Re: Logon Domain

From: Lee Marsden [MSFT] (leemar_at_online.microsoft.com)
Date: 06/09/04


Date: Wed, 9 Jun 2004 15:03:48 +0100

Hi Svein,

There is no supported way to 'hide' a domain in the same forest from the
logon UI. The domains appear because the are trusted by the domain that the
workstation logs in to. You could ask your users to use UPN logon so that
the domain field in the logon UI is not available. Then they would not be
able to select the other domain to log on to.

Hope this helps,

Lee.

-- 
This posting is provided "AS IS" with no warranties, and confers no rights.
"Svein P Johnsen" <anonymous@discussions.microsoft.com> wrote in message 
news:06ECA88B-500C-4D42-8B51-3DB17D8841C0@microsoft.com...
> Hi
>
> Enviroment (functional level):
> Forest: Windows Server 2003
> Domain(s): Windows Server 2003
>
> I've set up a forest root domain, and a new domain in an existing forest.
> I've created two sites, two subnets, and put in the GC in the propiate 
> site for its respective domain
>
> It works very well, as the eventlog gives me "ok" for replication etc.
>
> Now to the problem:
> Users in Site A does not need to see "Domain B" as an alternative logon 
> domain, and visa versa
> How do I get rid of this?
>
> I guess the tool are "Sites and Services" MMC, but not really sure how.
>
> Svein-P Johnsen 


Relevant Pages

  • RE: Logon in interim mode
    ... Windows Server 2003 in the forest in each domain: ... The domain naming master in the forest so that you can create default DNS ... The primary domain controller in each non-root domain so that you can ... and promote it to DC and set it as GC to speed up the logon process. ...
    (microsoft.public.windows.server.migration)
  • Re: Forest trust child domain not visible in logon dialog box
    ... search for "User Experience Changes in Moving to Forest ... Trusts from External Trusts" ... the logon dialog box do not display the child domain B ... only the root domain A. I have no problem logging on by using the user ...
    (microsoft.public.windows.server.active_directory)
  • RDP onto DCs with non-admin accounts
    ... Production Forest there are 4 DCs which won't accept the logon. ... the sysem won't allow you to logon interactively"; however this user account ...
    (microsoft.public.windows.server.active_directory)
  • GC Question
    ... I know that is needed at least one GC per forest. ... The GC enables finding directory information regardless of which domain in ... and provides Universal Group Membership ... Gc was available then the users would only be allowed to logon locally. ...
    (microsoft.public.win2000.active_directory)
  • Re: AD Last User Logon Question
    ... We are currently domain functional level 2003> not forest. ... Last logon is not a replicated attribute, it is unique> to every DC. ... > Replicating last logon>>attributes would have killed my directory. ... We have run 3 different tools to show us>>> last logon date for each user account:>>> ...
    (microsoft.public.windows.server.active_directory)