the_Grinch wrote: » 1. Launch GPO editor Launch you GPO editor and navigate to the OU that contains the machine(s) that you wish to apply this GPO to. 2. Create a new GPO Right click on the OU and select 'Create a GPO in this Domain and link it here' from the available options. Give the new GPO an appropriate name. 3. Edit the new GPO Right click on the new GPO and click Edit. This will now open the Group Policy Management Editor. 4. Setting the GPO To select the service that you wish to edit, navigate to: Computer Configuration >> Windows Settings >> Security Settings >> System Services Locate the services that you wish to restrict, right click and select 'Properties'. Place a check box in the 'Define this policy setting' and select the appropriate startup mode. 5. Securing the Service Click on 'Edit Security' and amend the security settings as you would any other Windows setting. If you wanted to secure this service using AD groups, you could create the group, assign users to this group and then add this group to the security settings here. This will effectively target users to deny access etc. Something like that?