Using Active Directory and I want to disallow internet access for some users/pcs.


I need to be able to deny internet access for specific users or machines.

I've been told that on their old server (i.e. Pre AD), they could set "internet access" within a user setup and that was it.

They've not been able to find it in AD.

And I'm very new to AD and windows security.

I think I really want a group which is denied access to the internet and I can then add/remove members without having to alter a user directly.

This needs to be centrally administered, as some users are not here (notebook users, WAN users, etc).

I am NOT familiar with windows security model so please be patient.


Richard Quadling.
LVL 40
Richard QuadlingSenior Software DeveloperAsked:
Who is Participating?
beem4nConnect With a Mentor Commented:

first aff all you didnt mention what proxy server are you using - it would be good if you write it

but anyway, if you r using some kind of ISA server (Microsoft proxy), then it has ability to grant
internet to specific users/groups, this way you should create sum group in AD, like Internet Users, and in add in it user account you want to be able surf internet,
and setup your ISA to allow only "Internet Users" group to internet

thats all

ps: if you are using some kind of squid, you can also grant not all users access but by another way
You can use GPO and restrict the usage of IE or other softwares for specific users or groups.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.