group policy to lock idle computers

Posted on 2008-10-31
Last Modified: 2012-05-05
Hi everyone, I'm trying to find in the GP editor on my domain controller the place to lock idle computers for a set period of time.  After researching post on EE it looks like people are talking about the screen saver and forcing that to lock.

What I'm looking for is the GP to edit so a computer left idle with lock and require a CTRL+ALT+DEL to be done to unlock by the current user/administrator.
Does anyone know that specific location? I remember in the past it had to be set by seconds too.
Thank you in advance!
Question by:jbishop2446b
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2

Expert Comment

ID: 22851883
??? When the screensaver is locked you have to hit CTRL+ALT+DEL  to unlock it.
LVL 24

Expert Comment

ID: 22851899
Not sure but it does sound like after X minutes you want the computer to local and when that user or another user returns they need to press control alt del and input their username and password to unlock...Is this right?
If so then the easiest and most efficient way would be to use the screen saver lock will meets all your requirements

Author Comment

ID: 22851913
if you hit ctrl+alt+del right now, then click on lock or press enter the screen locks.. that is what I'm looking for in a group polocy and with a set time...I've done it in the past but can't find where it is.
Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.


Expert Comment

ID: 22851954
When you put password lock on a screen saver (even if the saver is blank) when you move a mouse, the only way to unlock it is to press CTRL + ALT + DEL

I 'm confused as to what you are asking for.

Author Comment

ID: 22851982
That must be the solution! I'm just looking for an auto lock... that takes place and does what one can do manually by press ctrl alt del..  The screen saver part confused me
LVL 24

Expert Comment

ID: 22851997
Yup just set the screen saver policy under a GPO and you will be good to go

Expert Comment

ID: 22852022
hahahaha... you were confusing me too.  yup.. it's the password protect on the screen saver

Author Comment

ID: 22852129
so any clue where the right spot is for that? thank you again ;)

Accepted Solution

cmarandi earned 500 total points
ID: 22852182
Go to Group Polic Manager
Right Click the Default Domain Policy
Choose to Edit
Go to User Configuration
Go to Administrative Templates
Go to Control Panel
Go to Display
Set these 3:
Screen Saver (So one is required)
Password Protect the Screen Saver (So it requires the CTRL+ALT+DEL)
Screen Saver Timeout (To set the timeout)

Featured Post

[Webinar] Code, Load, and Grow

Managing multiple websites, servers, applications, and security on a daily basis? Join us for a webinar on May 25th to learn how to simplify administration and management of virtual hosts for IT admins, create a secure environment, and deploy code more effectively and frequently.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DNS logs 1 33
DNS Record Manupluation 11 44
Unable to start workstation service 12 467
Writing reports to a script 7 29
Last week, our Skyport webinar on “How to secure your Active Directory” ( provided 218 attendees with a step-by-step guide for…
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question