RE: Create user that dont have access to domain

From: Allen Firouz (AllenFirouz_at_discussions.microsoft.com)
Date: 01/21/05


Date: Fri, 21 Jan 2005 08:55:04 -0800

Steve:

How are you locking down the PC's? Through a GPO or local policy?

It is not a good idea to have generic logins in any environment. That being
said and out of the way, your best bet is to creat an OU for the account and
apply a very restrictive GPO that restricts their access to browsing and
accessing network resources. If you have specific machines that need that
login, put the PCs in that OU as well and apply policy restictions on the
machine as well as the user policies. Without knowing how restrictive you
want it to be, it is hard to recommend GPO settings. Here are some useful
links:
GPO Setting overview and links:
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q322143
Restricting software using GPO (including access control)
http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/rstrplcy.mspx
Local policy settings for Windows XP:
http://www.microsoft.com/downloads/details.aspx?FamilyID=ef3a35c0-19b9-4acc-b5be-9b7dab13108e&displaylang=en

Hope that helps.

-Allen Firouz [MentalFloss]

"Steve" wrote:

> Hello,
>
> I have a program that uses Active Directory to authenticate the user to
> have access to that particular program. What I have set up in my environment
> is a generic login to these computers that is in a locked down state for
> security reasons. What I want to do is create a user that will pass
> authentication for this program via Active Directory but NOT allow them to
> log into the machine itself on the domain. I want the generic account with
> the locked down state logged in at all times. Any advice? Change permissons
> somewhere? Create a policy?



Relevant Pages

  • RE: Create user that dont have access to domain
    ... Through a GPO or local policy? ... > It is not a good idea to have generic logins in any environment. ... > apply a very restrictive GPO that restricts their access to browsing and ...
    (microsoft.public.windows.server.active_directory)
  • Re: Prevent logons other than PC owner?
    ... log on rights in local policy rather than by GPO. ... limiting all accounts without fail). ... >> In a domain Users includes Domain Users, ...
    (microsoft.public.windows.server.security)
  • Re: Deploy a local policy
    ... Get a GPO defined and linked to your OU and write of its ... by being innovative or by visiting 600 machines. ... being controlled by AD based GPO policy settings. ... > I need to change the local policy of all my computers in my domain. ...
    (microsoft.public.win2000.security)
  • Re: local gp vs domain based gp
    ... which may be set for a domain or OU linked GPO ... local policy would be effective only if the AD ... OU/domain/site-linked GPO doesn't apply) would the local policy then be ... effect if there were no conflicts with GPO based settings. ...
    (microsoft.public.windows.group_policy)
  • Re: local gp vs domain based gp
    ... Roger Abell [MVP] wrote: ... which may be set for a domain or OU linked GPO ... local policy would be effective only if the AD ... OU/domain/site-linked GPO doesn't apply) would the local policy then be ...
    (microsoft.public.windows.group_policy)