Jump to content

Recommended Posts

Posted

We are using AD 2008 and have three categories of users

Faculty

Staff

Students

 

All three categories have different privileges

 

I have smart classrooms and all computers in those rooms are connected to the domain

I want only category "Faculty" to be authenticated on those computers and must not allow any users in the category of

Staff or Students

to login to those machines.

How can i do it ? what changes can i make on client machine or domain

 

thanks

Posted

First of all in "Active Directory Users & Computers" arrange your computers into groupings (Organisation Units).

 

Then open "Group Policy Management" and create a new policy for the Users that will be for Restricted Logons to specific machines.

 

Right click to Edit the new policy.

 

Open Computer Configuration > Policies > Window Settings > Security Settings > Local Policies > User Rights Assignment

 

Open the "Deny log on locally" policy and add the groups you wish to deny.

 

Close the policy

 

Attach/Link the new Restricted Logon policy to all the Organisational Units you created for your computers that you wish to apply the policy to.

 

Don't worry about the policy been referred as local logins, it works.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...