Re: "Lock workstations" after certain idle time. Is it advisable to do it from 'server side' ?

From: Ryan Hanisco (rhanisco_at_flagshipis.com)
Date: 11/24/04


Date: Wed, 24 Nov 2004 10:46:37 -0600

Marlon,

Anthony is correct on the way to set this, but you have more to think about
than just the technical issues... Always let the technology follow the
business needs, never the other way around.

Enforcing this policy is a good idea from a business standpoint as it helps
to mitigate the risk of unauthorized access. Court cases have shown that an
unlocked terminal or even a logon prompt without a warning can be considered
an invitation for use. This opens yourself to legal and personnel problems.

This strongly points at doing this from a centralized point rather than
allowing your users any control over this. You would also be wise to use
the logon message to specify that access is for Authorized Use only in
accordance with your company's AUP -- Some even go as far as to post the
entire AUP on every logon.

While there may be some initial headaches for your helpdesk, they will be
short-lived. This is something that users will see every day and will
quickly disappear as it becomes one of their daily tasks. Spend 5 minutes
creating a PDF with screen shots to send to everyone with a cutover date and
get management buy-in (sounds like you already have that) to draw fire.

-- 
Ryan Hanisco
MCSE, MCDBA
Flagship Integration Services
"Marlon Brown" <marlon_brown@hotmail.com> wrote in message
news:OsMU36j0EHA.2824@TK2MSFTNGP09.phx.gbl...
> In my organization I have asked trainers/helpdesk to always advise users
to
> do CTRL+ALT+DEL and lock workstations when they go away from their
> computers.
>
> I have one of our senior managers asking why we don't enforce the "lock
> workstations" on our WinXP/Win2000Prof automatically in case users leave
> workstations idle for a certain period of time.
>
> My first thought is that enforcing this would cause more support issues;
> By the way, do we have a way to do suck 'lock the workstations't via Group
> POlicies  ? The way I know it can be done is via the Screensaver on the
> respective workstations.
> Please advise if there is a way to do that from the server side and also
if
> that's something people are doing out there or is more effective to let
> users lock their workstations on their own.
>
>


Relevant Pages

  • RE: Event ID 529
    ... The source is clear - workstations that are not part of my ... SBS2003 domain share the same local network (it's a shared local network in ... This kind of issue may be caused by Application logon such as while Outlook ... is connecting to Exchange Server, or this is an automated dictionary attack ...
    (microsoft.public.windows.server.sbs)
  • Re: How do manage your workstations?
    ... For the most part these functions require a local administrator rights. ... Therefore I have to logoff the regular user, then I logon as local administrator so I can update programs or add-in devices. ... However, if there are hundreds of workstations involved, it’s really time consuming! ... Maybe there is remote installation system that push program updates to the workstation and that system logons on as domain admin. ...
    (microsoft.public.windowsxp.general)
  • Re: "Lock workstations" after certain idle time. Is it advisable to do it from server side
    ... > business needs, ... > to mitigate the risk of unauthorized access. ... > unlocked terminal or even a logon prompt without a warning can be ... >> workstations idle for a certain period of time. ...
    (microsoft.public.win2000.active_directory)
  • Re: Cant login interactively after domain rename
    ... those workstations, for the policies in the User Rights section ... for Log on locally, and Deny local logon. ... Microsoft MVP (Windows Server System: ...
    (microsoft.public.windows.group_policy)
  • Re: Restricting network Logins
    ... Since you're on a 2003 domain, I'll assume your workstations are either ... Computers has an old left-over from the Windows NT days - "Logon To" on the ... NetBIOS name to the "Logon To..." ... >> simply enable passwords on the user's accounts on each PC. ...
    (microsoft.public.windowsxp.security_admin)