Home All Groups Group Topic Archive Search About

Limit users to logon only to computer that belong to user's domain

Author
10 Mar 2006 7:47 PM
Stefano Del Furia
Hi all,
i have 100Pcs used in 7 child domains in a single AD forest.
I would like to set a group policy so that an user can logon to his domain 
only from PCs that belong to that
domain.

I know that there is an "AD users and computers" account setting for 
granting access only to certain PCs but i have 400 users and 100 PCs and 
do it manually is a "very annoying game".
Could some one point me to the right direction ???
Thanks in advance
Stefano

Author
10 Mar 2006 8:03 PM
one3cap
i have never posted on here before but hey ill give it a shot. what about a
GPO for the computers in that domain and the setting allow logon locally and
add domain users group only for that domain because i am sure everyone is a
member of the domain user groups in that domain. just a thoughtnot telling
you the exact answer

Show quoteHide quote
"Stefano Del Furia" wrote:

> Hi all,
> i have 100Pcs used in 7 child domains in a single AD forest.
> I would like to set a group policy so that an user can logon to his domain 
> only from PCs that belong to that
> domain.
>
> I know that there is an "AD users and computers" account setting for 
> granting access only to certain PCs but i have 400 users and 100 PCs and 
> do it manually is a "very annoying game".
> Could some one point me to the right direction ???
> Thanks in advance
> Stefano
>
Author
11 Mar 2006 3:08 AM
Paul Bergson
I have one ou that the users aren't allowed to log onto any machine, it is
only used for domain web access.  I have set up a gpo on this ou that
completely locks all access down.  No icons on desktop, no programs on the
start menu, etc...  I have also included a logoff script which executes
logoff.exe.

If you wanted to use something similar you could place users in a group that
was denied apply for the gpo.  That way any users who don't belong to this
group would execute the logoff script.  The reason the lockdown is setup is
so if the uesrs are able to stop the logoff script they still have no access
to anything else.

http://www.ss64.com/nt/logoff.html

--


Paul Bergson  MCT, MCSE, MCSA, CNE, CNA, CCA
http://www.pbbergs.com/

This posting is provided "AS IS" with no warranties, and confers no rights.


"Stefano Del Furia" <de***@tech-center.com> wrote in message
news:op.s57qk5mtvqn431@nemo...
Show quoteHide quote
> Hi all,
> i have 100Pcs used in 7 child domains in a single AD forest.
> I would like to set a group policy so that an user can logon to his domain
> only from PCs that belong to that
> domain.
>
> I know that there is an "AD users and computers" account setting for
> granting access only to certain PCs but i have 400 users and 100 PCs and
> do it manually is a "very annoying game".
> Could some one point me to the right direction ???
> Thanks in advance
> Stefano