Re: Authenticated Users & Interactive groups
- From: Kurt <kurtl@xxxxxxxxxxxxxxxxx>
- Date: Mon, 26 Feb 2007 12:34:59 -0800
andrewbb@xxxxxxxxx wrote:
It appears those are BUILTIN Groups. Is there a way to create a User
or a Group that ONLY includes those two groups? That would seem to
create a synthetic Guest account, correct?
Is this possible?
In case you're wondering why: I'd like to create a User that is not a
member of Guests or Users, but can log into the computer interactively
with a profile. The Users group has too much permission and the
Guests group profiles are deleted when they log out. So basically I
want a Guests account with a permanent profile. How?
Explicit "deny" takes precedence over inherited "permit". So you could create a user that is a member of the "Users" group and also a member of a group of your creation. You can explicitly deny permissions to that group. You can also put that user in an OU and define a very restrictive set of policies with limited user rights, etc.
....kurt
.
- Follow-Ups:
- Re: Authenticated Users & Interactive groups
- From: andrewbb
- Re: Authenticated Users & Interactive groups
- References:
- Authenticated Users & Interactive groups
- From: andrewbb
- Authenticated Users & Interactive groups
- Prev by Date: Authenticated Users & Interactive groups
- Next by Date: Re: DST2007 using script and Group Policy
- Previous by thread: Authenticated Users & Interactive groups
- Next by thread: Re: Authenticated Users & Interactive groups
- Index(es):
Relevant Pages
|
Loading