Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Yes, Active Directory can deny a user or group read access through the object’s discretionary access control list (DACL). Use an explicit Deny ACE only for a documented exception—such as excluding a Payroll-Restricted group from a broad Helpdesk read grant. For most environments, least-privilege allow rules, separate OUs, or attribute-level protection are safer and easier to maintain.
The procedure below shows how to scope a deny, test its real effect, avoid common inheritance traps, and recover if an ACL change disrupts administration or applications.
Decide what you actually need to restrict
“Read access” is not one permission in AD DS. A security descriptor can control:
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →- Read Property (RP): reading attribute values.
- List Contents (LC): enumerating children in a container.
- List Object (LO): visibility of a particular object in directory-enumeration scenarios.
- Read Permissions (RC): reading the object’s security descriptor.
- Object-, class-, property-set-, and attribute-specific rights.
These rights are independent. Denying RP may leave an object name or distinguished name visible. Denying a list right may not prevent a client that already knows the distinguished name from reading permitted attributes. Microsoft notes that AD DS does not enforce List Object checks by default, so LO alone is not a dependable “hide this object” switch (dsacls reference).
#1 Best Overall
- Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
- ABIS BOOK
- Packt Publishing
| Requirement | Usually preferred |
|---|---|
| No administration, but ordinary visibility is acceptable | Remove write/delegation rights; do not deny read unnecessarily. |
| No ordinary properties | Narrow Read Property restriction on the object or descendant class. |
| Object may be visible, but one value is sensitive | Attribute-specific permission or a confidential attribute. |
| No container enumeration | Review List Children, List Object, parent permissions, and LDAP search scope. |
| Broad Helpdesk read access with one excluded group | Explicit deny for that exception group, carefully scoped and tested. |
| Separate administrative boundary | Separate OU/container and group-based delegation. |
AD object and attribute protection is described in Microsoft’s object-and-attribute protection guidance.
Why Deny is an exception, not the default
An explicit deny can override access a user would otherwise receive through a broad group such as Authenticated Users, Domain Users, or a delegated Helpdesk group. That makes it useful for a narrow exception, but fragile as a general design. It can affect nested-group members, service accounts, synchronization and inventory tools, backup products, address books, and scripts. Later role changes can also make a forgotten deny surprising.
Windows evaluates applicable ACEs in order. The result depends on the user’s complete access token, nested and transitive group membership, explicit versus inherited ACEs, inheritance flags, the requested access mask, and object-specific rights. Do not reduce this to “deny always wins.” Microsoft’s DACL and ACE guidance recommends allow-based least privilege in normal designs and explains ACE ordering.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #2
A deny is also not a boundary against a determined forest or domain administrator. An authorized principal with ownership, permission-change, or equivalent privileged rights can generally take ownership or rewrite the ACL (Microsoft privileged-account guidance).
Safe GUI procedure in Active Directory Users and Computers
The following fictional example protects OU=Payroll,DC=contoso,DC=com from CONTOSOPayroll-Readers-Blocked, while a separate recovery group remains able to administer it. Labels can vary slightly by Windows Server and RSAT version.
- Create a dedicated security group. Add test accounts first; do not begin with production users.
- Record the current ACL. Export or otherwise capture the target security descriptor and identify a recovery account that is not in the deny scope.
- In Active Directory Users and Computers, select View → Advanced Features if advanced object controls are not visible. Right-click the OU or object, choose Properties → Security → Advanced. Microsoft documents the Advanced Features context in its ADUC management guidance.
- Select Add, choose the restricted group, and create an ACE with Deny only for the required right—for example, Read all properties if the business requirement truly covers ordinary attributes. Expand the entry and review the underlying rights; GUI checkboxes can be broader than expected.
- Set Applies to deliberately. Prefer Descendant user objects (or the exact object class) over all descendants when only user objects are affected. Choose This object and all descendant objects only when that is the documented requirement. Avoid a deny on the domain root without extensive lab validation.
- Check inheritance and ACE order. Ensure the recovery or approved administrative principal is not accidentally denied.
- Apply the change, allow replication to the domain controllers used by applications, and test with real non-administrative credentials.
Object-specific ACEs should not be added casually; Microsoft cautions that administrators must understand AD object security before changing them (reference).
Rank #3
Inspecting and applying permissions with dsacls
dsacls.exe displays and changes AD object ACLs. Start by inspecting the target:
dsacls "OU=Payroll,DC=contoso,DC=com"
A representative inherited deny for Read Property on child objects is:
dsacls "OU=Payroll,DC=contoso,DC=com" ^
/D "CONTOSOPayroll-Readers-Blocked:RP" ^
/I:S
/Dadds a deny ACE.RPmeans Read Property./I:Sapplies the inheritable permission to child objects rather than necessarily the OU itself.
