cneilson6 Posted March 28, 2012 Posted March 28, 2012 Hi I have a laptop that needs to be on the domain but i only want to allow local logins? is this possble?
cneilson6 Posted March 28, 2012 Author Posted March 28, 2012 Sorry should have mentioned that windows 7
3s-gtech Posted March 28, 2012 Posted March 28, 2012 Yes, if you set a policy that denies logon for users in a certain group. You can do this locally with secpol.msc or across the domain, and just set the groups that you want to deny (eg Students, Staff). We use this to stop students logging onto staff PCs.
Pottsey Posted March 28, 2012 Posted March 28, 2012 Depending on what you need this might work. Set the local login to match a username and password of the domain user. We do this with our staff laptops then use mapped drives to parts of the network and virus checker updates from the server as though its on the domain. Sometimes with windows 7 renameding a profile doesn’t work and you have to make a fresh profile matching the domain user .
cneilson6 Posted March 29, 2012 Author Posted March 29, 2012 Ok after a long time searching and thinking about it... i realised there was a very easy way of doing it. Access the user and groups on the laptop, within users group remove domain\domain users. Problem solved domain admins can still log in which is good and any user that try is given a message to contact support, local accounts can log on fine. Don't know why i didn't see that before.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now