GPO to restrict logons to some computers

  • Thread starter Thread starter Neil McFadyen
  • Start date Start date
N

Neil McFadyen

Is there a way to create a group policy to restrict logons to certain
computers to users in a particular global group. In this case I have a
win2000 server and the client comupters I need to restict are running
winXP

thanks
 
You can use the setting below

Deny logon locally
Computer Configuration\Windows Settings\Security Settings\Local
Policies\User Rights Assignment

Description
Determines which users are prevented from logging on at the computer. This
policy setting supercedes the Log on locally policy setting if an account is
subject to both policies.

This user right is defined in the Default Domain Controller Group Policy
object (GPO) and in the local security policy of workstations and servers.

By default, there are no accounts denied the ability to logon locally.


--
Tim Hines, MCSE, MCSA
Windows 2000 Directory Services

=====================================================
When responding to posts, please "Reply to Group" via
your newsreader so that others may learn and benefit
from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
 
So is it just a matter of changing the local policy on the particular client
computer?

I have also tried opening mmc and opeing a group policy for a particular
computer.
There is only 1 setting for Computer Configuration - Windows Settings - Security

and no settings for User Configuration - Windows Settings - Security
Is there some way of adding the entry to deny local logons here?

or
Could I create an addition group policy (I just have a Default Domain Policy
now) and give it a higher priority. But then How do I make it apply to only
certain client computers?

thanks
Neil
 
If you want to apply a group policy to certain computers only, put all
those computers in the same OU. Then add a new group policy to that
OU... where you set the restrictions for computers.
That should do it.
 
Back
Top