-ins for a domain: