Lets say I have users imported from active directory and I have only read only privileges on AD roles (I still can add my sitecore roles on top):
every user is in a generic domainuser role
I have other roles, for instance budgetviewers
I have a folder, budget that should be accessible only to users on budgetviewers role.
so, the typical user accessing to that folder will be on domainusers AND budgetviewers roles
Now, my problem is that deny privileges/inheritance seem to take precedence on "allow privileges". So If domainusers are denied privileges and or inheritance on the budget folder, no matter what i do to the budgetviewer role, the users are not able to see the folder. As every user is in the domainusers folder, no user can access the budget folder. If I don't limit domainusers from seen budget folder, as every user is in that role, every one will see that folder. I don't have privileges/ownership to delete the domainuser role from users. Ho should I approach this. thank you