If you right click on root of AD and go to Properties then select security tab, there are 2 groups (Everyone & Authenicate Users) with read access by default. My question is does those 2 groups need to be there? What would happen if I remove them from it. I am trying to lock down our AD or audit who can view what. Thanks advance for any feed back.