Re: Only logon to computers in 1 OU
- From: Caesar <Caesar@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Wed, 15 Oct 2008 12:18:14 -0700
Thanks for the reply, but since I have so many OU's in my Active Directory I
would really like to just set this one user up with allow only, and not have
to go to the over 100 different OU's to deny access.
Plus, I am not well versed in scripts or how to write them. I have a user
we'll call "AI_User" and an OU called deptartments\finance\ap\computers If
you say "run a script" do you know where I can find samples written?
Thanks
"Florian Frommherz [MVP]" wrote:
Caesar,.
Caesar wrote:
I want to know how through GPO I can have this 1 user only logon to the
computers in their department's OU?
I don't want to add computers in AD and then have to Add and Delete
everytime the department gets new systems. There has to be a way in GP to do
this but I don't see it.
I need to do this ASAP so any help quickly is more than appreciated!
The other way round would be possible but doesn't meet your requirement
(not to re-configure when new systems arrive). Is that a restriction to
this particular user or is that a requirement that nobody (except the
one user) needs access (only) to the machines?
There isn't a built-in functionality for this, you'll either have to
script it or link a GP with the "Deny log on locally" security setting
with the user's username to all other server except the OU he needs
access to the machines.
cheers,
Florian
--
Microsoft MVP - Group Policy
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
Maillist (german): http://frickelsoft.net/cms/index.php?page=mailingliste
- Follow-Ups:
- Re: Only logon to computers in 1 OU
- From: Florian Frommherz [MVP]
- Re: Only logon to computers in 1 OU
- References:
- Only logon to computers in 1 OU
- From: Caesar
- Re: Only logon to computers in 1 OU
- From: Florian Frommherz [MVP]
- Only logon to computers in 1 OU
- Prev by Date: Re: Only logon to computers in 1 OU
- Next by Date: Re: Only logon to computers in 1 OU
- Previous by thread: Re: Only logon to computers in 1 OU
- Next by thread: Re: Only logon to computers in 1 OU
- Index(es):
Relevant Pages
|
Loading