Hi,We have the following scenario:1. We want users to see only the branches/wa's that they have access too2. Planning on using LDAP/AD groups3. branch/workarea security swithed on in iw.cfg4. TeamSite 6.7.1 on Windows Server 2003What is the best approach the achieving the above scenario? For now we are also switching the 'restrict access' on the branch and 'restict access to this workarea' on. Imagine a branch structure looking like the following:main->web->intranet->department->IT-> here there is a workareamain->web->extranet->com->WAmain->web->extranet->uk->WAmain->web->extranet->dk->WANow if a user is to work on the dk branch and the workareas is owned by a super TeamSite user and shared with AD group named ex_dk. The above forces us to add the group to roles on each branch all the way to the top (eg. group added as Editor role to dk, extranet, web, main, default branches).Is there a better approach ?RegardsVaqas