Re: How to restrict some users to log in?



The most simple and direct way to do this is to take control over either
the user right to Log on locally, or, the membership of the Users group,
on each machine. You can do either using a GPO linked to the OU that
contains the affected machines (in your case you may want to consider
a minor reorganization so that there is an OU for computers of each lab,
likely as a subOU within the current OU)
You need to be very careful that Authenticated Users and/or Domain
Users are not granted the local login user right, either directly or via
membership in Users (if Users is given that user right)
--
Roger Abell
Microsoft MVP (Windows Server : Security)

"Harvey" <Harvey@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4FA1A0D9-B9CF-4684-9627-CCA2B73D2029@xxxxxxxxxxxxxxxx
We have a Win 2003 domain that has several OUs. Each OU has several
user-groups for different Labs -- for security issues, e.g. file sharing,
printer sharing etc. Currently, all users in a OU can login to any
computer
that
belongs to that OU (not neccessary in the same Lab). Now, a director of a
lab
asks me if there is a way to allow only users in his lab be able to log in
to his lab's computers. That is only one group of users can log in some
computers, but other user-groups cannot log in those computers even they
are
in the same OU. Is it possible to do this? How to do it?

Any help or link is greatly appreciated!

Harvey



.



Relevant Pages

  • members of "user" group cannot access internet
    ... Problem with "user" account: unable to access any internet site; ... Computer lab; 10 PCs with identical hardware & software. ... None of the other 9 computers in the lab have this problem. ... Files can be accessed across the network, but I cannot access the internet ...
    (microsoft.public.windowsxp.configuration_manage)
  • members of "user" group cannot access internet
    ... Problem with "user" account: unable to access any internet site; ... Computer lab; 10 PCs with identical hardware & software. ... None of the other 9 computers in the lab have this problem. ... Files can be accessed across the network, but I cannot access the internet ...
    (microsoft.public.windowsxp.security_admin)
  • Re: advice on setting up lab
    ... A lab with at least three computers is great in my opinion. ... internet name resolution requests to your ISP dns server. ... 802.1X authentication if the WAP and wireless adapters are capable however I ...
    (microsoft.public.cert.exam.mcse)
  • Re: Any creative ideas?
    ... We have a lab with 300++ computers and we need a way to locate a specific ... I was able to run a program on a remote machine that beeped. ... Microsoft MVP Scripting and ADSI ...
    (microsoft.public.win32.programmer.wmi)
  • Re: Two XP Pro problems
    ... membership of the local groups. ... > and both computers are members of the domain. ... > One of the computers clears the Local Administrators group of all accounts ... > Kjartan Þór Kjartansson ...
    (microsoft.public.windowsxp.security_admin)