My Company has 80 Users. There is a ADS in place and all the users log in to the domain. All the users have acess to internet. I need to restrict 30 users internet access. They should be able to access only three sites and nothing else. these 30 users can use any pc avialable in the network.  sugest me any group policy modification or login script for these users..
Erik BjersConnect With a Mentor Principal Systems AdministratorCommented:
You need a proxy server that can limit internet access then assign the proxy to those users via group policy assigned to an OU with those users in it.

Sorry I can't tell you what proxy to use (I don't use them) but you can look at this link to find out how to set proxy settings in GPO.

You are going to have A LOT fun trying to get this working with GPOs and/or logon scripts. You may want to change your approach and look at something like this:
crlpntAuthor Commented:
Is there any other solution other than Proxy server..
Erik BjersPrincipal Systems AdministratorCommented:
Proxy would be the best and easiest to manage, there are many types of proxy out there some are even free

gothicbloodyConnect With a Mentor Commented:
as ebjers said The best way to do this is by firewall (like isa server from microsoft) not
by gpo. Anyway, if you want to do it, you could use a "fake proxy server":
create a group policy that enforce proxy setting of for example. In
this way the users won't have acces to the internet. For the sites on which
you want to grant access, you must put them on proxy exceptions.

