J
Juan Carlos
Hi:
I have some requirements for a software and I don't know how to
use/configure Active Directory (or whatever) to comply them or the best way
to do it. I have no experience with Active Directory.
The following are the requirements:
1) Configure a maximum "idle" status of a session: if a user logs in and
does not use the PC for a certain time the user must be logged off
automatically.
2) Make the system users "expire" automatically when a certain
(configurable) time has passed since the last time the user logged in.
3) Audit the user management (creation/deletion/modification) by
administrators to record all modifications and authors of those
modifications.
For 1) a way may be using a screen saver configured to auto log-off after a
certain time, but I don't know how to configure a default screen saver for a
group of users (and make those users unable to modify it) . May be using
logon scripts and some registry stuff?
For 2) I've seen out there that the "LastLogonTime" or something like that
is recorded for all users, but I don't know a good way to automatically make
this.
For 3) there is a way (policy) that windows "events" are generated when
Active Directory objects are modified. Is that a good way?
I'd really appreciate your help.
Juan Carlos
I have some requirements for a software and I don't know how to
use/configure Active Directory (or whatever) to comply them or the best way
to do it. I have no experience with Active Directory.
The following are the requirements:
1) Configure a maximum "idle" status of a session: if a user logs in and
does not use the PC for a certain time the user must be logged off
automatically.
2) Make the system users "expire" automatically when a certain
(configurable) time has passed since the last time the user logged in.
3) Audit the user management (creation/deletion/modification) by
administrators to record all modifications and authors of those
modifications.
For 1) a way may be using a screen saver configured to auto log-off after a
certain time, but I don't know how to configure a default screen saver for a
group of users (and make those users unable to modify it) . May be using
logon scripts and some registry stuff?
For 2) I've seen out there that the "LastLogonTime" or something like that
is recorded for all users, but I don't know a good way to automatically make
this.
For 3) there is a way (policy) that windows "events" are generated when
Active Directory objects are modified. Is that a good way?
I'd really appreciate your help.
Juan Carlos