RE: Client Access Rights

From: Scott Ford (removethis.scott_at_starlite-entertainment.com)
Date: 02/23/05


Date: Tue, 22 Feb 2005 18:07:03 -0800

Blaze,

You can do this with Group Policy. Make a container in AD which contais all
the COMPUTERS (not users) in the admin and sales dept. Create a group policy
and, in it, go to COMPUTER CONFIGURATION > ADMINISTRATIVE TEMPLATES > SYSTEM
> LOGON. Now find the rule called "Only allow local user profiles" and enable
it. Now apply this policy to the container you made containing the computers
you want this enforced on. You will have to go to the individual computers
and delete the accounts off of them that you dont want logged on. The reason
for this is, when a roaming user logs into a network machine, windows
automatically downloads that user into the local profiles. Once the machine
policy is set, they wont be able to do this, and the oly way for a differnt
user to log in is if the Network Admin (You) installs that account on the
local machine using the administrive computer account. Hope this helps. Using
Group Policy for the first time always takes some experimentation.

"Blaze" wrote:

> Hi
>
> How can I restrict a Domain User Group from access ing a range of client
> PC's.. ie Admin cannot logon to Sales Departments PC's and Visa Versa
>
>
>



Relevant Pages

  • RE: Client Access Rights
    ... You can do this with Group Policy. ... the COMPUTERS in the admin and sales dept. Create a group policy ... Now apply this policy to the container you made containing the computers ...
    (microsoft.public.cert.exam.mcse)
  • RE: Client Access Rights
    ... You can do this with Group Policy. ... the COMPUTERS in the admin and sales dept. Create a group policy ... Now apply this policy to the container you made containing the computers ...
    (microsoft.public.win2000.networking)
  • Re: Group Policies have stopped working.
    ... > We've had Group Policies running for well over a year here with little ... > Group Policy was applied from: ... > My AD is split geographically with a US container with seperate Users ... > There is also a EU container with seperate Users and Computers ...
    (microsoft.public.win2000.group_policy)
  • Re: Group Policies have stopped working.
    ... > Group Policy was applied from: washington.silvacocorp.com> Group Policy slow link threshold: 500 kbps> ... > My AD is split geographically with a US container with seperate Users> and Computers containers below the US container. ...
    (microsoft.public.win2000.group_policy)
  • RE: Deploy SP2 with Active Directory and GPOs?
    ... In a Windows 2000 or Windows 2003 based domain, ... Group Policy is stored as part of Active ... publish programs to users or computers in the Windows 2000 or Windows 2003 ... After the installation files have been prepared, ...
    (microsoft.public.windowsxp.general)

Loading