Re: User Login



We have several inactive accounts, and these users use their departmental
login to logon to the domain. We plan to activate these accounts for them to
logon to their email (not exchange). So, if we activate their accounts, they
will be able to logon to any computers which we do not want to and we would
like to restrict these group of users not to logon with their own credentials
to the domain or to the local computer. Instead only use this for email login
purpose. I hope I am clear in this.

thanks again for you earlier response.


"Meinolf Weber" wrote:

Hello Neil,

If i got you correct, they should only be aible to logon to the domain and
not to the local machine without the domain? Create and link a GPO to the
OU, move the computers there and set:

Computer configuration, windows settings, security settings, local policies,
security options, in the right pane choose "Interactive logon: Number of
previous logons to cache" and set it to "0", so it is disabled.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

I am looking to add a set off users in AD to a separate group and want
to restrict these users not to logon to computers since they logon
with departmental login credentials. How can I go about doing it.

thanks in advance!




.



Relevant Pages

  • Re: Domain Password Security
    ... accounts need to use complex passwords and minimum of ntlmv2 should be used for lan ... Services Client and configuring authentication level on Domain Controller Security ... controllers if you have all W2K/XP computers. ... I also recommend you enable auditing of account logon and logon ...
    (microsoft.public.win2000.security)
  • Re: Domain Password Security
    ... Domain Controller Security ... >controllers if you have all W2K/XP computers. ... >administrator accounts only when needed to, ... account logon and logon ...
    (microsoft.public.win2000.security)
  • Re: User Login
    ... The accounts are currently disabled, but they will be enabled when they link ... "Meinolf Weber" wrote: ... accounts for them to logon to their email. ... they will be able to logon to any computers ...
    (microsoft.public.windows.server.active_directory)
  • Re: Making the case for not installing DCs on remote sites (2xT1 links)
    ... 25,000 users;-) and I don't know how may servers -4,000 perhaps. ... I think that the logon ... >>>>to logon from branch offices where I have no DC+GC there. ... >>>>offices with more than 60 computers. ...
    (microsoft.public.win2000.active_directory)
  • Re: OWA 2003 is only accessable during workingdays
    ... Is it the same when you log in from a client on the network? ... thinking of AD Users and Computers, Properties, Accounts, Logon Hours. ...
    (microsoft.public.exchange.misc)