Denying domain logon to certain users on W2K workstation?

From: Pat Furrie (pat.furrie_at_wesh.com)
Date: 04/27/04


Date: Tue, 27 Apr 2004 12:20:26 -0400

We have several computers on our network which attract casual users due to
their private locations in the office. We have certain domain logon
accounts that we'd like to deny any logon ability at those workstations.
When I put the accounts-in-question into a "Disallow" group on on of these
machines, and then turned off "Logon locally" permissions for that group, I
thought that might prevent (hopefully) them from logging into the domain,
but that didn't happen.

Is there a way to prevent domain users from logging into these workstations?

Pat



Relevant Pages

  • Re: Prove that there is no need for additional domain controller
    ... This could be misconfiguration or overloading. ... Set up a logon script for them and have it record ... Logging on from the main site with same account it takes about ... > accounts when logging on from that site takes about 4 minutes. ...
    (microsoft.public.win2000.active_directory)
  • Logging in takes 20 minutes on SBS
    ... I have a windows 2003 SBS network with 40 users. ... logging in now takes between 15-20 ... accounts and it seems it does not happen on any machine that a user ... logged on to my machine tries to logon, ...
    (microsoft.public.windows.server.sbs)
  • concurrent logins
    ... How can I prevent users from logging in with their accounts more than once ... I they will have to logoff a pc before they can logon to ...
    (microsoft.public.win2000.security)
  • Re: User Login
    ... filtering so that only this group gets the deny logon locally privilegs. ... the domain group called Domain Users is a member of the local ... put those user accounts into domain group and apply a GPO to the OU ... "Meinolf Weber" wrote: ...
    (microsoft.public.windows.server.active_directory)
  • Re: RODC ...
    ... Win2003 DCs with RODC the WAN link between the RODC and RWDC goes ... Only then the users are able to logon if the WAN link is down. ... The Password Replication Policy acts as an access control list. ... The Password Replication Policy lists the accounts that are permitted ...
    (microsoft.public.windows.server.active_directory)