Re: Limit OWA users to one domain?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



If you deny a person or group of users(ex: domaina\Domain Users) the
permission to access a computer from the network, then they will be unable
to do so, whether they are on the same LAN as the server, or connecting
from the Internet. Keep in mind that EVERY USER, including Domain Admins
and Enterprise Admins, is a member of one or more Domain Users groups. So,
if you want to deny all users from a certain domain from having this right,
then you can deny the Domain Users group from that domain. However, if
there are any users in that domain that you do want to have this right, do
no user the Domain Users group from that domain. Instead, create a group
for that domain that contains the users you do want to have this right.

===================================
From: Kevyn Pietsch[MSFT]

This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at:

http://www.microsoft.com/info/cpyright.htm

===================================

.



Relevant Pages

  • Re: can we remove a user from "EVERYONE" group
    ... > -Add an explicit deny to that security group on the folders they ... then stated that he couldn't logon locally as admin anymore. ... member of the domain users group. ...
    (microsoft.public.win2000.general)
  • client Local Drives permission
    ... I want to set the security permissions on clients C: ... drive to remove everyone group and to deny delete ... folder's/files to domain users group. ...
    (microsoft.public.win2000.security)
  • Re: How to audit one specific user?
    ... I'm surprised that everyone on a network doesn't have a list they filter out ... Firewall devices typically keep logs of the internet access. ... Phillip Windell ... Don't have him in the normal Domain Users Group. ...
    (microsoft.public.windows.server.networking)
  • Re: Permissions for outside users to a particular folder(s) on net
    ... Even though by default they are put into the domain users group I would still ... two folders on one server when they VPN/RDP and nothing else on the ... prompted to provide cerdentials when accessing to Any network resource, ... network and then rdp into a server to access a database. ...
    (microsoft.public.windows.server.active_directory)
  • Newbie question re: security principles
    ... users all are members of the Domain Users group, with very limited control. ... I'm trying to change some IP setting on some network interfaces, ... Is a domain security principle overriding ...
    (microsoft.public.win2000.active_directory)