allow 1 user to logon ONLY to 1ou



I have 1 user named "IA_User" that needs to logon to the 15 or so machines
inside of 1 or 2 OUs on my network. I have probably another 100 OUs of
computers that we do not want this use to be able to logon to.

I don't want to us the "Logon To" button in AD because if the computers get
added or deleted (moved) we don't want to have to change the settings in AD
each time as that would get messy. I am also thinking that once done we may
get more requests so I don't want to have to manually check 50 accounts
everytime a computer gets added or pulled off the network.

thanks
.