They are NOT part of the "Account Operators" group.Then they cannot create or edit anything in AD. They can only browse AD. This is the expected behavior. So you shouldn't be concerned at all.
Before I do the group policy is there anything else I can try or check??I am not aware of anything else. If you want to prevent users from browsing the tree, just configure the policy.
Before I do the group policy is there anything else I can try or check??