Re: Deny Logon Locally

From: Ben Smith [MS] (bensmi@microsoft.com)
Date: 08/01/02


From: Ben Smith [MS] <bensmi@microsoft.com>
Date: Wed, 31 Jul 2002 21:58:55 -0700


In article <ai9k8b$12aakk$1@ID-56130.news.dfncis.de>, Justus
(justus@dotcool.com) writes...
> If I am using AD and want me users to have to logon to a the domain and not
> logon to there computer locally is there something I can implement in a
> domain policy or group policy? I was reading about deny log on locally but
> was not sure if that prevented from logging on to the machine all together.
> I don't want any of my users using any local users for the computers only
> logging on through the domain. What is the best way to implement this? Some
> of the user already have administrator accounts locally so they know how to
> create new local accounts. Any help or suggestions would be appreciated.
> -Thanks
> Justus
>
>
>

Ensure that the users do not have local accounts or cached
credentials and that they do not know the local Administrator
password.

-- 
Ben Smith
Microsoft Training and Certification
Are you secure? http://www.microsoft.com/security
This posting is provided “AS IS” with no warranties, and confers no 
rights.


Relevant Pages

  • Deny Logon Locally
    ... If I am using AD and want me users to have to logon to a the domain and not ... domain policy or group policy? ... was not sure if that prevented from logging on to the machine all together. ... I don't want any of my users using any local users for the computers only ...
    (microsoft.public.win2000.security)
  • Re: Deny Logon Locally
    ... Don't give them local ID's on the computers and then they can only logon to ... > domain policy or group policy? ... > logging on through the domain. ...
    (microsoft.public.win2000.security)
  • Re: New employee, same computer -- what to do?
    ... Doesn't that name become a local logon? ... The only local accounts you have to have are administrator and guest ... there's no real need to rename user accounts to ensure ... Let's see, I want to print to the $100 label printer, which *is* hung ...
    (microsoft.public.windows.server.active_directory)
  • Re: New employee, same computer -- what to do?
    ... The only local accounts you have to have are administrator and guest (the ... "Marketing department") permission to a resource, ... good domain logon password, but everyone has access to all the shared ... there's no real need to rename user accounts to ensure people ...
    (microsoft.public.windows.server.active_directory)
  • Re: Re: How to allow any domain user to logon to a XP Pro PC
    ... Server or advanced server and you create a domain by using DC promo ... (goes with logon hours). ... Local accounts should be limited to only those that need to be there - ... ie best case scenario -- local administrator. ...
    (microsoft.public.windowsxp.security_admin)