Link to home
Get AccessLog in
Avatar of cmapel
cmapel

asked on

How can I remove the authenticated users group from the local users group

I am trying to use group policy to restrict the people that can log into our domain computers to only people in the local domain and the local users on the computers.  I have defined the allow logon locally policy to include our domain and local administrators but when I add the local users group it opens the computer up again to logons from other domains in our forest.
Avatar of Adam Brown
Adam Brown
Flag of United States of America image

Adding the Local Users Group isn't the best way to allow local access to devices in User Rights Assignment. Use the Domain Users Group instead. The Domain Users Group can only include users in the local domain.
ASKER CERTIFIED SOLUTION
Avatar of cmapel
cmapel

Link to home
membership
This content is only available to members.
To access this content, you must be a member of Experts Exchange.
Get Access
Avatar of cmapel
cmapel

ASKER

I found how to do it myself by editing the group policy from a server other than the domain controller.