Re: Access policy

jabrandt_at_online.microsoft.com
Date: 08/14/04


Date: Fri, 13 Aug 2004 19:11:00 -0500

Group Policy.
Create a GPO and apply it to a container that has all the computers you want
this setting to take effect on.

-- 
James Brandt [MSFT]
"Jerry" <anonymous@discussions.microsoft.com> wrote in message 
news:589701c48136$6cd6f3a0$a501280a@phx.gbl...
> Thanks fo the reply.
>
> Isn't there a way to do from the DC and apply it to all
> the machines or the machines tha I choose ?
>
> Regards
>
>>-----Original Message-----
>>Configure a security policy (through Group Policies) on
> all computers in the
>>domain makins that so only domain accounts have
> interavtive logon privilege.
>>For example, you can remove default "Authenticated
> Users", "Everyone" and
>>"Users" groups from that privilege, and assign it to
> Domain Users instead.
>>Since all domain user accounts are members of this
> group, they will be able
>>to log on, and local accounts which are not members,
> will not.
>>
>>-- 
>>Dmitry Korolyov [d__k@removethispart.mail.ru]
>>MVP: Windows Server - Active Directory
>>
>>
>>  "Jerry" <anonymous@discussions.microsoft.com> wrote in
> message
>>news:5ab801c48129$ff8428b0$a401280a@phx.gbl...
>>  Hi
>>
>>  Is there any way to force users using their domain
>>  accounts instead of local account to access the
> network?
>>
>>  Thanks
>>
>>  Jerry
>> 


Relevant Pages

  • Re: debugger user autochange
    ... One possibility could be that Group Policy Restricted Groups are being ... applied to the computers in question. ... I think I failed to convey the problem clearly - the user accounts ... domain/userxyz assigned to the administrator group. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Domain Users to have Local Admin rights
    ... Group Policy because a new policy doesn't wana work. ... to local Administrator group on all the computers. ... We have various admin accounts other then administrator ...
    (microsoft.public.windows.server.security)
  • Re: allow 1 user to logon ONLY to 1ou
    ... only computers a user is allowed to login to. ... it before and it didn't deny it at all. ... -All Accounts ... Depending on exactly what you need to do, you can user the Group Policy ...
    (microsoft.public.windows.group_policy)
  • Re: allow 1 user to logon ONLY to 1ou
    ... it before and it didn't deny it at all. ... -All Accounts ... -public computers ... Depending on exactly what you need to do, you can user the Group Policy ...
    (microsoft.public.windows.group_policy)
  • Re: Default Domain Policy - Password Policy
    ... The new policy won't take effect until users actually change their ... computers - since accounts of domain users are stored on domain controllers, ...
    (microsoft.public.windows.server.active_directory)