Either create a new GPO or edit the "Default Domain Controllers Policy",
right select the Domain controller OU, properties, select the Group Policy tab then hilite the Default domain controller policy, edit, under Windows Settings, Security Settings, Local Policy, user Rights Assignment, edit "Log on Locally" remove Everyone and ensure Administrators is there.
Main Topics
Browse All Topics





by: Netman66Posted on 2007-07-05 at 14:12:52ID: 19427404
Open up GPEDIT.msc from each server's console.
Navigate to this location:
Computer Config>Windows Settings>Security Settings>Local Policies>User Rights Assignment::
Allow logon locally.
Make sure to only remove the domain group that allows normal users to logon.
If you have Terminal Services on any of these then normal users must have this right to log into a TS session.