We have a MOSS 2007 farm and are using AD Security Groups to populate
the SharePoint groups in our site collections. On various sites we have
the Domain Users with view privelages, we also have an AD Security Group
named Contractors that while it's members are a part of the Domain Users
group, we need to disallow or exclude them from the sites while still
allowing the remaining Domain Users privelages.
Coming from the Network Folder structures it was simply denying the
group access, I was going to try adding the Contractors to a group
without privelages (an empty SharePoint permissions group) but you have
to assign at least 1 privelage to a SharePoint group (open).
Creating a seperate group in AD would be far to cumberson on our domain.