Jump to content

Recommended Posts

Posted

I'm trying to find a way of blocking all users from logging onto domain computers unless that have been added as an admin/power user/guest/user etc...

 

At the moment, anybody with an account can log onto which ever computers they feel like, and I've discovered that alot of kids and certain staff often go into the library and use the librarians computer when she's not there.

What I'd like to do is create an OU and add the 3 ladies who work in the Library on different days, and deny anybody from logging onto that machine except members of that library OU.

 

Any suggestions would be greatly appreciated!

Posted (edited)

Do you have W2K3 network?

 

If so, using AD is one way, using Account > Log on to. This is tidious to setup though.

 

I prefer to use Windows Security Groups and add members in that I wish to be able to use the machine(s). Then it is a matter of assigning in Computer Management.

 

Furthermore, if it's only one or two machines you could simply edit the User section of Local Users and Groups, remove the 'Domain Users' and such like, add only the required staff and everyone else will recieve a 'You cannot logon interactively' message, or something similar.

Edited by plock
Posted

I tried removing the "Domain Users" from "Users" under "Local Users & Groups" and yet all accounts still seem to be able to log on...

 

That is the way I had hoped to do it, are there any other accounts I need to remove?

Posted

You can stop groups from logging into machines in a specific OU, not quite the way round you want it but it might work.

 

In group policy there is a "Deny Logon Locally" option in the security settings. You can add groups to this to stop them logging on to the machine

 

Edit: Fix setting name

Posted

Under the 'Users' group in 'Local Users and Groups' remove the following, 'Domain Users', 'Authenticated Users' and 'Interactive'.

 

Your setup may be different and include other groups. However, only you will know what your Security Groups/Users are doing in the 'Users' group.

Posted
I'm trying to find a way of blocking all users from logging onto domain computers unless that have been added as an admin/power user/guest/user etc...

Any suggestions would be greatly appreciated!

 

Group policy allow you to set a machine setting that will block log on locally rights to certain security groups.

 

It is in Windows Settings/Security Settings/Local Policies/User Rights Assignmebt and is called "Deny log on locally". We have this set to deny access by students to certain computers.

 

Hope this helps.

 

Jonathan

Posted

Thanks guys, I'll go give it a try now....

 

My issue with using the "Deny Logon Locally" is that I don't want to deny certain OUs, I want to deny everyone EXCEPT certain OUs

Posted
No, Deny Logon Locally doesn't Deny or Allow OU's. This works on Users or Security Groups. In this case it will Deny Logon Locally to certain Users/Security Groups that you specify.
Guest frankybaloney
Posted
Why dont you disable all the accounts in the OU's that you dont want to logon?
Posted

@ frankybaloney - ?? - He is still going to require them to login to other resource around site?

 

Disabling the computer/user accounts will lock the resource/user out of the network altogether?

Posted

Incase anybody is interested:

 

I remove the

 

"Domain Users", "Interactive User" & "Authenticated Users" accounts from under the 'Users' Groupd in Local Users & Groups

 

then Add the OU that I want to be able to access that computer under Power Users.

 

thanks to everybody for your help & suggestions!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...