What is the most effective way to DENY via Access Templates all Authenticated Users the ability to Read a specific attribute in the entire domain, but then ALLOW very specific groups/accounts to Read that same attribute.
In a quick test, the DENY overrides the ALLOW (seems logical), but not the desired outcome.
Any suggestions.