Solved

Restrict logon with Group Policy

Posted on 2004-03-22
8
2,252 Views
Last Modified: 2012-05-04
I have a Windows 2k domain with XP workstations.  I have one workstation that I want to restrict logon to one user, let's call him joe.  I would like to make this change on the server rather than on the client to make it easier to manage.
I created a new OU and placed the computer in that OU.  I then created a new group policy object for that OU and I defined the 'Log on Locally' to have just joe in the list.
I then when to the client machine and ran gpupdate and restarted.  I tried logging on with a different user(besides joe, and not an aministrator) and it still let me login.
I looked at the Local Security Policy on the client and it had inherited the correct settings from Active Directory - that is, Log On Locally had Administrators(which I guess is just thrown in by default) and Joe in the list.  I could tell that it had inherited because the icon was different and I was not able to update it.
So, even through only Administrators and Joe are in the list, it is still letting others logon.  The only way that I have found to keep other users out is to add them to the Deny Log On Locally but I don't want to use that because then I would have to modify that list every time I create a new user.
Also, I do not want to create a group that contains all users except Joe.
0
Comment
Question by:ErnieExpert
  • 3
  • 2
  • 2
8 Comments
 
LVL 7

Expert Comment

by:Isigow
ID: 10651995
Add 'Domain Users' to the Deny logon Locally list
That should remove all other users from the ability to logon, except that Joe has an exception already so he should still be able to.

Isi
0
 
LVL 2

Author Comment

by:ErnieExpert
ID: 10652035
no, that will not work because Deny permissions take precedense and since Joe is member of Domain Users, Joe would then be denied permission.
0
 
LVL 11

Expert Comment

by:kabaam
ID: 10654419
you may have a domain policy that is overriding this setting.
also check the permissions on the gpo for the computer OU.  joe needs read and apply


http://www.microsoft.com/windows2000/techinfo/reskit/tools/existing/gpotool-o.asp
http://www.microsoft.com/windows2000/techinfo/reskit/tools/existing/gpresult-o.asp
0
Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

 
LVL 2

Author Comment

by:ErnieExpert
ID: 10661353
The domain policy does not have anything defined for 'Log on Locally'  so I don't think that that is conflicting.
I checked the permissions and Authenticated Users have Read and apply permission

I ran gpresult on the workstation and it showed that it was in the new OU that I created for it.  It also reported that it was applying the group policy from the new OU so that confirms that it is applying it.

0
 
LVL 7

Accepted Solution

by:
Isigow earned 75 total points
ID: 10661502
Odd thing is, I just tried this on a 2k server and it worked fine, on an XP workstation it still allowed Domain Users in...
Anyone know of why XP (and possible 2k workstation) does this while server does not? (not a DC, just a standard server)

Isi
0
 
LVL 11

Assisted Solution

by:kabaam
kabaam earned 50 total points
ID: 10669178
you best bet maybe to edit the local policy on the machine. instead of the OU level.
this will ensure there are not any compatibility issues.

http://support.microsoft.com/default.aspx?scid=kb;en-us;823659
0
 
LVL 2

Author Comment

by:ErnieExpert
ID: 11143158
Thanks Isigow for taking the time to test this out.  I ran the same test and came out with the same results.  I tried kabaam's suggestion and that worked.  It did not exactly answer my request bacause I said that I wanted to be able to manage it from the server, however, this seems to be the best solution for now.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Nslookup is a command line driven utility supplied as part of most Windows operating systems that can reveal information related to domain names and the Internet Protocol (IP) addresses associated with them. In simple terms, it is a tool that can …
This article is in response to a question (http://www.experts-exchange.com/Networking/Network_Management/Network_Analysis/Q_28230497.html) here at Experts Exchange. The Original Poster (OP) requires a utility that will accept a list of IP addresses …
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question