Hi, we are tring to replace with ADS with Fedora DS, In ADS the following can do, when the client login into ADS domain. 1) Right click disable for clients 2) Block/Allow the specific software installation 3) Can override the users local setting by group policy eg) password expire, if the local user set the password expire date to 5 days, the ADS can override to 3 days. 4) Disable the client to change the internet options-> to modify the proxy server name. 5) Do the software updates to clients from ADS, if the client not updated properly. 6) Block/Allow the regedit from ADS. now we are able to PDC with samba using FedoraDS, and each user can able to login and their profile can create in either common storage or localstorage of FedoraDS server. Can any one suggest howto fullfill the above points. regards Karthikeyan.N