Re: Disable the right to logon locally

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 05/22/04


Date: Fri, 21 May 2004 22:42:10 -0700

Yes, policy values applied from GPO completely replace
values as they are set with lower priority policy.
You likely cannot add all the local machine accounts to
the policy as applied from the domain.
IIRC you can obscure the password in the unattend
file if you are using the newer deployment toolset.

-- 
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCSE (W2k3,W2k,Nt4)  MCDBA
"Dave Bowman" <dbwmn2001@yahoo.com> wrote in message
news:47e33e2c.0405200742.a3e4a24@posting.google.com...
> I have one doubt about the User Rights Assignment.
> I need to setup one user in order to add a computer to a domain using
> the unattended setup. Since in this file the password is unencrypted I
> want to remove from this special user the opportunity to logon
> locally.
> The question is the following: if I enable the policy in the Default
> Domain Security Settings/Local Policies/User rights assignment/Deny
> Logon locally and I add this user, does this change override
> completely the machine policies?
> I ask this because I notice that an XP workstation has a local setting
> which denies logon to support* Users, ASPNET etc. so I'm wondering if
> I have to add these users to the domain policy as well
>
> Thanks
>   Dave


Relevant Pages

  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
    (microsoft.public.windows.server.sbs)
  • RE: Event ID 537 and Kerberos
    ... a logon type of 3 translates to Network. ... Click Services tab and select Hide All Microsoft Services and Disable ... Step 4: Configure account lockout policy. ... and then click Account Lockout Policy. ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote Client Configuration
    ... Thanks for quickly updates. ... Just as I know, if you only logon the domain with cache credential, the ... group policy will not be updates, instead it will use the old policy that ... dial up VPN connection to logon SBS domain once-in-a-while for the group ...
    (microsoft.public.windows.server.sbs)
  • RE: Remote Desktop not working after SP1
    ... "The local policy does not permit you to logon interactively" error message ... Remote Desktop Users ... Use the ISAinfo utility to collect the ISA configuration information: ...
    (microsoft.public.windows.server.sbs)
  • Re: No Shut Down or Restart for Domain Admins
    ... run rsop.msc from your DC and check which policy is responsible to this. ... I have created a group policy in a development network and imported it ... NT AUTHORITY\Authenticated Users Read (from Security Filtering) No ... Enforce user logon restrictions Enabled ...
    (microsoft.public.windows.server.active_directory)