On a Win2K server is there a GPO that can limit access to shared directories and files. Or how to create a GPO that can do this. I have many users that have changed the permissions on fils and folders and have caused them selves and other to be locked out of the files. The most common is that a user makes an explicite deny to the everyone group. Useing a GPO to remove the ability to edit the security tabs is what is desired but by certain groups.