Solved

Restrict domain accounts that can log into specific computers?

Posted on 2011-03-16
2
600 Views
Last Modified: 2012-05-11
We use roaming profiles in our office under a Server 2008 domain environment with all windows 7 workstations.

Our managers sit in the same area as support staff and previously they once in a while would use a managers computer for work, since they had a roaming profile.

now managers have access to skype and such, support clerks dont, so i wanted to prevent people from logging into certain machines.

For example only Joe Blow can log into his computer with his domain account, no one else.

is this possible?

i did read up on some methods but they seem rather long and drawn out.
0
Comment
Question by:Mathiau
2 Comments
 
LVL 7

Expert Comment

by:brota
ID: 35151827
go to the properties of the user account go to the account tab.
there is a logon to button
0
 
LVL 4

Accepted Solution

by:
bigstyler earned 500 total points
ID: 35152602
Hi,

in your situation, it shoud be better to use the "deny logon locally" group policy settings : http://technet.microsoft.com/en-us/library/cc957048.aspx

With this method, you will be able to deny a specific group to logon on locally to some specific computers (those that will be in the scope of the GPO).

It will be then more easy for you to deploy this configuration on several computers with group policy and not individually on each computer.

Otherwise, it is possible to define an "allow logon locally" settings, that will do the trick by removing the "domain users" group and adding a group that is containing the granted users.(http://technet.microsoft.com/en-us/library/cc756809(WS.10).aspx)
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This Micro Tutorial will teach you how to the overview of Microsoft Security Essentials. This is a free anti-virus software that guards your PC against viruses, spyware, worms, and other malicious software. This will be demonstrated using Windows…

929 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now