Networking Forums

Networking Forums > Computer Networking > Windows Networking > Client Access Rights

Reply
Thread Tools Display Modes

Client Access Rights

 
 
Blaze
Guest
Posts: n/a

 
      02-22-2005, 10:13 PM
Hi

How can I restrict a Domain User Group from access ing a range of client
PC's.. ie Admin cannot logon to Sales Departments PC's and Visa Versa


 
Reply With Quote
 
 
 
 
Phillip Windell
Guest
Posts: n/a

 
      02-22-2005, 10:18 PM
It is part of the individual user accounts, where you set which machines
they are allowed to log into. I don't think it can be done by "groups".


--

Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com


"Blaze" <(E-Mail Removed)> wrote in message
news:h0PSd.51$(E-Mail Removed)...
> Hi
>
> How can I restrict a Domain User Group from access ing a range of client
> PC's.. ie Admin cannot logon to Sales Departments PC's and Visa Versa
>
>



 
Reply With Quote
 
Steven L Umbach
Guest
Posts: n/a

 
      02-22-2005, 11:29 PM
You can use Group Policy to do such. For instance place a group of computer
accounts in an Organizational Unit. Then create a Group Policy for that OU
and add the global group you want to restrict to the deny logon locally or
deny access this computer from the network user right in computer
configuration/Windows settings/security settings/local policies/user rights.
Note that while this will work in general, ultimately you can not restrict a
domain admin that does not want to be restricted as they always have the
power to undo settings that restrict them. To do such you really need to use
separate domains or better yet separate forests. You still can connect
forests and/or domains with trusts. --- Steve


"Blaze" <(E-Mail Removed)> wrote in message
news:h0PSd.51$(E-Mail Removed)...
> Hi
>
> How can I restrict a Domain User Group from access ing a range of client
> PC's.. ie Admin cannot logon to Sales Departments PC's and Visa Versa
>



 
Reply With Quote
 
=?Utf-8?B?U2NvdHQgRm9yZA==?=
Guest
Posts: n/a

 
      02-23-2005, 01:07 AM
Blaze,

You can do this with Group Policy. Make a container in AD which contais all
the COMPUTERS (not users) in the admin and sales dept. Create a group policy
and, in it, go to COMPUTER CONFIGURATION > ADMINISTRATIVE TEMPLATES > SYSTEM
> LOGON. Now find the rule called "Only allow local user profiles" and enable

it. Now apply this policy to the container you made containing the computers
you want this enforced on. You will have to go to the individual computers
and delete the accounts off of them that you dont want logged on. The reason
for this is, when a roaming user logs into a network machine, windows
automatically downloads that user into the local profiles. Once the machine
policy is set, they wont be able to do this, and the oly way for a differnt
user to log in is if the Network Admin (You) installs that account on the
local machine using the administrive computer account. Hope this helps. Using
Group Policy for the first time always takes some experimentation.

"Blaze" wrote:

> Hi
>
> How can I restrict a Domain User Group from access ing a range of client
> PC's.. ie Admin cannot logon to Sales Departments PC's and Visa Versa
>
>
>

 
Reply With Quote
 
Kurt
Guest
Posts: n/a

 
      02-23-2005, 08:16 PM

This would only be a problem if the users in question had domain admin
rights. I think you've hit the solution on the head. If the OPs users are
all domain admins, there's little hope for any kind of security..


...kurt

"Steven L Umbach" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> You can use Group Policy to do such. For instance place a group of

computer
> accounts in an Organizational Unit. Then create a Group Policy for that OU
> and add the global group you want to restrict to the deny logon locally or
> deny access this computer from the network user right in computer
> configuration/Windows settings/security settings/local policies/user

rights.
> Note that while this will work in general, ultimately you can not restrict

a
> domain admin that does not want to be restricted as they always have the
> power to undo settings that restrict them. To do such you really need to

use
> separate domains or better yet separate forests. You still can connect
> forests and/or domains with trusts. --- Steve
>
>
> "Blaze" <(E-Mail Removed)> wrote in message
> news:h0PSd.51$(E-Mail Removed)...
> > Hi
> >
> > How can I restrict a Domain User Group from access ing a range of client
> > PC's.. ie Admin cannot logon to Sales Departments PC's and Visa Versa
> >

>
>



 
Reply With Quote
 
Blaze
Guest
Posts: n/a

 
      02-25-2005, 07:33 PM
Thanks Guys :-)


"Kurt" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>
> This would only be a problem if the users in question had domain admin
> rights. I think you've hit the solution on the head. If the OPs users are
> all domain admins, there's little hope for any kind of security..
>
>
> ..kurt
>
> "Steven L Umbach" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>> You can use Group Policy to do such. For instance place a group of

> computer
>> accounts in an Organizational Unit. Then create a Group Policy for that
>> OU
>> and add the global group you want to restrict to the deny logon locally
>> or
>> deny access this computer from the network user right in computer
>> configuration/Windows settings/security settings/local policies/user

> rights.
>> Note that while this will work in general, ultimately you can not
>> restrict

> a
>> domain admin that does not want to be restricted as they always have the
>> power to undo settings that restrict them. To do such you really need to

> use
>> separate domains or better yet separate forests. You still can connect
>> forests and/or domains with trusts. --- Steve
>>
>>
>> "Blaze" <(E-Mail Removed)> wrote in message
>> news:h0PSd.51$(E-Mail Removed)...
>> > Hi
>> >
>> > How can I restrict a Domain User Group from access ing a range of
>> > client
>> > PC's.. ie Admin cannot logon to Sales Departments PC's and Visa Versa
>> >

>>
>>

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Access Rights George Schneider Windows Networking 2 02-12-2007 01:18 PM
Wireless USB stick access rights question Justin Wireless Internet 2 07-06-2005 11:23 PM
Administrator access rights of win 2003 from MAC. Abhijit Windows Networking 0 04-14-2004 10:14 AM
User Access Rights To Folder Jason Windows Networking 1 02-03-2004 09:06 AM
User level-access rights in Win 98? Leo Edwards Windows Networking 3 07-15-2003 10:38 AM



1 2 3 4 5 6 7 8 9 10 11