Hi All and thanks for taking the time to read my question.
I have a Windows 2003 Native Domain.
I have been asked whether it is possible to ensure that a single AD group cannot be added to any another AD group.
After playing with the security on a test global group called TEST1, I have managed to stop any AD object being added via the memberOf tab on the TEST1 group properties by changing the Write and Read MemberOf attributes. But if I go to another group, lets say TEST2, I can easily add TEST1 as a member.
Is it possible to stop TEST1 being added to any other group via the Members tab?