Active Directory: Access Control on a group of users based on their attribute

Active Directory: Access Control on a group of users based on their attribute

In AD, how can I grant access to password attributes for a group of users without creating a new OU? Is it possible to specify grants based on users' attributes, e.g, grant access on all the users who area member of a group?

Any solution with ACL inheritance etc. would work as long as the users are not moved.  

Thanks


                New to ADSelfService Plus?