Re: Need advice on limiting login's by users

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Mike - some random thoughts:

That res kit tool should work, but consider this. Let's say you create one or more local (not domain) accounts for the summer workers to use for e-mail or whatever. Now someone involved in sharing mp3s or whatever logs in with that account you thought was safe and had no domain access, and ends up installing a trojan or virus on that machine through some action they consider innocent. Even though you may have taken precautions to prevent the person from accessing domain resources, I think you put your network at risk by allowing "strangers" any access whatsoever to your production domain.

I have a guest wireless network that is isolated from our production LAN. For guests who don't have laptops of their own, I have an inexpensive XP laptop that's locked down with the Shared Computer Toolkit. They connect through the guest network. So what I would propose is to take some number of those shared PCs and dedicate them solely to workers who don't require their own accounts on your domain. Lock them down and isolate them from your production network however you have to - you could even put in a separate Internet connection just for a little workgroup created for this purpose (or a standalone PC). The Shared Computer Toolkit has been upgraded since I built that laptop - you might want to look into it and see what you think.



"Mike in Nebraska" <Mike_in_Nebraska@xxxxxxxxxxxxxxxx> wrote in message news:F7FA013F-CB69-4E2A-84DA-A7D16D4CCB81@xxxxxxxxxxxxxxxx
Running SBS 2003 Premium. Workstations a mix of WinXP Pro SP3 and Vista Business SP1.
=================
I've got what I perceive as a problem; every year during Spring and Summer we get a bunch of undergrad and grad students in do do work for us, or complete their theses. We have a bunk house for them to live in with wireless access. However, some of the kids don't bring laptops so they ask their staff sponsor to let them on one of our PC's so they can check email, etc. We have 4 PC's in a work room for projects, temp staff, etc. and the staff member will take them in and login with their login info and go back to work, leaving the kid alone.

While I can't pinpoint a problem in the network due strictly to this practice, I still am very much against it. I am firm in our staff meetings about the security risks, but they just smile and ignore me.

I'd rather not wait for an "I told you so" moment as I'll be the one to clean up the mess.

I did some searching and found an old tool called LimitLogin utility http://support.microsoft.com/kb/237282 as part of the Windows 2000 Kit.

Any comments on this or other tools? My thought is to restrict the staff to one "active" login at a time to prevent the above practice. In other words, they'd have to log out of a PC before they could login to another.

TIA,

--
Mike Webb
Platte River Whooping Crane Maintenance Trust, Inc.
a conservation non-profit (501 (c)(3)) organization
Wood River, NE

.



Relevant Pages

  • Re: Need advice on limiting logins by users
    ... Even though you may have taken precautions to prevent the person from accessing domain resources, I think you put your network at risk by allowing "strangers" any access whatsoever to your production domain. ... I have a guest wireless network that is isolated from our production LAN. ... We have 4 PC's in a work room for projects, temp staff, etc. and the staff member will take them in and login with their login info and go back to work, leaving the kid alone. ...
    (microsoft.public.windows.server.sbs)
  • Domain logon
    ... I joined a XP Pro laptop to our ... It logged in fine and I went back to user accounts and added the ... Now the problem that I have is that on initial login after the machine has ... If I am connected to the network and login, although the initial login is so ...
    (microsoft.public.win2000.active_directory)
  • Re: Domain Users loging into Win98 machine.
    ... I like to ditch the w98 machine but unfortunately we cnat as the accounts ... ppl use it to fax thing across on a modem, and there isn't any modem drivers ... > the network, but because your password conflicts with the password it's ... >> innitial login prompt asks for username, pass, domain. ...
    (microsoft.public.win2000.networking)
  • Re: Need my Welcome Screen back
    ... network" (there will be a third "domain" box available on the login screen)? ... Note that this will disable all domain accounts from being able to ... I just want to choose my personality and go. ...
    (microsoft.public.windowsxp.configuration_manage)
  • Re: win login in xp
    ... > Does anyone know of any way to disable the xp user login? ... > login in to the network and have access to all the ... are using roaming profiles) and you should have access to all ... You should only have to create network accounts for all of the users - ...
    (microsoft.public.windowsxp.security_admin)