Solved

How do i restrict who can log in

Posted on 2014-02-27
3
421 Views
Last Modified: 2014-02-28
Greetings and thank you for reading.

Background: I'm the network assistant administrator, I manage a single domain using Windows Server 2008 R2  with 150 users and about 120 machines. I am the ONLY IT individual on site. Last year, we installed two xp machines in our lecture hall to be used for Powerpoint presentations.  We created an User account named "Projector" and informed staff to use that log in.  Staff continues to use their own credentials to log in and get frustrated when they realize they are missing items.

Management has requested that all user accounts, other than "Projector" and "Administrator", be removed from the machine so that ONLY "Projector" or "Administer" can log in it.

I have asked for help with other sources who suggest that I modify the User account and just exclude the select machines from being able to "logon" screen.  Problem is, the user needs to have rights to be able to log into any OTHER machine, just not the Projector.  Besides, I really don't want to modify 120 users, adding machines that I "think" they'll need access to.  

I know there has to be a way in Group Policy to manage this, but I'm very new at this.

I hope I asked the question correctly.  Simple question is: "How do I restrict who can log on to a specific computer?"

Thank you.
0
Comment
Question by:James Dart
3 Comments
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 150 total points
Comment Utility
Use the Groups to only included the ones you want.
http://technet.microsoft.com/en-us/library/ms175588%28v=sql.105%29.aspx
Open secpol.msc and go to, Local Policies -> user rights assignment and you will see quite a few "Deny log on" entries. Modify those, or just use the "Access this computer from the network" setting to include the groups you want.
-rich
0
 
LVL 61

Expert Comment

by:btan
Comment Utility
As shared by richrumble, there is the  "Deny log on locally" setting, but thought that this for restrictions for local machine. You can catch this as well http://mintywhite.com/windows-7/7maintenance/prevent-users-logging-domain-workstations/

But note that it only work for specific groups of users to specific groups of computers. If you want to restrict a random set of users to that specific computer, you may want to look at the Logon to option under that user account. so may consider to create a new policy such as "restrict logon" and edit the new policy
e.g. goto Computer Configuration > Policies > Window Settings > Security Settings > Local Policies > User Rights Assignment
e.g. Open the Deny log on locally policy and add the group for your Users
e.g. Close and save the policy
e.g. Attach the new policy to the computer

There is a product called UserLock that allows you more granularity, you can check out http://www.isdecisions.com/products/userlock/features.htm

Maybe a graceful scale up of the solution in future where you can explore some of the lockdown can factor in access based on workstations, time, business hours, and connection type.
e.g. own workstation, IP range, department, floor or building.
e.g. working hours and/or maximum session time for protected users.
e.g. Outside of allowed timeframes and/or when time is up, users will be disconnected with prior warning.
0
 

Author Closing Comment

by:James Dart
Comment Utility
That is what I just found. Excellent.  Thank you for confirming my research!
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
Big data transfers via information superhighways require special attention and protection. Learn more about the IT-regulations of the country where your server is located. Analyze cloud providers and their encryption systems for safe data transit. S…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now