Re: Access restriction for domain user

From: Tim Springston [MS] (tspring_at_online.microsoft.com)
Date: 09/08/04

  • Next message: Miha Pihler: "Re: Access restriction for domain user"
    Date: Wed, 8 Sep 2004 10:45:37 -0500
    
    

    You could also set the user account property in Active Directory Users and
    Computers to only allow logon to specific computer(s). This does not test
    the OS of the computers you specify though.

    -- 
    Tim Springston
    Microsoft Corporation
    This posting is provided "AS IS" with no warranties, and confers no rights.
    "Miha Pihler" <mihap-news@atlantis.si> wrote in message 
    news:OYaqGpFlEHA.3520@tk2msftngp13.phx.gbl...
    > Hi Simon,
    >
    > There are two settings in Group or Local Policy that should help you out.
    > This will keep user away from computer based on user’s permission 
    > and based
    > on computers policy settings. Set this policy at level that suites you 
    > best
    > (e.g. OU level).
    >
    > Create new policy (or edit existing one) and under Computer Settings ->
    > Windows Settings -> Security Settings -> Local Policies -> User Rights
    > Assignment.
    >
    > Here look for policy "Log on Locally" and "Deny Log on Locally" You can 
    > add
    > your users that may only logon from certain computers on majority of 
    > server
    > to "Deny Log on Locally" (to make it easier create a group and add group 
    > to
    > policy while you add your users to this group).
    >
    > Now your users will only be able to log on to domain from computers that
    > don't have this policy applied.
    >
    > When creating policy make sure you don't lock yourself out.
    >
    > Mike
    >
    > "Simon" <t-chofu@microsoft.com> wrote in message
    > news:OuIqsdFlEHA.3912@TK2MSFTNGP12.phx.gbl...
    >> I want to set up an access restriction to W2K and W2003 domain users.
    >> Some users are only allowed to log on the domain from a certain PC.
    >> Is it possible to specify an IP address or Mac address somewhere in user
    >> profile?
    >> Or are there any ways to be able to manage this?
    >>
    >> Any advice would be appreciated.
    >>
    >> Simon
    >>
    >
    > 
    

  • Next message: Miha Pihler: "Re: Access restriction for domain user"

    Relevant Pages

    • Re: Parts of GPO not working.
      ... If your users use other browsers like firefox from an usb stick/drive or whatever medium your policy will not help. ... I have a request that all of those computers not have Internet ... The settings in this GPO can only apply to the following groups, ... Group Policy refresh interval for computers Enabled ...
      (microsoft.public.windows.server.active_directory)
    • Re: Logon failures reported by RSOP
      ... of the computers in that OU? ... reapplication of Security Settings to carry Services or User Rights ... Browser, Server, Automatic Updates, and Secondary Logon (I don't have ...
      (microsoft.public.windows.group_policy)
    • Parts of GPO not working.
      ... I have a request that all of those computers not have Internet ... The settings in this GPO can only apply to the following groups, ... Group Policy refresh interval for computers Enabled ...
      (microsoft.public.windows.server.active_directory)
    • Re: Automated logoff using Winexit.scr
      ... New OU - New Policy ... Settings: Configure this key then Propogate inheritable permissions to ... Permissions granted: Authenticated Users: Read/Special ... test GPO linked to it trying to accomplish that and move a couple computers ...
      (microsoft.public.windows.group_policy)
    • Re: Reinstall everytime assigned applications through GPO on start
      ... Software installation extension has been called for background policy refresh ... Stations - R&D Software (EMEA computers). ... Stations - R&D Software (EMEA computers) is set for installation because it ... The assignment of application Remote Administrator v2.1 from policy Software ...
      (microsoft.public.windows.group_policy)