Re: Log on the domain

From: Chee Heng Chin (chchin@iastate.edu)
Date: 04/15/03

  • Next message: irado@hotpop.com: "Re: TripWire like product"
    To: "Chris Berry" <compjma@hotmail.com>, security-basics@securityfocus.com
    From: Chee Heng Chin <chchin@iastate.edu>
    Date: Tue, 15 Apr 2003 14:14:44 -0500 (CDT)
    
    

    Becareful, if you set this policy the user will not be able to logon to the
    workstation at all. It doesnt mean that he cannot logon as a local user, it
    means he is not allowed to physically logon to the domain through the
    workstation. A user cannot logon locally(example:
    <insert_your_computer_name_here>) if he does not have a local account.

    Chee-Heng Chin, MCSA
    Senior in Computer Engineering
    Iowa State University

     
    > >From: "J.S" <mwharbi@hotmail.com>
    > >How can we enforce the users log on to domain? I mean: Users can not access
    > >computer using admin or any other account, must log on the domain
    > >controller. Is there any policy to do that?
    >
    > Adjust your security policy to deny them the log on locally right.
    >
    > Chris Berry
    > compjma@hotmail.com
    > Systems Administrator
    > JM Associates
    >
    > "Without change, something sleeps inside us, and seldom awakens. The
    > sleeper must awaken." -- Duke Leto Atreides
    >
    > _________________________________________________________________
    > STOP MORE SPAM with the new MSN 8 and get 2 months FREE*
    > http://join.msn.com/?page=features/junkmail
    >
    >
    > -------------------------------------------------------------------
    > Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the
    > world's premier event for IT and network security experts. The two-day
    > Training features 6 hand-on courses on May 12-13 taught by professionals.
    > The two-day Briefings on May 14-15 features 24 top speakers with no vendor
    > sales pitches. Deadline for the best rates is April 25. Register today to
    > ensure your place. www.blackhat.com
    > -------------------------------------------------------------------
    >
    >

    ---------------------------------------------------------------------------
    Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the
    world's premier event for IT and network security experts. The two-day
    Training features 6 hand-on courses on May 12-13 taught by professionals.
    The two-day Briefings on May 14-15 features 24 top speakers with no vendor
    sales pitches. Deadline for the best rates is April 25. Register today to
    ensure your place. http://www.securityfocus.com/BlackHat-security-basics
    ----------------------------------------------------------------------------


  • Next message: irado@hotpop.com: "Re: TripWire like product"

    Relevant Pages

    • RE: Cant set Local Security policies. They fail to save
      ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
      (microsoft.public.windows.server.sbs)
    • RE: Event ID 537 and Kerberos
      ... a logon type of 3 translates to Network. ... Click Services tab and select Hide All Microsoft Services and Disable ... Step 4: Configure account lockout policy. ... and then click Account Lockout Policy. ...
      (microsoft.public.windows.server.sbs)
    • Re: Remote Client Configuration
      ... Thanks for quickly updates. ... Just as I know, if you only logon the domain with cache credential, the ... group policy will not be updates, instead it will use the old policy that ... dial up VPN connection to logon SBS domain once-in-a-while for the group ...
      (microsoft.public.windows.server.sbs)
    • Re: Right & Permissions
      ... i linked the domain controller policy to the ou i created. ... rsop.msc on the workstation i get "invalid namespace error". ... user in AD and have them as a member of the admin group also and when i logon ... to the workstation with that user i do not have admin rights?? ...
      (microsoft.public.windows.group_policy)
    • RE: Remote Desktop not working after SP1
      ... "The local policy does not permit you to logon interactively" error message ... Remote Desktop Users ... Use the ISAinfo utility to collect the ISA configuration information: ...
      (microsoft.public.windows.server.sbs)