I figured it out. I basically did everything I already did, but chose deny for list directory contents on C:, then on folders I want the group to access, I unchecked inherit permissions, and set the to modify.
Now one more question, since I cannot create additional containers in AD, is it OK...