Hi Srinivas,They have permissions to MediaBin to see everything and do whatever they like.We recently have acquired test server hardware and we are heading down that road to try and reproduce the issue. We haven't had the license or hardware in the past to recreate the issue.I can see a list of all AD groups that the user is associated with and I have looked at every one of those groups to ensure that it not associated to the Windows box.Yes, if we remove users from the Windows groups, they will lose their permissions.So here is an example.1. We do not setup permissions for User A.2. User A connects to server and they can't see anything.3. We grant User A permissions to Windows Group "testing group."4. The "testing group" only has mb permisissions to one container under the $\Production\Test container where $ represents the ROOT.5. The user can see everything. Not just the $\Production\Test group.It seems like the user is part of another elevated permissions group but, we have personally combed through the entire server, all Windows groups, and the AD groups.Thanks for your assistance.