But will users be able to log into Outlook Web Access using this account after it's been disabled? I'm thinking not.
Main Topics
Browse All TopicsI have a mail-enabled user account that I do not want users using to log onto any workstation. However, this account needs to be able to receive mail and I want users to be able to access this mailbox through Outlook Web Access. Would the best way to accomplish this be to deny the log on locally right through the default domain GPO? If so, will users still be able to log into Outlook Web Access with this account? Or is this not the best way to do this and is there another way?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
I was involved in a similar question a few months ago.
As you can see my first thought was also "deny logon locally"
I thought Simon/Mestha's answer was good there
"Change the setting for "log on to" to only the Exchange server, nothing else. As long as the account is not an administrator they will be unable to login to the server..."
Thanks
Mike
well in that case, you can do what Simon suggested in http://www.experts-exchang
that should solve your problem.
This will work without issue.
Create a GPO that is set at the Computer Config --> Windows Settings --> Security Settings --> Local Policies -> Users Right Assisgment --> Deny Login locally for user or group that you want.
This will Deny the user to login to any workstation/server that is a member of your domain. If you have a Terminal server you might want to deny TS Login for the user/group. You will still be able to login to OWA.
Depending on the authentication type to the server (doesn't work with forms based)
The user with access can use:
http://owaservername/excha
where http is http or https
owaservername is the fully qualified external name of your outlook web access server (or internal if accessing inside the network)
mailbox is the name of the account you want your users to access
This works even if the account 'owning the mailbox' is disabled (which stops it logging on anywhere using its own credentials)
Business Accounts
Answer for Membership
by: rakeshmiglaniPosted on 2009-06-25 at 06:49:55ID: 24711339
you can disable the user account associated with this mailbox. om/kb/3190 47
once done, also make the changes as mentioned in http://support.microsoft.c
after all these changes have been made, the assoicated user account will not be able to login into any workstation and will be able to receive emails.