The policy you configured and used in this section may interfere with the policies discussed in the sections that follow. To prevent this issue, you should block the effect of the E-mail Alias Generation policy on your test domain before you proceed to the next sections.
To block the effect of the E-mail Alias Generation policy
This scenario describes how to configure a policy to ensure that only non-universal groups are permitted to be created. The script prevents Active Roles from creating universal groups.
The policy is based on a script that detects the group scope setting and disallows the creation of groups with universal scope. The script comes with Active Roles SDK. You can access the Active Roles SDK documentation by selecting Active Roles 7.2 SDK on the Apps page or Start menu, depending upon the version of your Windows operating system.
To implement this policy, you first need to prepare a script module using the Active Roles console.
To prepare the script module
The module RestrictGroupScope is created in the Script Modules container. You can view the script code in the details pane by selecting the module in the console tree.
Once you have prepared the script module, you can create, configure, and apply the Policy Object using the Active Roles console.
To create and apply the Policy Object