I need to configure my AD instance such that regular non-admin users cannot look up any other user information in the same domain. Is there a best practices way to go about it? It’s looking like I’ll have to do a schema level update on the user object, and run a script to strip existing permissions.