I have a namespace created called Dept. Under this lies a target for various Dept shares. ABE is on for both the namespace and the actual shares located on another server. Both are Server 2008 R2. On each target I am using the "Set Explicit View Permissions" and have a security group added. Same setup for all targets but different sec groups.
I then map a drive to the \\domain\dept namespace. Users log in and they get can see the folder for 'their' dept but not the others. That part works great.
Is there a way though to prevent Admins from seeing every single target under Dept when they log in? They also have a dept folder but see all the other depts. Lot of clutter. I removed the admins group from the main Dept folder that houses all the targets and no luck. Im explicitly defining who can see each target and Admins in not added. Im guessing that DFS somehow automatically adds Admins somehow.
Id rather have like a DFS admins only group and not the local admins used if I have to as there are admins that are seeing everything but dont manage dfs. Is this possible or does someone have a suggestion?
Thx
Carito