Re: Disabling Interactive Login

From: -KK- (KK_at_discussions.microsoft.com)
Date: 08/24/05


Date: Tue, 23 Aug 2005 17:00:03 -0700

Is it possible to create this sort of a policy and apply it only to a Group
of users rather than to a whole Domain..? My biggest concern is applying a
policy that will lock all users down, this is only required for users in a
specific OU

"Steven L Umbach" wrote:

> You can configure security policy which is a subset of Group Policy to
> modify user rights for logon locally or deny logon locally. For instance
> you could create a global group and add it to the deny logon locally user
> right via Group Policy to all computers in a domain or Organizational Unit.
> Be careful with deny user rights as they override the companion allow user
> right and keep in mind that administrators are members of users,
> authenticated users, and everyone groups. --- Steve
>
>
> "-KK-" <KK@discussions.microsoft.com> wrote in message
> news:14787456-9319-4E3E-9E6B-303C970534C7@microsoft.com...
> > We've been working on an in-house application that works through an
> > portal.
> > Users who log-in through this portal use LDAP to authenticate through
> > Active
> > Directory.
> >
> > Is is possible to make these logins disabled from being able to
> > Interactively Login to a desktop machine on the domain..?
> >
> > If so which method would be the best way..? Using Group Policies or is
> > there
> > a better option within Active Directory.
> >
> > Thanks,
>
>
>



Relevant Pages

  • Re: Bandwidth Hogging by server communication...
    ... > Therefore you could try to change the slow link detection speed to be ... > Policy is being applied, expand the User Configuration node and navigate ... > Active Directory Replication Events During Scheduled Available Windows ...
    (microsoft.public.win2000.networking)
  • Re: Disable search for Active Directory
    ... either Group Policy settings or Registry. ... Maximum size of Active Directory searches ... that are returned from an Active Directory search. ... Hides the Active Directory folder in My Network Places. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Active Directory Domain Policy
    ... Joe Richards Microsoft MVP Windows Server Directory Services ... Author of O'Reilly Active Directory Third Edition ... organizations that are realizing this limitation of one password policy ...
    (microsoft.public.win2000.active_directory)
  • Organizational Units
    ... I was told I do not know anything about active directory ... that I could apply group policy to them. ... All *domain* Israel Network resources will be univalible ... up security wise, does it not inherit security info from ...
    (microsoft.public.win2000.active_directory)
  • Re: Disable users from searching for other users
    ... You can use group policy to restrict the Maximum size of Active ... You can hide the Active Directory folder which will hide the AD folder ... Users can currently search the AD and display a list of other users, ...
    (microsoft.public.windows.server.active_directory)