Restrict/deny logon privileges

M

msu-iitians

Create another group ex: called Managers Group and grant
this group to "Logon Locally".Select a certain user in the
active directory and in the member of tab select Managers
Group. Remove the selected persons from Domain Users group
since we will deny this group to "Logon Locally". Hope
this will help..
 
S

Steven Umbach

I would not recommend ever removing anyone from the domain users group
[not sure if it is even possible by default, and he has 36,000 users]. All that
needs to be done is what Walter suggested - only have the desired users/groups
in the allow logon locally user right. If you are not in that setting, then you
have implicit deny rights. --- Steve
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top