Solved

SBS 2011 Block Specific User Account

Posted on 2014-02-18
6
304 Views
Last Modified: 2014-02-28
I have a simple request from a customer.  They're running Small Business Server 2011 and are having a problem with a domain admin getting into the server.  To detour additional conflict they have asked me to block their account from accessing the server.  How would I do this?  I figured it would probably be a GPO of some sort but can I do this on the local level to block a domain account.  They're logging in both locally and remotely.

Thanks.
0
Comment
Question by:TripapHoniC
  • 3
  • 2
6 Comments
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 39869639
you can disable the account, change the password .... easier to just disable the account in aduc
0
 

Author Comment

by:TripapHoniC
ID: 39874248
Thanks David but this is an active user.  I cannot disable his account.  I need to prevent him from logging into the server but still allow him access to everything else.
0
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 39878728
aving a problem with a domain admin getting into the server

remove the user from the domain administrator security group
0
Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

 

Accepted Solution

by:
TripapHoniC earned 0 total points
ID: 39881697
Again, thanks David.  Unfortunately this issue wasn't as easy as the obvious.  

I ended up pushing out a GPO with specific user groups ONLY allowed to log in locally.  Basically an explicit deny to logon locally.  It worked.

Thanks.
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 39890156
You do realize that this user can disable that GPO without logging onto the server itself?  Giving them the ability to bypass your fix?

Just want you to be aware of that -- because it really isn't a proper solution.

Why is the user a domain administrator in the first place?  The only need to have a person in that group is to give them access to log onto the server.  If they manage something else in the network, you can grant specific access to whatever it is they need to do without compromising the full security of your domain -- which is exactly what you are doing.

Jeff
0
 

Author Closing Comment

by:TripapHoniC
ID: 39894352
No tangible answer offered for question.
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Introduction At 19:33 (UST) on Tuesday 21st September the long awaited email arrived with the subject title of “ANNOUNCING THE AVAILABILITY OF WINDOWS SBS 7 PREVIEW”.  It was time to drop whatever I was doing and dedicate as much bandwidth as possi…
The SBS 2011 release date (RTM) is supposed to be around Christmas, 2011.  This article is a compilation of my notes -- things I have learned first hand.  The items are in a rather random order, but I think this list covers most of what is new and d…
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now