Solved

windows 2003 server active directory

Posted on 2008-10-22
3
219 Views
Last Modified: 2010-03-17
is there a way through active directory group policy to only allow one user to login to a computer? I used group policy to due the opposite. I have a user that can only sign in to a specific computer. but I want to make it so nobody but one user can sign in to a specific computer.
0
Comment
Question by:JeffBeall
3 Comments
 
LVL 2

Accepted Solution

by:
calepantke earned 167 total points
ID: 22780030
You can restrict who logs into specific computers through Users and Groups on the specific machine. For example, you could set User A as the only user allowed to log into Computer B by having him be the only one in the local users group on Computer B. (that is excluding administrators).
0
 
LVL 4

Assisted Solution

by:futurefiles
futurefiles earned 167 total points
ID: 22780068
Go into the user's profile, Account, Log On To, and set the computer names the user should be able to login to.
Or use the Log on locally policy setting using local or domain GPO's.
0
 
LVL 18

Assisted Solution

by:Americom
Americom earned 166 total points
ID: 22782974
On your GPO under Computer Configuration>Windows Settings>Security Settings>Local Policies>User Rights Assignment>Allow log on locally

Here by default, only Gest, Administrators, Users, and Backup Operators granted the right to logon locally. You can remove all these four default user and groups and only grant the user you want to allow to logon. You may want to do the same for Allow log on Through Terminal Services in case someone try to logon remotely.

You just need to decide how you can logon if you ever forgot the password of that user's account. So a spare admin account would be safe.

Once the above GPO is configured you link it apply to the OU where the computer is in.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Active Directory Failed Logon Attempts. 18 54
Wild Card CName in Windows Active Directory integrated zone - Good Idea? 4 26
Enterprise Mode 4 30
Locating a GPO setting 3 31
Introduction You may have a need to setup a group of users to allow local administrative access on workstations.  In a domain environment this can easily be achieved with Restricted Groups and Group Policies. This article will demonstrate how to…
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

778 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question