' Remove an ACE from a Security Descriptor
Set objSdUtil = GetObject("LDAP://OU=Finance,DC=fabrikam,DC=Com")
Set objSD = objSdUtil.Get("ntSecurityDescriptor")
Set objDACL = objSD.DiscretionaryACL
For Each objACE in objDACL
If objACE.Trustee = "FABRIKAM\kmyer" Then
objDACL.RemoveAce objACE
End If
Next
objSD.DiscretionaryAcl = objDacl
objSDUtil.Put "ntSecurityDescriptor", Array(objSD)
objSDUtil.SetInfo