Solved

Deny login access to computers in an OU via Group Policy

Posted on 2014-03-31
3
1,682 Views
Last Modified: 2014-04-03
Since XP is coming to it's end of life I will like to stop users accessing any XP workstation using Group Policy. All my XP workstation reside in a separate Organisational Unit (OU).

Basically, I will like to stop users accessing these XP workstations in this OU or once a computer object  is moved into this OU. Please what is the best approach in achieving this via GPO?

Look forward to hearing from you soon.

Regards,

TA
0
Comment
Question by:adigu1t
3 Comments
 
LVL 6

Accepted Solution

by:
Hassan Besher earned 500 total points
ID: 39968453
Create an Group Policy for that OU. THIS group policy will have an entry under computer configuration, windows settings, security settings, local policies, user rights assignment for "Allow logon locally". (The local GPO for XP machines has a Deny Logon Locally setting, but not an Allow Logon Locally setting. Go figure.)
4. Configure this right, adding "Administrators" and the users you want to log on to this PC. ( P.S. Do NOT configure "Deny logon locally" for everyone!! Deny overrides allow!)
0
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 39968884
hi,

apply "WMI" filter for xp os ............

select * from Win32_OperatingSystem where Version like "5.1%"



for more detail visit this site  
"http://technet.microsoft.com/en-us/library/cc947846%28WS.10%29.aspx"
0
 
LVL 53

Expert Comment

by:McKnife
ID: 39973021
Simply remove the physical machines :)
Or remove them from active directory, works, too.
0

Featured Post

The curse of the end user strikes again      

You’ve updated all your end user’s email signatures. Hooray! But guess what? They’re playing around with the HTML, adding stupid taglines and ruining the imagery. Find out how you can save your signatures from end users today.

Join & Write a Comment

Redirected folders in a windows domain can be quite useful for a number of reasons, one of them being that with redirected application data, you can give users more seamless experience when logging into different workstations.  For example, if a use…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now