When syncing to an AD Domain it does not update the "Full Group Path"
for an endpoint if it has been moved in the Domain. It only seems to
show the first OU that it was detected in and no matter where the object
gets moved to in AD it always shows th...
You should just point your visitors DNS to your ISP's DNS (or any DNS
really, who cares). There is no way to block them from resolving IP
addresses if you let them access your DNS and if there is any DNS
vulnerability then it is a possible attack vec...