How to restrict some users to log in?

How to restrict some users to log in?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
How to restrict some users to log in? Harvey 10-16-2006
Posted by =?Utf-8?B?SGFydmV5?= on October 16, 2006, 6:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We have a Win 2003 domain that has several OUs. Each OU has several
user-groups for different Labs -- for security issues, e.g. file sharing,
printer sharing etc. Currently, all users in a OU can login to any computer
that
belongs to that OU (not neccessary in the same Lab). Now, a director of a
lab
asks me if there is a way to allow only users in his lab be able to log in
to his lab's computers. That is only one group of users can log in some
computers, but other user-groups cannot log in those computers even they are
in the same OU. Is it possible to do this? How to do it?

Any help or link is greatly appreciated!

Harvey


Posted by Roger Abell [MVP] on October 16, 2006, 7:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
The most simple and direct way to do this is to take control over either
the user right to Log on locally, or, the membership of the Users group,
on each machine. You can do either using a GPO linked to the OU that
contains the affected machines (in your case you may want to consider
a minor reorganization so that there is an OU for computers of each lab,
likely as a subOU within the current OU)
You need to be very careful that Authenticated Users and/or Domain
Users are not granted the local login user right, either directly or via
membership in Users (if Users is given that user right)
--
Roger Abell
Microsoft MVP (Windows Server : Security)

> We have a Win 2003 domain that has several OUs. Each OU has several
> user-groups for different Labs -- for security issues, e.g. file sharing,
> printer sharing etc. Currently, all users in a OU can login to any
> computer
> that
> belongs to that OU (not neccessary in the same Lab). Now, a director of a
> lab
> asks me if there is a way to allow only users in his lab be able to log in
> to his lab's computers. That is only one group of users can log in some
> computers, but other user-groups cannot log in those computers even they
> are
> in the same OU. Is it possible to do this? How to do it?
>
> Any help or link is greatly appreciated!
>
> Harvey
>



Posted by =?Utf-8?B?SGFydmV5?= on October 17, 2006, 11:33 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I will try. Thanks, Roger.

Harvey

"Roger Abell [MVP]" wrote:

> The most simple and direct way to do this is to take control over either
> the user right to Log on locally, or, the membership of the Users group,
> on each machine. You can do either using a GPO linked to the OU that
> contains the affected machines (in your case you may want to consider
> a minor reorganization so that there is an OU for computers of each lab,
> likely as a subOU within the current OU)
> You need to be very careful that Authenticated Users and/or Domain
> Users are not granted the local login user right, either directly or via
> membership in Users (if Users is given that user right)
> --
> Roger Abell
> Microsoft MVP (Windows Server : Security)
>
> > We have a Win 2003 domain that has several OUs. Each OU has several
> > user-groups for different Labs -- for security issues, e.g. file sharing,
> > printer sharing etc. Currently, all users in a OU can login to any
> > computer
> > that
> > belongs to that OU (not neccessary in the same Lab). Now, a director of a
> > lab
> > asks me if there is a way to allow only users in his lab be able to log in
> > to his lab's computers. That is only one group of users can log in some
> > computers, but other user-groups cannot log in those computers even they
> > are
> > in the same OU. Is it possible to do this? How to do it?
> >
> > Any help or link is greatly appreciated!
> >
> > Harvey
> >
>
>
>

Similar ThreadsPosted
Restrict users to only connect to our wireless network July 30, 2005, 10:23 am
How to restrict users to access web pages all exept one July 8, 2006, 2:03 pm
How do I restrict users from joing member servers to my domain May 1, 2006, 6:02 am
How to restrict others to "Add Reference" to a DLL ? August 12, 2005, 6:03 am
Restrict Anonymous access November 5, 2006, 5:05 am
restrict access to desk top only March 19, 2008, 3:04 pm
Restrict take ownership rights September 3, 2008, 11:01 pm
Restrict Installs to only be from local network October 11, 2005, 10:19 am
how to restrict limited user only visiting several websites July 1, 2006, 10:34 pm
What is the best way to restrict access to Domain Admins on certain folders? March 19, 2008, 10:31 am

The site map in XML format XML site map

Contact Us | Privacy Policy