This is a template, not a universal “deny all reading” command. Depending on the outcome, you may need to address list permissions, security-descriptor reads, a particular object class, or an individual property. Microsoft’s dsacls documentation covers grant, deny, inheritance, object-type, and property-specific syntax. Validate every command in a lab and preserve a rollback copy.
Rank #4
For comparison, a property-specific grant can be expressed as:
dsacls "CN=User1,OU=Payroll,DC=contoso,DC=com" ^
/G "CONTOSOPayroll-Auditors:RP;telephoneNumber"
Test effective access under the real user token
Do not test only as Domain Admin or as the account that changed the ACL. Use the restricted account, an approved reader, a user who belongs to both a broad allow group and the restricted group, affected service accounts, and the recovery account.
For a PowerShell test session:
runas /user:CONTOSOTestRestrictedUser powershell.exe
Then query the directory from that session:
Import-Module ActiveDirectory
$searchBase = "OU=Payroll,DC=contoso,DC=com"
Get-ADUser -Filter * -SearchBase $searchBase -Properties mail,telephoneNumber,department |
Select-Object SamAccountName,DistinguishedName,mail,telephoneNumber,department
Get-ADUser supports search base, scope, LDAP filters, and selected properties (cmdlet reference). A denied operation may return an error, omit an object or attribute, or produce a partial result depending on the LDAP client.
Best Value
Test each of these separately:
- Base-scope read of a known object.
- OU search and subtree search.
- Ordinary attributes and the specifically protected attribute.
- Queries against the domain naming context and, where used, a Global Catalog.
- LDAP searches made by provisioning, HR, monitoring, backup, and other service accounts.
Repeat tests against the domain controllers or LDAP endpoints used by the application. ACL changes replicate through AD; topology and site-link state determine when each controller sees the change.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Protecting one attribute instead of an entire object
If users should find an object but must not read one sensitive value, denying the whole object is usually excessive. Use an attribute-specific ACE or the confidential-attribute model. A confidential attribute is marked in the schema through searchFlags and requires the appropriate extended control-access permission. Schema changes require change control and compatibility testing; they are intended for application or security-sensitive values, not as a substitute for sound OU design.
Microsoft documents an important Windows Server 2025 behavior: LDAP operations involving confidential attributes require an encrypted connection to domain controllers running Windows Server 2025. Clients that worked against earlier DC versions may otherwise return a missing attribute or INSUFF_ACCESS_RIGHTS (Microsoft troubleshooting guidance). Use LDAP signing/sealing or TLS as appropriate for the client.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteThe ADUC property list is filtered and may not show every attribute. Microsoft explains that Dssec.dat controls this list; ADSI Edit can expose a fuller set (filtered-properties guidance).
Protected accounts, inheritance, and AdminSDHolder
Objects in protected administrative groups can receive permissions from AdminSDHolder and SDProp rather than normal OU inheritance. An inherited deny placed on the parent OU may therefore not behave as expected for those objects. Conversely, changing AdminSDHolder affects every protected object and is a high-impact operation. Check the target’s protected status before relying on inherited permissions; configure protected objects directly only with a documented design. Microsoft’s protected-account guidance also warns that write access to protected group membership can enable privilege escalation.
Troubleshooting common results
- The object is still visible: You may have denied Read Property but not enumeration rights, or the client may already know the distinguished name. Review parent List Children, List Object enforcement, and search behavior.
- Properties are missing but the search succeeds: This can be the expected result of an attribute or property-set restriction. Inspect the exact requested attributes.
- The deny appears ineffective: Check nested group membership, ACE order, inheritance, object class, requested access mask, and the test account’s actual token.
- A protected administrator is unaffected: Check AdminSDHolder and SDProp rather than assuming parent OU inheritance applies.
- Only some domain controllers show the result: Verify replication and test the endpoint used by the application.
- An application breaks: Restore the prior ACL if necessary, then identify the exact LDAP query and grant the service account only the minimum required permission.
- Confidential-attribute reads fail after a DC upgrade: Use an encrypted LDAP connection and verify client support for Windows Server 2025 requirements.
Rollback and governance
Every production deny should have a change ticket, business owner, affected OU or object class, restricted group, exact rights, inheritance scope, test evidence, and rollback method. Keep a separate controlled recovery account or group outside the deny scope. Export the ACL before editing, test restoration in a lab, and periodically review both group membership and ACL changes. If administrators are locked out, an authorized owner or permission administrator must restore the DACL; do not assume a normal user can undo it.
Quick Recap
Operational checklist
- Requirement distinguishes object access, attribute reads, enumeration, security-descriptor reads, and transport encryption.
- Allow-only, separate-OU, or attribute-level alternatives were considered.
- A dedicated group—not individual users—is used for the exception.
- The deny is limited to the smallest rights, object class, and subtree.
- ACE order, inheritance, nested groups, and AdminSDHolder status were reviewed.
- Non-administrator, approved-reader, service-account, Global Catalog, and recovery tests passed.
- ACL export, rollback account, change owner, and periodic review are documented.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

