?
Solved

Restrict computers to specific user accounts in AD

Posted on 2006-05-27
5
Medium Priority
?
262 Views
Last Modified: 2010-04-18
Hi,

I'm familiar with the user account option to restrict use of the account to a list of named computers.

What I want to do is the opposite. For certain computers I only want certain accounts to have access.

E.g. User U1 can login to all computers, but user U2 can log into most computers not five of them.

I could do this by setting allowed workstations for every account but, apart from being a lot work, this seems a clumsy solution.

Is there a better way?

W2003 domain, XP Pro clients.

Thanks,

Leon...
0
Comment
Question by:leonst
3 Comments
 
LVL 9

Accepted Solution

by:
imnajam earned 252 total points
ID: 16775055
Hi leonst,

You may try grouping computers, may call it public (all workstation) and private(5 computers) when restricting /allowing users allow to log on to public group

Cheers!
0
 
LVL 74

Assisted Solution

by:Jeffrey Kane - TechSoEasy
Jeffrey Kane - TechSoEasy earned 248 total points
ID: 16776225
Almost all Group Policies have both positive and negative settings.  If you want the opposite, then just DENY permission to the list of users instead of GRANTING permission.

Jeff
TechSoEasy
0
 
LVL 1

Author Comment

by:leonst
ID: 16788935
You're both correct, although what I really wanted to know was exactly how to do it.

I found this article:

http://www.microsoft.com/technet/security/prodtech/windows2000/w2kccadm/localpol/w2kadm12.mspx

and worked out that the policy I wanted was Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Logon Locally.

By specifying one group for this it seems to work fine.
0

Featured Post

Upgrade your Question Security!

Add Premium security features to your question to ensure its privacy or anonymity. Learn more about your ability to control Question Security today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
Please read the paragraph below before following the instructions in the video — there are important caveats in the paragraph that I did not mention in the video. If your PaperPort 12 or PaperPort 14 is failing to start, or crashing, or hanging, …
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question