Is it possible to restrict access

  • Thread starter Thread starter Leo
  • Start date Start date
L

Leo

to the local computer a user logs into from a GPO that I
setup on the Domain Controller?

For example if you belong to a group called Finance, can I
setup a policy on the domain that restricts any member of
the Finance group from accessing their CD-ROMs, or they
cannot see 'My Computer' icon...etc etc.

Thanks
Leo
 
Yes. Although you don't directly apply GPO to groups (you apply them to
Sites, Domains or OUs) you can use groups to filter the policy - either
allowing or disallowing the applying of the GPO.
 
I don't think there is a setting to restrict local access to a cdrom. However there
are two parts to a GPO - computer and user. If you are configuring user
configuration, then the users need to be in the scope of influence of the GPO. Domain
Controller policy affects only domain controllers and the users that log on to them.
You would want to configure a GPO at the domain level if you want to apply it to all
users and non domain controller computers. If you want to apply more granular policy
to specific users then create an OU for those users with a GPO for them and move
those users into that GPO. Keep in mind password/account policy for domain members
can only be set at the domain level. ---Steve
 
Back
Top