Views:

To resolve the issue:

  1. Create a new user (dsadmin) and a new group (dsadmins/Global Security Group) in Active Directory Users and Computers.

    dsadmin user

  2. Check the properties of the dsadmin user and make sure it has the following settings:
    • The User must change password at next logon check box is unticked.
    • The Password never expires check box is ticked.

    Account Password settings

  3. Add the dsadmin user as a member of the dsadmins group.
  4. Set the dsadmins group as the default group.
  5. Remove the Domain Users group under the Member of tab list.

    dsadmins group

  6. Select the View tab and activate the Advanced Features in Active Directory Users and Computers.

    Advanced Features

  7. Perform the following steps on the OUs you want to hide from the DSM console.
    1. Right-click the OU you want to hide and choose Properties.
    2. Choose the Security tab and add the dsadmins group.
    3. Deny the read privileges to the dsadmins group for the OU.

    Hide OU

  8. After setting the necessary rights, add the Active Directory in the DSM with the credentials of dsadmin user.

    Adding Active Directory

The Active Directory tree of the DSM will now only show the computers of the OUs, which you did not deny the read permission.

Active Directory