How to prevent users from logging on locally to their computers?

From: Branislav (bkaric_at_hotmail.com)
Date: 09/30/03


Date: Tue, 30 Sep 2003 09:36:17 -0700


Hello,
We would like to force users to logon into domain so all the scripts and
patches could be applied.

The situation is this: there are no local accounts on workstations, users
have only a domain account. It is an NT4 domain, on workstations we have
Win2000Pro and WinXP. Now, my boss wants every user to be a local
administrator on his/her computer so we put their domain account to be a
member of the local Administrators group. This gives them possibility to
logon locally on their computers.

I have created a VB script which will check if a user is logged on locally
and then change the IP address on the computer so it can not use network
resources. That's the way my boss wants it. If someone change the IP address
to some static value and connect to the LAN after all than we are suppose to
use more drastic measures.

Now, we are planning to migrate to Win2003 servers so I was thinking that
this script can be applied using GPOs. But it will be applied to users or
computers only if they logon into the domain. I don't know how to push out
this script to every workstation so it can be run when users logon locally
on their computer.

The other solution someone mentioned to me is to configure DHCP server to
give IP addresses to authenticated users only, but I still didn't find a way
to this either.

Can you give me some advice about these things?

Thank you,
Branislav



Relevant Pages

  • Re: Domain logon after sysprep
    ... Auto domain logon after sysprep seems to be not possible. ... During the local logon you can execute a script with the ... I need to autologon using a domain account, ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: Users last logon info from logon script
    ... I put this line in the users logon script: ... If I run the script manually, it shows the last logon time. ... I guess it is because Windows update the lastlogon attribute once a user ... Then, for each Domain Controller, ADO is used to search the ...
    (microsoft.public.security)
  • Re: slow logon
    ... in the logon time have been reduced so far. ... update the time for the clients that talk to the dc as the logon server. ... start up script in AD to apply updates to the clients machines which is ...
    (microsoft.public.windows.server.active_directory)
  • Logon Script Causing Laptops To Hang - Problems in script?
    ... I'm using the following script to map drives, ... functions when users logon to our domain. ... 'Disconnects Drives This assures everyone has the same drive mappings. ... objNetwork.MapNetworkDrive strTrainDrv, strPath ...
    (microsoft.public.scripting.vbscript)
  • Re: SMSLOGON Share point
    ... clients as you would specify the logon point in the script e.g. ... > NT4 domain along with the majority of my workstations. ...
    (microsoft.public.sms.admin)