Restricting user/group to a particular server via GP

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I would like to restrict a particular user/group to logon to a single machine
on our domain. I figured Group Policy would be the way to do this. I've
been trying to figure out the best way to do this...

Thanks in Advance for your help...

Bill
 
You can try to use Deny logon locally and Log on locally in

Comp Config\Win Settings\Sec Settings\Local Policies\User Rights Assignment

BR,
Denis
 
And this will work!

For example, I - when testing in the lab - create three OUs ( Baseball,
Football and Basketball ) for my user account objects and two OUs ( WIN2000
and WINXP Pro ) for the computer account objects. I create three security
groups ( Baseball, Football and Basketball ) and play with this setting.
So, if I do not want any of the members of the Baseball security group to be
able to log on to the WINXP Pro machines I use this on the WINXP Pro OU and
low and behold - the members of the Baseball security group can not log on
to the WINXP Pro systems!

Cary
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top