Restrict/deny logon privileges

  • Thread starter Thread starter msu-iitians
  • Start date Start date
M

msu-iitians

Create another group ex: called Managers Group and grant
this group to "Logon Locally".Select a certain user in the
active directory and in the member of tab select Managers
Group. Remove the selected persons from Domain Users group
since we will deny this group to "Logon Locally". Hope
this will help..
 
I would not recommend ever removing anyone from the domain users group
[not sure if it is even possible by default, and he has 36,000 users]. All that
needs to be done is what Walter suggested - only have the desired users/groups
in the allow logon locally user right. If you are not in that setting, then you
have implicit deny rights. --- Steve
 
Back
Top