Re: Internet Access

From: Steven L Umbach (
Date: 11/08/05

Date: Mon, 7 Nov 2005 19:50:03 -0600

If ONLY Internet Explorer is used and allowed on that computer you can
configure Group Policy to give that domain user a bogus proxy server IP
address and then he will not be able to access the internet via IE. If you
are using ISA 2000/2004 you can create firewall rules based on user or group
membership. See the link below for more information on using a bogus proxy
server and make sure the user can not access the connection tab of IE [in
order to remove the bogus proxy IP] which you can also disable via Group
Policy in user configuration/administrative templates/Windows
components/Internet Explorer/control panel. You might need to create a Group
Policy just for that user linked to an OU and move the users account into
the OU. That OU could be a child OU to the domain container or another OU so
that other Group Policies still apply to the users account. Use the mmc
snapin for RSOP to see what settings apply to that user in either logging or
planning mode to see what settings apply or should apply to that user. ---

"Btfdffemt" <> wrote in message
>I want to restrict access to a single (non-admin) user on my domain.
> The user must still be able to access the server. Is this possible if
> so then how. Thank you in advance for your time.

Relevant Pages

  • Re: How to allow users to create groups and shares
    ... Add the user/group to the Computer configuration, windows settings, security settings, Local policies, "Allow logon locally" in the Default domain controllers policy and on a existing or new created policy for the member servers. ... Filtering: Not Applied ... check with GPMC on the server or from a client the policy settings. ...
  • Domain Controller Security Policy errors
    ... Security Policy or the Domain Controller Security Policy. ... The DC is also a print and file server. ... The domain controller for Group Policy operations is not available. ...
  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
  • Re: Security Logon/Logoff Events
    ... I haven't yet set password policy or configured account lockout policy so I ... will do that in due course to fully secure the server. ...
  • Re: Move W2K3 server to its own OU seperate from SBS (MyBusiness) OU
    ... OU and move the member server to so that it does not inherit it's GPO from ... policies from inheriting the default domain policies of the SBS ... section of the default domain policy. ... In direct answer to your question, you would need to filter this ...