Solved

Restricting users who can log into a computer on the domain

Posted on 2004-09-03
6
256 Views
Last Modified: 2010-04-11
Here is my question.  I have a computer plugged into the network.  The network is on a domain.  It uses active directory.  Here is my questions.  I can log onto my pc as local administrator or with my domain account.  When I'm not here, there is nothing to prevent another user from re-booting my computer and logging on with their own domain account.  I want to stop this from happening.  I want to restrict the logon rights to the local administrator on the computer, my domain account and one other.  Can I do this without going through the network administrator?  I am running a Windows 2000 Pro machine with SP4 and all the patches.  I also have admin rights as the local administrator and my domain account.

Thank you in advance!

Kevin Rutherford
0
Comment
Question by:kevrut
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 1

Expert Comment

by:Moskjis
ID: 11972151
Hi kevrut,

Go to:
Start/ Settings/ Control panel/ Administrative tools/computer managament/ local user and groups/users and delete all you do not want to access your computer.
If you can not delete something, there is no way (whitch I know) how to do it without going through the network administrator.

This can be wrong, of course :)
Cheers!
0
 
LVL 1

Expert Comment

by:Moskjis
ID: 11972195
Hi kevrut,

P.S. Maybe there is cause, why you are not the only one user on your machine!


Cheers!
0
 

Author Comment

by:kevrut
ID: 11972243
Thank you.  I tried.  That doens't prevent someone with a domain account from logging on.  There is a reason, it allows anyone to access their files and the network from any machine, but I operate a series of machines that are extremly sensitive and I need to restrict any acces.  I can go through the network admin, but based on past experience, it will take a long time to get anything done.  If I can possibly do it myself, it will be a huge benefit.
0
Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

 
LVL 1

Expert Comment

by:Moskjis
ID: 11972319
Hi kevrut,

Well, you can ask: Can he give you the rights of net administrator (for limited time), so you can do it yourself. Question is, will he give you that.

This can be wrong, of course :)
Cheers!
0
 
LVL 16

Expert Comment

by:JammyPak
ID: 11972365
There's a user right called 'log on locally'. No-one who doesn't have this right can login. modify your 'local security policy' (in Administrative Tools) and go to 'Local Policies' - 'User Rights Assignment'. 'Log on Locally' is probably assigned to the local group 'Users', which contains the Domain group 'Domain Users'.
0
 
LVL 16

Accepted Solution

by:
JammyPak earned 250 total points
ID: 11972547
remove 'Domain Users', but remember to specify yourself in there...
0

Featured Post

Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
For many of us, the  holiday season kindles the natural urge to give back to our friends, family members and communities. While it's easy for friends to notice the impact of such deeds, understanding the contributions of businesses and enterprises i…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question