1. In dsa.msc console right click on the Domain Name (example.: lab.local) and click Properites. 2. Click Advanced button in Security tab. 3. Select Permission tab and short the list by Name field. 4. Browse two Authenticated user's entry who has "Apply To" field contain "Descendant User Object" and "Descendant Contact objects" 5. click Edit.. button each entry and Remove these rights.
I have another issue, now when i search a contact using the "company" field, it never returns anything, i can however search using First Name and Last Name.haytham,