Re: Should I "Deny logon locally" to ANONYMOUS LOGON, Everyone and Gue

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 05/14/05


Date: Sat, 14 May 2005 05:40:55 -0700

Oli gave you a good pointer, that Deny overrides affirmative grants,
and denying Everyone would mean no account could log in except
over the network.

There is really no reason to use Deny Logon Locally except where
some account do have a grant to Logon Locally due to the groups
given that right. For example, if Users is allowed to login but there
are a couple of account in Users that should not be able to log on.

-- 
Roger Abell
Microsoft MVP (Windows  Security)
MCSE (W2k3,W2k,Nt4)  MCDBA
"Silly" <Silly@discussions.microsoft.com> wrote in message
news:57C2CC48-5875-43DB-8CE1-006C42AE2117@microsoft.com...
> What will be affected if I enable the "Deny logon locally" to those
groups?
> Thanks


Relevant Pages

  • Re: Trusted SQL Connections & NT AUTHORITYNETWORK SERVICE
    ... SYSTEM account in terms of the credentials it uses on the network. ... hitting a SQL Server on the same machine as the web app. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Problem: No Network Connections under Guest Account
    ... The Guest Account on my other computer seems to ... Sounds like you might have more of an issue with your network than with the ... network connection settings. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: ATTN : Microsoft - Security Event 529....Second Request for help....
    ... According to the events, the logon ... failure is from the local machine account. ... disconnected from the network. ... Security Event ID 529 is a failure audit for logon/logoff. ...
    (microsoft.public.windows.server.sbs)
  • Re: Problem: No Network Connections under Guest Account
    ... The Guest Account on my other computer seems to ... Sounds like you might have more of an issue with your network than with the ... network connection settings. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Writing to a network share
    ... probably running into the "double hop" issue, where impersonation will not work across two network hops. ... An unhandled exception occurred during the execution of the current web request. ... Highlight the ASP.NET account, and check the boxes for the desired access. ... I've changed machine.config process model to the SYSTEM account. ...
    (microsoft.public.dotnet.security)