Re: Is it possible access limitation on Computer Accounts?



<mswin2003jp@xxxxxxxxxxx> wrote in message
news:1155632342.463055.305720@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
The system have share resources.
Is it possible that only some computer can access these resources?

Sure, but usually people want to limit USER access rather
than "computer" access to resources.

For user access, the standard answer it so to use permission.

[For computer answer permissions are also possible but this
only affects those things access by the "computer account"
such as GPOs and computer assigned installation files.]

Generally computer access is restricted by IP address which
is NOT perfect but is better than nothing. (IP addresses can
at least in theory be spoofed.)

For true computer restrictions, you can require IPSec for access to
the resource computer (or on certain ports for certain services on
the resources computer.)

Any domain user who logon from the resource acceptable computer can
access share resources?

Use permissions to restrict it to domain users and IPSec
to filter on the "approved computer".

I imagine the resources are NAS, or share folders.


--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]




.



Relevant Pages

  • Re: Microsoft Security Groups
    ... resources, ... Global and Domain local groups for the past few ... > When would you use this group over a global group and why? ... > Microsoft recommends that you don't apply any permissions to the user ...
    (microsoft.public.security)
  • Re: ADMT and SIDs
    ... but will the permissions need to be reassigned once ... >that is the SID from the old NT domain. ... >users will still be able to access resources in the NT ... >> existing user accounts along with the associated SID's, ...
    (microsoft.public.windows.server.active_directory)
  • Re: sub domain
    ... In a Windows 2000 network, parent and child domains have an automatic ... resources in both domains using the user accounts in each. ... assign permissions to the Domain Local group. ... I was going to create groups on the>subdomain and add the users from the parent to that domain. ...
    (microsoft.public.win2000.active_directory)
  • Re: Universal Group Issue
    ... it just changes the way it displays the group memberships and it does not ... change permissions to resources. ... > Is this just a display problem or would it cause issues with permissions ...
    (microsoft.public.windows.server.active_directory)
  • Re: User rights analysis
    ... >which and which kinds of resources exist in this forest. ... This "personal" namespace contains all the ... resources the user has permissions to and can be mapped as a drive. ... The personal namespace ...
    (microsoft.public.windows.server.active_directory)