Re: Blocking log-ons to specific computers by specific users

Tech-Archive recommends: Fix windows errors by optimizing your registry



JR - one more remark - keep in mind that group policies do not apply to
Windows 98 systems - which actually is another argument for using the method
recommended by Isaac..

hth
Marcin

"Marcin" <marcin@xxxxxxxxxxxxxxxx> wrote in message
news:etEYvj6wJHA.4104@xxxxxxxxxxxxxxxxxxxxxxx
JR,
this seems to be a popular topic lately - check a similar post from Kim
dated 4/21.
In essence, Isaac's advice (and others from the previous post) is likely
the most efficient approach - although it is intended for scenarios where
you want to limit number of computers that individual users can use to log
on interactively - which might not be necessarily what you are trying to
accomplish.
If this happens to be the case, you could consider utilizing the "Allow
logon locallly" user right (rather than "Deny log on locally" by limiting
it to designated non-privileged group (GroupA in your example) for target
computers. As I have mentioned earlier, you should review
http://support.microsoft.com/kb/823659 regarding potential implications -
and test before applying this change in production. Note though that using
this method on per-computer basis still introduces considerable management
overhead (security group filtering plus having a large number of GPOs) -
so this approach would be more appropriate if you have designated groups
of computers with groups of users assigned to each...

hth
Marcin


"JR Raith" <james.raithiii@xxxxxxxxxxxx> wrote in message
news:ONSb6o3wJHA.5672@xxxxxxxxxxxxxxxxxxxxxxx
Hi Again,

I've been pulling my hair out trying to get a GPO going to block specific
users from logging in to specific computers, but it just doesn't seem to
be working. It's a 2003 Server and workstations ranging from Win98 to
WinXP.

I've been testing mostly on a Win2k client as that should work most
easily.

It seems ridiculous that I would have to add in every single group to the
"Deny Local Log-on" policy... I also seem to have trouble figuring out
where or how to apply a policy to a specific computer.

Ideally, I'd like to say "Users in Group A are allowed to log on to
Computer 1; all other users are denied." I'd hate to have to add more
than a dozen groups or so to the Deny List before setting this up for all
of the various computers became really, really tedious... Is there a
better way?

Thanks and sorry for the newbie question.
J.R.




.



Relevant Pages

  • Re: Applying GPO only to certain computers within an OU...........
    ... Don't forget that deny permissions take precedence over allows. ... I think if you remove the authenticated users grou0p from the acl, ... add in the security group "Yes Software" or whatever (the computers that are ... supposed to get the policy) and give them Read & Apply GPO permissions. ...
    (microsoft.public.win2000.group_policy)
  • Re: USB, Floppy & CD Drive access through GPO
    ... So if they are all linked at the domain level, then the last policy that runs will win. ... So, if your deny is at the top of the priority list, and denies all access to these devices, then all computers will receive the deny. ... You can change the order of GPOs linked at that level so that your deny all devices GPO is processed first. ... However, if you have no filtering on the subsequent device-specific allow GPOs, then all computers in the domain will simply get the allow for all devices. ...
    (microsoft.public.windows.group_policy)
  • Re: Joining Computers to Domain
    ... >>immediately indicate if you have a DENY somewhere. ... >>> is some permission that is blocking it. ... >>> Our problem is with student admins. ... >>> add computers to the domain. ...
    (microsoft.public.windows.group_policy)
  • Re: Re: Applying GPO only to certain computers within an OU.....
    ... > GPOs via security and groups. ... > moved computers will still get those GPOs applied to them. ... >> which we don't want the policy to apply. ...
    (microsoft.public.win2000.group_policy)
  • Re: Restricting domain users from logging on to XP
    ... This setting can also be set on all computers in your domain through group ... The setting is at the same location in the group policy editor ... > Deny Logon Locally policy and set the user's you whish to deny there. ...
    (microsoft.public.windowsxp.security_admin)