Restricting User Logons to Workstations in Domain

S

Stuart Mackie

Hi. This is probably a very basic question but I can't seem to find an
answer :)

At the minute any user in our domain can login to any workstation. We are
not using roaming profiles so a new user account with default settings is
therefore created on the workstation(s).

Is it possible to restrict a user to one workstion so that only they (and
the local admin) can logon ?

Thanks for any help,
Stuart.
 
S

Steven L Umbach

You can configure that in Local Security Policy/security settings/local policies/user
rights assignments for logon locally where you would list administrators and users.
There is also a deny setting, but be careful using it keeping in mind that
administrators are members of the users and administrators group. --- Steve
 
M

Michael Bednarek

Hi. This is probably a very basic question but I can't seem to find an
answer :)

At the minute any user in our domain can login to any workstation. We are
not using roaming profiles so a new user account with default settings is
therefore created on the workstation(s).

Is it possible to restrict a user to one workstion so that only they (and
the local admin) can logon ?

Active Directory Users and Computers (or shorter: dsa.msc): Double-click
a user, tab: "Account", button: "Log On To..."
or shorter:
NET USER JaneDoe /DOMAIN /WORKSTATIONS:pC1,PC2
See also: NET HELP USER or
ms-its:c:\winnt\Help\ntcmds.chm::/net_user.htm
 
S

Stuart Mackie [MVP, MSP]

Sorry it took me as long to post back. Thats perfect, thanks for your help.

Stuart.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top