Restricting user/group to a particular server via GP

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I would like to restrict a particular user/group to logon to a single machine
on our domain. I figured Group Policy would be the way to do this. I've
been trying to figure out the best way to do this...

Thanks in Advance for your help...

Bill
 
You can try to use Deny logon locally and Log on locally in

Comp Config\Win Settings\Sec Settings\Local Policies\User Rights Assignment

BR,
Denis
 
And this will work!

For example, I - when testing in the lab - create three OUs ( Baseball,
Football and Basketball ) for my user account objects and two OUs ( WIN2000
and WINXP Pro ) for the computer account objects. I create three security
groups ( Baseball, Football and Basketball ) and play with this setting.
So, if I do not want any of the members of the Baseball security group to be
able to log on to the WINXP Pro machines I use this on the WINXP Pro OU and
low and behold - the members of the Baseball security group can not log on
to the WINXP Pro systems!

Cary
 
Back
Top