Re: denying domain logon

From: Roger Abell [MVP] (mvpNOSPAM@asu.edu)
Date: 02/17/03


From: "Roger Abell [MVP]" <mvpNOSPAM@asu.edu>
Date: Mon, 17 Feb 2003 05:46:17 -0700


Yes.
The most direct way to do this is to place Domain Users
as a listed item in the security policy User Right area, named
something like Deny Local Logon. You will need to make
sure that this setting is either set from the domain level or
if set in local policy that it is not being overwritten by domain
level GPO

-- 
Roger Abell
MS MVP (Security, Windows), MCDBA,  MCSE both
Associate Expert - Windows XP ExpertZone
http://www.microsoft.com/windowsxp/expertzone
"C King" <cking@kws.nsw.edu.au> wrote in message news:021101c2d673$ea599e00$a001280a@phx.gbl...
> Is it possible to prevent users with a domain user 
> account from logging on to the domain other than through 
> terminal server on certain workstations where they should 
> only logon locally

Quantcast