Is it possible to restrict access

  • Thread starter Thread starter Leo
  • Start date Start date
L

Leo

to the local computer a user logs into from a GPO that I
setup on the Domain Controller?

For example if you belong to a group called Finance, can I
setup a policy on the domain that restricts any member of
the Finance group from accessing their CD-ROMs, or they
cannot see 'My Computer' icon...etc etc.

Thanks
Leo
 
Yes. Although you don't directly apply GPO to groups (you apply them to
Sites, Domains or OUs) you can use groups to filter the policy - either
allowing or disallowing the applying of the GPO.
 
I don't think there is a setting to restrict local access to a cdrom. However there
are two parts to a GPO - computer and user. If you are configuring user
configuration, then the users need to be in the scope of influence of the GPO. Domain
Controller policy affects only domain controllers and the users that log on to them.
You would want to configure a GPO at the domain level if you want to apply it to all
users and non domain controller computers. If you want to apply more granular policy
to specific users then create an OU for those users with a GPO for them and move
those users into that GPO. Keep in mind password/account policy for domain members
can only be set at the domain level. ---Steve
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Back
Top