verdammt, da war ich etwas zu schnell, grad die lösung gefunden
Code:
Set objSdUtil = GetObject("LDAP://OU=TEST,DC=TEST,DC=Com")
Set objSD = objSdUtil.Get("ntSecurityDescriptor")
Set objDACL = objSD.DiscretionaryACL
For Each objACE in objDACL
If objACE.Trustee = "TEST\testuser" Then
objDACL.RemoveAce objACE
End If
Next
objSD.DiscretionaryAcl = objDacl
objSDUtil.Put "ntSecurityDescriptor", Array(objSD)
objSDUtil.SetInfo