?
Solved

Group Policy for single user

Posted on 2006-05-03
5
Medium Priority
?
313 Views
Last Modified: 2010-04-18
I have a single user in a 2003 domain that I need to severely restrict his access.  I do not want ANY other users affected (or is that effected).  Can I create and apply a group policy too a single user?
0
Comment
Question by:Pioneermfg
  • 2
  • 2
5 Comments
 
LVL 85

Accepted Solution

by:
oBdA earned 500 total points
ID: 16598977
Yes, it's called sceurity filtering; just add a GPO to the OU where the user account is, remove the default "Authenticated Users" from the "Read" and "Apply" permissions, and assign these permissions to a dedicated group instead (don't assign permissions to single accounts!). Test with a harmless policy setting first.
Restrict away in the "User Configuration" part.
0
 
LVL 19

Expert Comment

by:BLipman
ID: 16599360
I like the idea of creating a new OU called LockDown and moving the user account into the new OU; it makes things a little more clear IMHO.  
0
 
LVL 3

Author Comment

by:Pioneermfg
ID: 16599772
I was hoping not to do that, but creating the OU worked great!  Now I have the user restricted from making changes to his workstation and limited his ability to search the network.
0
 
LVL 3

Author Comment

by:Pioneermfg
ID: 16599787
What would be nice is an ERD (Entity Relationship Diagram) for Group Policy that shows which settings in Computer and User are the same.
0
 
LVL 19

Expert Comment

by:BLipman
ID: 16608851
RSoP is for you!  

How to Target Resultant Set of Policy (RSoP) for Users and Computers
http://www.microsoft.com/windowsxp/using/setup/expert/rsop.mspx

Determine Resultant Set of Policy with GPResult.exe
http://technet2.microsoft.com/WindowsServer/en/Library/10997a3d-98f4-4fc2-bc82-f85beb6fd13e1033.mspx
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …

864 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question