Re: AD account - limiting access to a single server

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Howdie!

RadioLontrA schrieb:
What about creating a gpo for the whole domain, excluding that single
computer, saying "deny access to this computer from the network" for
that user?

Good point, you could to that - but "injecting" every single machine and server in your domain just to lock out one single user. I don't feel like this is a good approach for such a thing. If you feel the effort is worth it and you're not afraid to create new policy at domain level and affect every client with it, you can give it a try, that should work.

Be sure to only add the particular user to that since you could easily lock yourself and all users out.

if he has local admin privileges he shouldnt be able to change domain
policies..

If you configure an Administrative Template which is nothing more than a registry entry in the client's registry, "Bob the bad guy" could, using his local administrative rights, change the corresponding registry entry's key and "unlock" whatever you set by (domain) policy. At least he could until the background refresh of Group Policy takes place and your settings get applied again. Then he would have to re-do his "reghacks"...

cheers,

Florian
--
Microsoft MVP - Windows Server - Group Policy.
eMail: prename [at] frickelsoft [dot] net.
blog: http://www.frickelsoft.net/blog.
.



Relevant Pages

  • RE: WSUS 3.0
    ... we need to configure a DWORD registry on the client. ... "Does this port need to be added in the group policy object where I ... specify the URL of the server?" ...
    (microsoft.public.windows.server.general)
  • Re: Remote Desktop
    ... group policy you can create a separate organization unit on the domain and ... Try the registry first, it should work. ... server) without affecting other servers. ... It will also no allow you to enable Offline files, ...
    (microsoft.public.windows.server.general)
  • Re: Group Policy Error - Parameter Incorrect
    ... Go into the registry on the server. ... then open group policy editor and change it in there. ... > It then opens the Group Policy Object Editory, however it just has a red X> on the root of the tree on the left pane. ...
    (microsoft.public.windows.group_policy)
  • RE: Terminal Server & SBS2k3
    ... Thank you for posting in SBS newsgroup. ... I understand you want to apply a group policy to lock ... How to lock down a Windows Server 2003 or Windows 2000 Terminal Server ...
    (microsoft.public.windows.server.sbs)
  • RE: Group policy
    ... >How can i create a group policy in windows 2000 server, ... How to Lock Down a Windows 2000 Terminal Server Session ... Definition of the RunOnce Keys in the Registry ...
    (microsoft.public.win2000.general)