Avatar of shaw71
shaw71Flag for United States of America

asked on 

Blocking all Internet access for a specific Domain user on Windows 2008R2 domain.

I have a domain controlled by a Windows 2008R2 server.  All users log into the domain utilizing Active Directories.  We also have an Exchange server and a Remote Desktop Server. All servers on the Domain utilize domain controller for authentication...etc.

I have a user that is utilizing a PC workstation as well as a Remote Desktop session on the Remote Desktop Server.

I have been able to block his PC workstation from accessing the Internet via the firewall.  I would like to take it a step further and block this domain user from accessing the Internet whether he signs onto remote desktop server or another PC on the domain.  

This user is to be allowed normal privileges on the LAN network.  File share, Remote Desktop Services, and Exchange.

I am assuming I would adjust group policies on the server.  Can this be done through group policies and if so, where would I adjust this?

Thank you
Shawn
Microsoft Server OSWindows Server 2008Active Directory

Avatar of undefined
Last Comment
Krzysztof Pytko
SOLUTION
Avatar of Tony Giangreco
Tony Giangreco
Flag of United States of America image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
ASKER CERTIFIED SOLUTION
Avatar of Krzysztof Pytko
Krzysztof Pytko
Flag of Poland image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
Avatar of shaw71
shaw71
Flag of United States of America image

ASKER

Krzysztof,

I went into the MMC and pulled up the Group Policy Object editor which edits the Local Group Policy Objects. I found where I can enter in the Proxy settings.  My concern at this point is that this is a global change not a user change.  Can you confirm that I am in the correct location for the 127.0.0.1 implementation section of your instruction?

Thanks!
Shawn

ps the screen shot is attached.
GPO.JPG
Yes, this is global change for local machine. Is that domain environment ? If so, you need to create GPO and apply GPO Security filtering.

To create GPO you need to use GPMC or Active Directory Users and Computers consoles.

If you're interested, I can prepare a short guide for you

Krzysztof
Windows Server 2008
Windows Server 2008

Windows Server 2008 and Windows Server 2008 R2, based on the Microsoft Vista codebase, is the last 32-bit server operating system released by Microsoft. It has a number of versions, including including Foundation, Standard, Enterprise, Datacenter, Web, HPC Server, Itanium and Storage; new features included server core installation and Hyper-V.

86K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo