Does anyone know if there is a permission clash if a member of the Domain Admin group is also a member of the Domain User group? I am trying to change group scope of a couple groups in Active Directory, but I can’t, even though I’m a Domain Admin. in my AD user profile, I’m listed as both a Domain Admin, and a Domain User. How does AD handle that? Do denies take precedence over allows with regards to permissions? Sorry for asking a few questions, but they all really tie together. Thanks!