Re: Prevent Users interactive login, but allow them to run batch jobs



"Avil" <Avil@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:28206A25-9B62-4AC7-BD1B-29873E82B760@xxxxxxxxxxxxxxxx
I have a Windows 2000 ADS domain. I need some domain user accounta who can
run batch jobs but they should not be able to login to domain by pressing
alt-ctl-delete. Is it possible to implement?


Is it possible? Yes.
Is it simple to implement? That depends on how your Windows
deployment is currently configured.

In the default, user accounts are members of Domain Users, and
Domain Users as well as Authenticated Users are made members
of the Users group of all domain joined machines.

You want an account that
a) does not have a grant of Log on locally, or if it does then is
also listed in the Deny log on locally (these are in User Rights)
b) does have user right grant of batch logon

Just how you effect it so that the account meets those depends on
how you have or have not taken control over user rights on members.

One possible approach is to make the accounts not be members of
Domain Users. However, that does not fully address the issue as
Authenticated Users would still allow local login to the account.
Another possible approach is to use the Deny local login setting
but that gets very messy in an infrastructure as the only way to set
that centrally (without coding that connects to each machine and
sets it) is via GPO and that will wipe out anything already listed
in that setting.

Roger


.



Relevant Pages

  • Weakness introduced by denying remote logins on AIX, possibly others
    ... AIX 4.3.3 and AIX 5.1, ... is possible to remotely enumerate the passwords of a known AIX account. ... believed to be in the response from the login program after authentication ... Give accounts that have been restricted from remote logins strong passwords. ...
    (Security-Basics)
  • Re: Rid AD of Circular Group Membership
    ... and have use on members if it is used there. ... Administrators group is still intact), nor do they have empowerments over ... Admins is being used for by the 30+ can be delegated I(ex. ... The quess is each has an account and uses it, ...
    (microsoft.public.windows.group_policy)
  • Re: Please! Doesnt anyone know a better way to do this?
    ... account, they need to automatically be directed to the page to enter data ... session variable on the Account page. ... I assume here that you're checking a database when the user attempts to ... When a new user attempts to login or clicks to register, ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: adminDSholder being over zealous!
    ... I have experienced the same problems, where users in members of groups ... without the account ACLs reverting to match AdminSDHolder. ... account operators can manage their own accounts or the ... >>A supported fix is now available from Microsoft, ...
    (microsoft.public.win2000.security)
  • WinXP laptop, simple-style login conn to Win2000 share, error
    ... So, to simplify matters, add all machines to the domain. ... local machine accounts) to keep track of... ... the local account information. ... the "pushbutton login") and configure the Laptops to auto ...
    (microsoft.public.windowsxp.security_admin)