The challenge here is to understand which security identity is being used to
query AD and then restrict the access to the user objects it can see.
I'm guessing this account is the one that runs the application pool for the
front end web site. If this is set to Network Service, then you'd need to
change it to a named Domain account. It's likely that PS users reside
across many AD OU's making it difficult/impossible to dynamically assign
constrained access.
Another option would be to use another directory (Domain/ADAM/LDS) which
contains only PS user objects and to sync the accounts with the main
directory with MIIS or ILM2.
Paul
--
Did this post help you. Consider passing on the good will by making a
donation this great charity.
http://www.fundraiseonline.co.nz/TheProjectServerGuru/
http://theprojectserverguru.spaces.live.com