>AD has a COM interface. That may be easier. I think the person doing the setup will need elevated Admin rights. > > >>I recognize the correct AD way is to have a group for each client and to assign the correct rights to the group. >> >>What I am concerned is that we may need to create more than 600 groups, each with data in a different directory, and that the process is likely to be error prone. >> >>For that reason I'd like to automate the assignment of rights via Powershell scripts (created and run from VFP) so that we can be confident that the rights are assigned correctly as long as the Powershell script is debugged and the customer (group) root directory is stored correctly in our table. >> >>Alex