Re: Restrict computers user in an OU or Group can log on to

From: JeffJ (JeffJ_at_discussions.microsoft.com)
Date: 08/23/04


Date: Mon, 23 Aug 2004 08:13:48 -0700

Thanks for your reply, but I don't think overriding all local policies for
Deny Logon Local seems to be a very good idea. XP machines all have local
guest, support, and ASPNET accounts disabled by default. Other software’s
may be adding to this also. With over 1500 computers I don't feel like
checking them all :-( If local policies where not being already used this
would seem the logical method as I stated at first in paragraph 3, but with
Microsoft now adding so much stuff to this right out of box I'm very
apprehensive to override it. Before XP and .NET there didn't used to be
anything in here from local policy but now Microsoft is using it. Giving
ASPNET access again would be a violation of what Microsoft is trying to do in
this case.

I'm still leaning towards adsi script to add all computers in one OU to all
user in another OU "Log on To" workstations.

Anyone have this script or a better method, or a convincing argument for
group policy method both Steven and I have thought of?

"Steven L Umbach" wrote:

> User rights are strictly computer policy. If you want to restrict users to logon to
> certain group of computers, put those computers in an OU, create a GPO for that OU
> and add the global group for those users to the logon locally user right [ along with
> administrators and other allowed users] . Then at the domain level and or other OU's
> add that global group to the deny logon locally user right to the GPO's. Group Policy
> is applied in this order - local>site>domain>OU where the last applied policy is the
> effective policy if settings are defined at multiple levels. I would not worry about
> overriding local policy. It will be much easier to manage policy at domain/OU
> evel. --- Steve
>
>
> "JeffJ" <JeffJ@discussions.microsoft.com> wrote in message
> news:F4F41598-0B08-41D1-AA8F-2C116E1CD872@microsoft.com...
> > I'm looking for a method to restrict what computers a set of users can log on
> > to.
> > The problems I see are this if I use Account "Log on to".. in Active
> > Directory the maintenance will be quite extreme as I will have quite a few
> > users in this group and the machines I do want them to sign on to are a
> > load-balancing cluster via thin clients with a fairly dynamic number of
> > machines in cluster, as we seem to be constantly adding new machines.
> >
> > If I use Deny Logon Locally in Group policy and then apply to entire domain
> > stopping inheritance in OU that has machines to connect to, it overrides all
> > local Deny Logon Locally in local policies, which seems to be a very bad idea.
> >
> > I think what is really needed is a Loop back for Computer portion not just
> > User of Group Policy, or Merge instead of replace on Group Policy, or Log on
> > to in User part of Group policy or something.
> >
> > I'm kind of guessing we will have to script with "Log on to", but want to
> > know if there is a better answer.
> >
> > Thanks,
> >
> > JeffJ
> >
>
>
>



Relevant Pages

  • Re: Scanning for unsecure shared folders
    ... be of help in securing your machines and it can be used on remote machines. ... then your network will be more secure. ... and bypass any Group Policy user configuration and reconfigure the computer. ...
    (microsoft.public.win2000.security)
  • RE: Content Advisor
    ... set in Group Policy do not apply to client machines. ... I suggest we check the following registry key on both client and server. ... Enable Content Advisor on the client first then apply the group policy. ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange OWA 2003 Trusted Root Certificate
    ... DNS looks to be fine. ... And if these machines reboot, ... and I can see this in the Group Policy Results Wizard in GPMC. ... > a network connectivity, dns name resolution, or domain computer account ...
    (microsoft.public.win2000.security)
  • Re: How to reduce default time out period at logon
    ... modifications to Group Policy, and those accounts won't be tied to any home ... home drives on particular machines (you could disable it in user manager, ... > accomplished this using IPsec filtering via group policy, ... > the default 'time out' period or by disabling the mapping of home ...
    (microsoft.public.windowsxp.general)
  • Re: XP Pro - Logging on to Domain issues
    ... Active Directory Group Policy to pump this setting out to all machines in ... and click on Logon - enable the policy. ... > Group Policy and it is "Always wait for the network at computer startup ... >>> XP Pro machines that are joined on the domain and rebooted cannot ...
    (microsoft.public.windowsxp.network_web)