Anyone has an idea how to "Out Scope" a subtree (or user-type) placed
inside the UA-scope?

In configupdate on the UA the scope is set to ou=first,o=top
In ou=second,ou=first,o=top I have users which should not be allowed to
login to UA.
Users placed in ou=third,ou=first,o=top and ou=fourth,ou=first,o=top
should be able to login to UA.

All of the users are active accounts with "Live Passwords" so we can
not disabled them or set random passwords.
The user types has different aux classes attached which we could filter
on if possible.

Any input would be very welcome.

- martin

