Re: Windows Logon Access

Tech-Archive recommends: Speed Up your PC by fixing your registry



This is because 'Domain Users' is in the 'Users' group of every domain
member by default. Only Administrators, Backup Operators, Guest, Power
Users, & Users can logon interactively to domain members.

You need to add your new global group to one of those groups on machines
that the users need to logon to or simply give the new global group 'Log on
locally' privileges to their respective set of machines via GPO or similar.
This setting is under 'Computer Configuration', 'Windows Settings',
'Security Settings', 'Local Policies', 'User Rights Assignment', 'Log on
locally'.

Note: If you modify this setting in group policy, be sure to place all
users/groups that you want to log on locally into the GPO as it will replace
the list, not append.

--
Tim

"Nphil" <Nphil@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:0CB6FF4A-084A-43AF-9126-091ED4968DEE@xxxxxxxxxxxxxxxx
When I remove a user fromthe Domain User group that user is not able to
logon
to the domain any at all. It there anyway to specifiy a new group as thw
primary group and still have the user logon to the domain and gain access
to
only explicit resources that this new global group has access to?

please help.



.



Relevant Pages

  • Re: Long time taking for Single user to logon
    ... Have them try and logon to a different workstation. ... posting is provided "AS IS" with no warranties, and confers no rights. ... Any chance that the user is member of an Universal Group? ... Asked user to login from some diffrent system from the same site. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM userProxy userPrincipalName domain suffix issue
    ... especially IF that member is a userProxy object? ... The membership of a group in ADAM is defined by the member attribute ... Successful Network Logon: ...
    (microsoft.public.windows.server.active_directory)
  • Re: User Login
    ... filtering so that only this group gets the deny logon locally privilegs. ... the domain group called Domain Users is a member of the local ... put those user accounts into domain group and apply a GPO to the OU ... "Meinolf Weber" wrote: ...
    (microsoft.public.windows.server.active_directory)
  • RE: Possible?
    ... the anonymous logon is not a AD user group as such and not something ... Its whats known as a 'special group' and can't be managed ... If a user is connecting to a resource in certain ways they ... We have a XP machine that is a member of the domain. ...
    (microsoft.public.windows.server.sbs)
  • RE: Adding Groups on the basis of text in a VBScript
    ... Firstly we need to read multiple text files, which are acting as logon ... If the Datalink string is present the filename of the file being read should ... > WScript.Echo " You are a member of Domain Admins " ... >> scripts which utilize vbscript. ...
    (microsoft.public.windows.server.scripting)