[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Deny Logon Locally GPO setting scriptable?

Posted on 2004-04-20
8
Medium Priority
?
1,253 Views
Last Modified: 2012-06-27
I'm trying to proigram a time-based (not idle time) logout for some public systems - I don't know if its doable but what I'd like to do is run a scheduled task on login that would wait 30 minutes before calling a logout and prohibiting the currently logged in user from immediately logging in again.  To that end I'm trying to figure out how to mimic the GPO LM/Security/Deny Logon locally in order to place the user on the deny list.  

I'd like an explanation of what that security setting modifies (registry/SAM/?) becasue I'm fairly clueless and whether there is scripting or programmatic access to accomplish the same thing.
0
Comment
Question by:baal32
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
8 Comments
 
LVL 24

Expert Comment

by:Kenneniah
ID: 10872163
How long would you want the user to not be able to login?
0
 

Author Comment

by:baal32
ID: 10872744
I don't know exactly - probably between 30 minutes and an hour...
0
 
LVL 24

Expert Comment

by:Kenneniah
ID: 10872914
Most likely I'd use "shutdown.exe -l -f" to accomplish the logoff.
For the user I'd use "net user username /diable" to make it so that user cannot log in.
Then either reenable account manually, or schedule "net user username /enable"
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 

Author Comment

by:baal32
ID: 10873121
Well... there's no net user username /disable command, although there is a "net user username /active:{yes:no}".  Will this disable the user's domain account altogether though?  I just need them not to be able to logon to that particular system until someone else has logged on (at which time I will reenable the previous user's ability to logon locally...)  The idea is that we make sure no person is on any one system for longer than x minutes - this shouldn't stop them from being able to go to another system hoever (if other systems are available...)
0
 
LVL 24

Accepted Solution

by:
Kenneniah earned 1000 total points
ID: 10873362
LOL oops, yes it is /active for net user, and yes it will disable the domain account completely.

If you have the Windows 2000 Resource Kit use ntrights.exe.
http://support.microsoft.com/default.aspx?kbid=315276
0
 

Author Comment

by:baal32
ID: 10880410
The following are the available security priveleges for this tool (ntrights.exe) ...  I was hoping to see something signifying local logon...  So is the security file which contains the local logon prohibnitions secedit.sdb?  SHould I be trying to moidify this directly?  

 SeCreateTokenPrivilege
 SeAssignPrimaryTokenPrivilege
 SeLockMemoryPrivilege
 SeIncreaseQuotaPrivilege
 SeUnsolicitedInputPrivilege
 SeMachineAccountPrivilege
 SeTcbPrivilege
 SeSecurityPrivilege
 SeTakeOwnershipPrivilege
 SeLoadDriverPrivilege
 SeSystemProfilePrivilege
 SeSystemtimePrivilege
 SeProfileSingleProcessPrivilege
 SeIncreaseBasePriorityPrivilege
 SeCreatePagefilePrivilege
 SeCreatePermanentPrivilege
 SeBackupPrivilege
 SeRestorePrivilege
 SeShutdownPrivilege
 SeAuditPrivilege
 SeSystemEnvironmentPrivilege
 SeChangeNotifyPrivilege
 SeRemoteShutdownPrivilege
0
 

Author Comment

by:baal32
ID: 10881198
Cool Kennenniah - the list of available rights doesn't mention the SeDenyInteractiveLogonRight but its still available.

Thanks
0
 
LVL 24

Expert Comment

by:Kenneniah
ID: 10891998
Glad it worked for you!
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There are 2 things you must have in order to connect to the internet behind a router, The "Gateway IP" of the router, which is usually something like 192.168.xxx.1, I've seen routers with default values of: 192.168.0.1, 192.168.1.1, 192.168.11.1, …
Step by step guide to Clean and Sort your windows registry! Introduction: Always remember: A Clean registry = Better performance = Save your invaluable time In this article we're going to clear our registry manually! Yes, manually! The e…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
In this video, Percona Solution Engineer Rick Golba discuss how (and why) you implement high availability in a database environment. To discuss how Percona Consulting can help with your design and architecture needs for your database and infrastr…

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question