Disable User Switching but Retain Ability to Log Off Locked Computer

Posted on 2012-08-16
Last Modified: 2012-09-07
We have a group of Windows 7 Pro machines in a Windows 2008 R2 domain that lock after a few minutes of inactivity.  Currently the machines all have User Switching enabled which I would like to disable so that we cannot have old sessions active on the computers.  

If we only disable User Switching, we are unable to log on as a different user once the machine is locked.

So....  How do we accomplish the following on our system.

- Remove the ability to have more than one user logged into the same machine
- Have the option for an administrator to log onto a locked computer and thereby force the log off of the locked user

- Is it possible to create a domain account that has just enough privileges to unlock the computers but no other Admin access on the computer or network?
- Is it possible to have the computers automatically log off if they have been locked for more than 5 minutes?

Question by:AutomatedIT
    LVL 52

    Assisted Solution


    I am quite sure that after removing fast user switching, the ability for an admin to log off users who locked their computer will be there without further effort - simply try it.
    Bonus 1: No.
    B2:  You can create a task that has the trigger "on workstation lock" and starts a batch that waits for 5 minutes and then fires shutdown -l for logoff.
    Problem: If the user logs back on we need to stop that task... let me think about how to achieve that.
    LVL 52

    Accepted Solution

    Ok, took the challenge and figured out B2 in detail, works. To reproduce: create two task called t1 and t2 here.
    t1: user: system, password:blank [no, this is no security risk but by design]. Trigger: on workstation lock of any user, but delay task for 5 minutes. Action: rwinsta console
    t2: user: system, password:blank. Trigger: on workstation unlock of any user. Action: schtasks /end /tn t1

    [For a test, set the delay to 10 seconds]
    LVL 59

    Expert Comment

    I've requested that this question be closed as follows:

    Accepted answer: 250 points for McKnife's comment #a38301710
    Assisted answer: 250 points for McKnife's comment #a38301848

    for the following reason:

    This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How to run any project with ease

    Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
    - Combine task lists, docs, spreadsheets, and chat in one
    - View and edit from mobile/offline
    - Cut down on emails

    Redirected folders in a windows domain can be quite useful for a number of reasons, one of them being that with redirected application data, you can give users more seamless experience when logging into different workstations.  For example, if a use…
    One of the features I've come to appreciate about Windows 7 and Windows Server 2008 R2 is the ability to pin applications to the task bar. As useful a feature as I've found this, it does have some quirks.  For example, have you ever tried pinning an…
    This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
    This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now