In Local Security Policy for the secure machines or in Group Policy for an
OU containing the secure machines, go to user rights assignment and add the
desired users/groups to:
Deny access to this computer from the network
and
Deny logon locally
Doug Sherman
MCSE Win2k/NT4.0, MCSA, MCP+I, MVP
"aken" <(E-Mail Removed)> wrote in message
news

431EC21-913F-48FC-B565-(E-Mail Removed)...
> hi,
> how can user/group in a domain with win2k server and win Xp pro clients,
be denied access to ceratain computers in the domain.
> this seems critical as datas in some computers needs security. we do make
backup and others relevent securty but would like to incoportrate this
feature.
>
> any suggestion,
>
> thnks
> aken