using groups to assign "log on to" computer permissions

From: mark1629 (mark1629_at_discussions.microsoft.com)
Date: 02/01/05


Date: Tue, 1 Feb 2005 08:01:04 -0800

In my organization, specific user groups are only permitted to log on to
certain computers in their area. For example, one group has 15 users, and
all 15 can log on to any of the 10 computers in their area. Up until now we
have been selecting each user's account in Active Directory Users and Groups,
selecting "Log on To", and adding each computer manually. We then repeat
this for each user account in the group, meaning we have to type the names of
the 10 computers as many times as we have users in that group. When new
computers are added or changed, we have to edit each account individually.

Is there a way to assign log on permissions to an entire group at a time? I
would also be happy to do it the opposite way: if I could tell each user
account it can log on to a group of computers. Or tell a group of users it
can log on to each computer...Is there some way to use groups to do this
rather than individual accounts?

Thanks in advance,
Mark



Relevant Pages

  • Re: Custom rights
    ... Try giving user who is adding account View Only Exchange Administrator ... >> To add computers to the domain go to AD Users and Computers. ... you will have to manually configure permissions on that user object ... >>> Look into AD delegation, though you may need to do some custom ...
    (microsoft.public.win2000.security)
  • Re: Windows security Question
    ... > i wasn't able to have users from other computers from my LAN being ... > does it require that I create an account on my own computer for each ... in order to set up their privileges and permissions ... > time they try to access my shared folders? ...
    (microsoft.public.win2000.security)
  • Re: Accounts keep disappearing from Security Tab
    ... was to remove all other permissions other than "Send As". ... Start Active Directory Users and Computers; ... Click the Security tab, ... In the Select User, Computer, or Group dialog box, click the user account ...
    (microsoft.public.windows.server.active_directory)
  • Re: Alerting - Malicious software removal tool
    ... >needed to install an application that she could not install from ... >"Administrator" account. ... You failed to analyze the root cause and correct it ... use their computers to have fun. ...
    (microsoft.public.security.virus)
  • RE: User template question
    ... Account tab). ... A new logon script was also assigned from the Profile tab. ... I'm afraid that your purpose cannot be achieved through User Template. ... Deploys software to user computers. ...
    (microsoft.public.windows.server.sbs)