Paxton, Darren wrote: > The other question though, regarding one-way from AD to FDS - anyone > got any thoughts on that? The sync code wasn't designed to allow this. However there are a couple of things you could consider : 1. configure FDS access control to disallow modifications on attributes that are sync'ed to AD. If there are no pretinent modifications then nothing will get sync'ed to AD. 2. Hack the code to turn off the FDS->AD (outbound) change propagation.