Solved

Using Group Policy to prevent users from locking a computer

Posted on 2016-08-09
3
24 Views
Last Modified: 2016-08-30
We have a server 2008 AD environment where users share workstations but login with unique accounts. It's a sales office and users are constantly logging into different computers for short sessions. This is creating a situation where computers can have over half a dozen different users logged in at the end of the day, and we believe it's causing a problem with some of our software. We are not concerned about data loss as just about everything these users do is in the cloud.

Is it possible to prevent users from locking computers as well as change the idle timeout to force a logout rather than a lock screen?
0
Comment
Question by:medium_grade
  • 2
3 Comments
 
LVL 5

Accepted Solution

by:
Manuel Flores earned 500 total points (awarded by participants)
ID: 41749248
To close idle session, seems not be so easy, the session limit group policy is related to RDP sessions.

It is possible using logon scripting ;
https://4sysops.com/archives/automatically-log-off-idle-users-in-windows/

This solution uses a proprietary .exe, beware with that.

Maybe somebody knows a better solution.
0
 
LVL 16

Expert Comment

by:FOX
ID: 41749251
log off after a certain period of inactivity

ref link: https://4sysops.com/archives/automatically-log-off-idle-users-in-windows/

idlelogoff download(add it to a gpo)
ref link: http://www.intelliadmin.com/?p=4439
0
 
LVL 5

Expert Comment

by:Manuel Flores
ID: 41776016
Provided a link with a valid solution to the question.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On some Windows 7 (SP1) computers, Windows Update becomes super slow even the computer is reasonably fast.  There's one solution that seemed to have worked well for me (after trying a few other suggested solutions).
This article runs through the process of deploying a single EXE application selectively to a group of user.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question