A. Its possible to restrict access to MMC snap-ins using the Group Policy settings:
- Start Active Directory Users and Computers snap-in (Start - Programs - Administrative Tools - Active Directory Users and Computers)
- Right click on the domain or OU with the Group Policy set and select Properties
- Select the Group Policies tab
- Select the Group Policy you wish to change and click Edit
- Move to User Configuration\Administrative Templates\Windows Components\Microsoft Management Console
- Double click 'Restrict Users to the explicitly permitted list of snap-ins'
- Set to Enabled or Disabled.
- You can then move to "Restricted/Permitted snap-ins" and enable or disable specific snap-ins
If "Restrict Users to the explicitly permitted list of snap-ins" is set to Disabled or Not Configured then the snap-ins are available unless they are explicitly set to "Disabled" under the "Restricted/Permitted snap-ins" folder.
If the "Restrict Users to the explicitly permitted list of snap-ins" is set to Enabled then no snap-ins are available unless the snap-in is explicitly set to "Enabled".