Nick_Parker Posted January 16, 2008 Posted January 16, 2008 I'm trying to find a way of blocking all users from logging onto domain computers unless that have been added as an admin/power user/guest/user etc... At the moment, anybody with an account can log onto which ever computers they feel like, and I've discovered that alot of kids and certain staff often go into the library and use the librarians computer when she's not there. What I'd like to do is create an OU and add the 3 ladies who work in the Library on different days, and deny anybody from logging onto that machine except members of that library OU. Any suggestions would be greatly appreciated!
plock Posted January 16, 2008 Posted January 16, 2008 (edited) Do you have W2K3 network? If so, using AD is one way, using Account > Log on to. This is tidious to setup though. I prefer to use Windows Security Groups and add members in that I wish to be able to use the machine(s). Then it is a matter of assigning in Computer Management. Furthermore, if it's only one or two machines you could simply edit the User section of Local Users and Groups, remove the 'Domain Users' and such like, add only the required staff and everyone else will recieve a 'You cannot logon interactively' message, or something similar. Edited January 16, 2008 by plock
Nick_Parker Posted January 16, 2008 Author Posted January 16, 2008 I tried removing the "Domain Users" from "Users" under "Local Users & Groups" and yet all accounts still seem to be able to log on... That is the way I had hoped to do it, are there any other accounts I need to remove?
Nick_Parker Posted January 16, 2008 Author Posted January 16, 2008 How and Where to I configure the Windows Security Groups?
DMcCoy Posted January 16, 2008 Posted January 16, 2008 You can stop groups from logging into machines in a specific OU, not quite the way round you want it but it might work. In group policy there is a "Deny Logon Locally" option in the security settings. You can add groups to this to stop them logging on to the machine Edit: Fix setting name
plock Posted January 16, 2008 Posted January 16, 2008 Under the 'Users' group in 'Local Users and Groups' remove the following, 'Domain Users', 'Authenticated Users' and 'Interactive'. Your setup may be different and include other groups. However, only you will know what your Security Groups/Users are doing in the 'Users' group.
ArchersIT Posted January 16, 2008 Posted January 16, 2008 I'm trying to find a way of blocking all users from logging onto domain computers unless that have been added as an admin/power user/guest/user etc... Any suggestions would be greatly appreciated! Group policy allow you to set a machine setting that will block log on locally rights to certain security groups. It is in Windows Settings/Security Settings/Local Policies/User Rights Assignmebt and is called "Deny log on locally". We have this set to deny access by students to certain computers. Hope this helps. Jonathan
plock Posted January 16, 2008 Posted January 16, 2008 @ ArchersIT - I use this method also. I prefer this as you can use Windows Security Groups.
Nick_Parker Posted January 16, 2008 Author Posted January 16, 2008 Thanks guys, I'll go give it a try now.... My issue with using the "Deny Logon Locally" is that I don't want to deny certain OUs, I want to deny everyone EXCEPT certain OUs
plock Posted January 16, 2008 Posted January 16, 2008 No, Deny Logon Locally doesn't Deny or Allow OU's. This works on Users or Security Groups. In this case it will Deny Logon Locally to certain Users/Security Groups that you specify.
Guest frankybaloney Posted January 16, 2008 Posted January 16, 2008 Why dont you disable all the accounts in the OU's that you dont want to logon?
plock Posted January 16, 2008 Posted January 16, 2008 @ frankybaloney - ?? - He is still going to require them to login to other resource around site? Disabling the computer/user accounts will lock the resource/user out of the network altogether?
Nick_Parker Posted January 18, 2008 Author Posted January 18, 2008 Incase anybody is interested: I remove the "Domain Users", "Interactive User" & "Authenticated Users" accounts from under the 'Users' Groupd in Local Users & Groups then Add the OU that I want to be able to access that computer under Power Users. thanks to everybody for your help & suggestions!
plock Posted January 18, 2008 Posted January 18, 2008 You're most welcome! Glad you managed to sort it.
ajbritton Posted January 18, 2008 Posted January 18, 2008 Just wanted to point out that OUs cannot be used to assign rights/permissions as OUs are not 'security principals'. Groups is the way to go.
plock Posted January 19, 2008 Posted January 19, 2008 @ ajbritton - you're correct, I think he meant Security Groups. As per my previous posts.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now