Solved

Restrictions on OU level in Windows 2003

Posted on 2004-08-24
4
177 Views
Last Modified: 2010-05-18
hi,

I have windows2003 domain i just installed. I just wana know that , is it possible that if OU A, OU B and OU C are created , in OU A & B there are Users and in OU C there are computers. I want to put restrictions on the users of OU A so that even if any user of OU A physically wants to login from the computers of OU C then he/she should have access denied while the users of OU B should be able to login.

So is it possible in OU level to restrict users of one OU to not be able to even physically login to the computers of another OU?
0
Comment
Question by:amirkasalam
4 Comments
 
LVL 16

Accepted Solution

by:
mdiglio earned 125 total points
ID: 11881667
Hello,

I don't think AD is dynamic enough to do this based upon an OU.

What you can do is create a new security group called 'UsersB'
highlight all users in ou B and add them to the 'UsersB' group.

Now in the Group Policy for OU C expand
coputer configuration >> windows settings >> security sttings >>
local policies>>user rights assignment >> 
double click the 'logon locally' policy and add the newly created group,
and all other groups\users you will need to administer these computers

When you click browse to add this group you will have to change the 'object types'
to look for Groups as well

This will allow only the users specified to logon to the computers in the OU

Hope this works for you!
0

Featured Post

Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Visual C++ Runtime Error on Windows 2000 Server 2 1,486
Migrate DHCP from server 2000 to 2008 1 623
windows 2000 image 3 124
OLD CPUs 12 38
NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
Note: This is the second blog post in a series on email clearinghouses (https://www.xmatters.com/alert-management/blog-email-has-failed-us?utm_campaign=70138000000ydLoAAI&utm_source=exex&utm_medium=article&utm_content=blog-post).   Every month t…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

28 Experts available now in Live!

Get 1:1 Help Now