PC Review


Reply
Thread Tools Rate Thread

deny logon locally for other domain users

 
 
GM
Guest
Posts: n/a
 
      5th Apr 2004
Hi,

I want to make my computer (OS=Win2KPro) only accessible for certain
domain users. The domain my PC is on, is a Win2000 domain.
So on my PC, I created a group DenyLogon and added all those
users/groups who I want to deny to login. So I added this group
DenyLogon to the Deny Logon Locally policy of my PC ... but, this
approach doesn't seem to work (yes I rebooted my computer after wards) :-(

Anyone an idea what I did wrong ? Or can this only be accomplished by
editing the domain policies ?

Thanx in advance,

Gaëtan Martens

 
Reply With Quote
 
 
 
 
Dmitry Korolyov [MVP]
Guest
Posts: n/a
 
      5th Apr 2004
I believe the actual problem is in effective settings of the policy. I
assume you have edited "Deny Logon Locally" settings in local security
policy on these PCs. However, in Default Domain Policy this setting is also
defined, and the list is empty. Since domain policies override local
policies, the effective setting is that noone is denied local (interavtive)
logon privilege.
So yes, you have to edit domain policy. In fact, it would be a good idea to
create a policy specially for that purpose, define the setting(s) in that
policy, and apply it to all required computer accounts.

"GM" <(E-Mail Removed)> wrote in message news:c4ra4n$5mo$(E-Mail Removed)...
> Hi,
>
> I want to make my computer (OS=Win2KPro) only accessible for certain
> domain users. The domain my PC is on, is a Win2000 domain.
> So on my PC, I created a group DenyLogon and added all those users/groups
> who I want to deny to login. So I added this group DenyLogon to the Deny
> Logon Locally policy of my PC ... but, this approach doesn't seem to work
> (yes I rebooted my computer after wards) :-(
>
> Anyone an idea what I did wrong ? Or can this only be accomplished by
> editing the domain policies ?
>
> Thanx in advance,
>
> Gaetan Martens
>



 
Reply With Quote
 
GM
Guest
Posts: n/a
 
      5th Apr 2004


> So yes, you have to edit domain policy. In fact, it would be a good

idea to
> create a policy specially for that purpose, define the setting(s) in

that
> policy, and apply it to all required computer accounts.
>

Ok thanx,
but 1 major question: how do I do that ?

Gaëtan Martens

Dmitry Korolyov [MVP] wrote:
> I believe the actual problem is in effective settings of the policy. I
> assume you have edited "Deny Logon Locally" settings in local security
> policy on these PCs. However, in Default Domain Policy this setting is also
> defined, and the list is empty. Since domain policies override local
> policies, the effective setting is that noone is denied local (interavtive)
> logon privilege.


> "GM" <(E-Mail Removed)> wrote in message news:c4ra4n$5mo$(E-Mail Removed)...
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Deny Logon Locally art.stroud@gmail.com Microsoft Windows 2000 Security 0 7th Dec 2007 07:25 PM
Domain controller GPO does not deny logon locally right to IWAM_machinename when running aspnet.wp.exe \Rob\ Microsoft Windows 2000 Group Policy 4 12th May 2004 01:13 AM
Domain controller GPO does not deny logon locally right to IWAM_machinename when running aspnet.wp.exe \Rob\ Microsoft ASP .NET 4 12th May 2004 01:13 AM
Deny logon locally misslemike Microsoft Windows 2000 Active Directory 1 26th Jan 2004 12:46 PM
deny logon locally T.B. Windows XP Security 1 7th Aug 2003 12:02 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 07:19 PM.