workstation login restrictions

Forum Windows 2000/NT : Windows 2000/NT General Discussion - workstation login restrictions

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Archived from groups: microsoft.public.win2000.security (More info?)

 

I know that AD will allow me to restrict a user access to only specified pcs
by adding the pcs to the allowed list. Is there a way that I can restrict all
unauthorized users to a specific pc. I need restrict login access to users on
a couple of desktops.

Thanks

Kevin

Sponsored Links
Register or log in to remove.

Archived from groups: microsoft.public.win2000.security (More info?)

 

Sure. Configure the user right for logon locally and deny logon locally for
your needs. Keep in mind that lack of a user right/permission is an implicit
deny, deny overrides allow, and administrators are also members of the users
and everyone groups. For a couple of computers you can use Local Security
Policy - security settings/local policies/user rights. --- Steve


"Kevin" <Kevin@discussions.microsoft.com> wrote in message
news:AB568BE8-8D84-428E-ACA4-74F0BBE0B0BF@microsoft.com...
>I know that AD will allow me to restrict a user access to only specified
>pcs
> by adding the pcs to the allowed list. Is there a way that I can restrict
> all
> unauthorized users to a specific pc. I need restrict login access to users
> on
> a couple of desktops.
>
> Thanks
>
> Kevin

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

You should take control over the setting for the Log on locally and/or
Deny log on locally User Right on all of your machines.
There is no setting to state, if a user is not one of (a, b, c, ...) then
allow logon only at machine (x, y, z ...) directly, but with use of
a domain group that controls the machines' Log on locally User Right
this is simply done.

--
Roger Abell
Microsoft MVP (Windows Security)
MCSE (W2k3,W2k,Nt4) MCDBA
"Kevin" <Kevin@discussions.microsoft.com> wrote in message
news:AB568BE8-8D84-428E-ACA4-74F0BBE0B0BF@microsoft.com...
> I know that AD will allow me to restrict a user access to only specified
pcs
> by adding the pcs to the allowed list. Is there a way that I can restrict
all
> unauthorized users to a specific pc. I need restrict login access to users
on
> a couple of desktops.
>
> Thanks
>
> Kevin

Reply to Anonymous

Archived from groups: microsoft.public.win2000.security (More info?)

 

Thanks I will try this

"Steven L Umbach" wrote:

> Sure. Configure the user right for logon locally and deny logon locally for
> your needs. Keep in mind that lack of a user right/permission is an implicit
> deny, deny overrides allow, and administrators are also members of the users
> and everyone groups. For a couple of computers you can use Local Security
> Policy - security settings/local policies/user rights. --- Steve
>
>
> "Kevin" <Kevin@discussions.microsoft.com> wrote in message
> news:AB568BE8-8D84-428E-ACA4-74F0BBE0B0BF@microsoft.com...
> >I know that AD will allow me to restrict a user access to only specified
> >pcs
> > by adding the pcs to the allowed list. Is there a way that I can restrict
> > all
> > unauthorized users to a specific pc. I need restrict login access to users
> > on
> > a couple of desktops.
> >
> > Thanks
> >
> > Kevin
>
>
>

Reply to Anonymous
Tom's Hardware > Forum > Windows 2000/NT > Windows 2000/NT General Discussion > workstation login restrictions
Go to:

There are 496 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them