Solved

Control which users can login to a machine w/Active Directory

Posted on 2004-09-18
1
153 Views
Last Modified: 2012-05-05
I'm running 2003 server with Active Directory
How can I control which users can login to specific machines.
Right now even though everyone has their own account, Everyone can log into every computer and get into everyone elses stuff using windows explorer and its causing big problems with people snooping around.

I need to basically assign users to computers and block everyone else who shouldn't be allowed to use them from being able to log into them.

Please describe step by step how to assign certain computers to a user / block all but certain users from a machine using Active Directory.

Thanks!
0
Comment
Question by:Matrix1000
1 Comment
 
LVL 82

Accepted Solution

by:
oBdA earned 500 total points
Comment Utility
In ADUC, in the user's profile, you can specify which machine(s) the user is allowed to logon.
But that's only treating the symptoms, not the cause.
If people are able to "snoop around", then your permissions are set incorrectly. With correct permissions set, people can logon to any machine without seeing anybody else's files. Assign home drives to your users, let them store their data there, which gives you the possibility to backup that data as well. Set proper NTFS permissions on the home drives, and your users could even (but shouldn't) be local administrators on the machine, without having access to other people's data.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Preface Having the need * to contact many different companies with different infrastructures * do remote maintenance in their network required us to implement a more flexible routing solution. As RAS, PPTP, L2TP and VPN Client connections are no…
This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now