blog sistemITecblog sistemITec

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Schedule a job on Aruba Switch

    July 5, 2023

    How to decrypt and verify text or files with GPG Services

    June 28, 2023

    How to send WhatsApp messages to someone without saving their phone number

    June 19, 2023
    Facebook Twitter Instagram
    • sistemITec website
    • contact us
    Facebook Instagram YouTube LinkedIn
    blog sistemITecblog sistemITec
    • IT Fundamentals
        Featured
        IT Fundamentals

        How to send WhatsApp messages to someone without saving their phone number

        By Cornel CabaJune 19, 20230
        Recent

        How to send WhatsApp messages to someone without saving their phone number

        June 19, 2023

        Network Topology Guide

        June 19, 2023

        Top 20 Essential ESXCLI Commands

        June 19, 2023
      1. Gaming
          Featured
          Gaming

          Application load error 5:0000065434 in Steam

          By sistemitec's teamAugust 8, 20210
          Recent

          Application load error 5:0000065434 in Steam

          August 8, 2021

          The Best Overlooked Video Game Of 2020

          August 2, 2021

          Hearts of Iron IV Review

          August 2, 2021
        1. Software
            Featured
            Software

            Schedule a job on Aruba Switch

            By Cornel CabaJuly 5, 20230
            Recent

            Schedule a job on Aruba Switch

            July 5, 2023

            How to decrypt and verify text or files with GPG Services

            June 28, 2023

            Windows Server 2019/ Product Key Free

            June 19, 2023
          1. Gadgets
              Featured
              Gadgets

              How to Simulate Arduino Projects With Proteus

              By Cornel CabaMarch 17, 20220
              Recent

              How to Simulate Arduino Projects With Proteus

              March 17, 2022

              How connect Apple AirPods to a Windows PC

              February 10, 2022

              How to Put Ebooks on Amazon Kindle

              October 12, 2021
            1. Tech
                Featured
                Tech

                Lenovo Unveils IdeaPad Laptops, 5G Internet & a Snapdragon 8cx Chipset

                By Cornel CabaJanuary 15, 20210
                Recent

                Lenovo Unveils IdeaPad Laptops, 5G Internet & a Snapdragon 8cx Chipset

                January 15, 2021

                2021 Apple MacBook Air: Apples New Leak Reveals Razor-thin Redesign

                January 15, 2021
                8.9

                Review: Xiaomi’s New Loudspeakers for Hi-fi and Home Cinema Systems

                January 15, 2021
              blog sistemITecblog sistemITec
              Home»Software»How to restrict computer logons to a group of users
              Software

              How to restrict computer logons to a group of users

              Cornel CabaBy Cornel CabaJune 19, 2023Updated:June 19, 2023No Comments4 Mins Read
              Facebook Twitter Pinterest LinkedIn Tumblr Email
              Share
              Facebook Twitter LinkedIn Pinterest Email

              Certain computers in open areas such as a laboratory need to be locked down to only allow those users to logon that are authorized to use that computer. This is easily done with group policy.

              Step 1: Create or select an organizational unit to which the policy will apply.

              If you already have an organizational unit (OU) which contains the computers you wish to restrict, select it. otherwise, create an OU for the policy and move the computers that require restricted access into that OU. be sure to apply your other required group policy objects to the OU as well. To create an OU, open active directory users and computers right click on the domain, select new and then select Organizational unit name the OU and click OK

              Step 2: Create a global security group to contain users.

              You can apply your group policy to individual users but it is more readable if you have a group called allowed users for restricted lab and apply the policy to that. then you will get feedback when looking at users that they are a member of the lab and are allowed to logon to the computers. in active directory users and computers,

              Step 3: Create the group policy object (GPO)

              How to step

              Open the Group Policy Management plug-in, right click on Group Policy Objects and select new, then. name the policy something like restricted lab allowed logons. or another appropriate name. I like to create lots of little policies that implement a few settings as opposed to one huge policy with far reaching settings because they are easier to implement and troubleshoot..

              Step 4: Add your policies to the GPO

              How to step

              You are going to configure two Local Policies right click on your GPO and select edit expand computer configuration and Local policies click User Rights Assignment and double click Allow log on locally

              Step 5: Add the group of allowed users

              How to step

              Once the properties for Allow log on locally are open, check define these policy settings and add allowed users for restricted lab you must also add the local administrators and also the domain admins groups.

              Step 6: You must require CTRL+ALT+DEL for the policy to work

              How to step

              If you do not require the three finger salute to Microsoft, all log ons are allowed and you will get a notice that the Member of attribute is missing the polcy setting is in Security options and is called Do not require CTRL+ALT+DEL define the setting and disable it.

              Step 7: Link the GPO to the OU and set the filtering

              How to step

              Now that you have your GPO built and applied to the group you created, it needs to be linked to the OU and apply the policy to your domain users. back in Group policy management, right click on the OU where you want the policy to apply and select link an existing GPO select the restricted lab allowed users policy from the list and click OK. in GPM you will see your policy under the OU and if you select the policy entry and select the scope tab you will see that the policy is linked to your OU but it is not enforced. right clickon the link and select enforced Then, under Security filtering, add domain users

              Now you have your policy that enforces that only one group is allowed to log on locally to computers that are contained in the OU you created.add your allowed users to the security group you created and add the computers to the organizational unit. any user not in the group will be restrict3ed from logging on to the computer. This policy can be circumvented by local administrators by making someone who is not a member of the group a local administrator. and of course, domain admins have access. Be very careful where and to whom you apply this policy as one could theoretically make an entire domain inaccessible.

              Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
              Previous ArticleHow to Reset 120 Days RDS Grace Period
              Next Article How to delete files older than X days automatically on Windows 10 and 11
              Cornel Caba
              • Website

              Related Posts

              Schedule a job on Aruba Switch

              July 5, 2023

              How to decrypt and verify text or files with GPG Services

              June 28, 2023

              Windows Server 2019/ Product Key Free

              June 19, 2023

              Sysprep Windows 10 and 11 Machine: Step by Step Guide

              June 19, 2023
              Add A Comment

              Leave A Reply Cancel Reply

              Editors Picks

              Shrinking VMDK Virtual Disk Size on VMWare ESXi

              August 11, 2022

              Oculus Quest X Headset: Discover a Shining New Star

              January 5, 2021

              iPhone Pro 13 Rumored to Feature 1 TB of Storage

              January 5, 2021

              Fujifilm’s 102-Megapixel Camera is the Size of a Typical DSLR

              January 5, 2021
              Top Reviews
              9.1

              Review: Mi 10 Mobile with Qualcomm Snapdragon 870 Mobile Platform

              By Cornel Caba
              8.9

              Comparison of Mobile Phone Providers: 4G Connectivity & Speed

              By Cornel Caba
              8.9

              Which LED Lights for Nail Salon Safe? Comparison of Major Brands

              By Cornel Caba
              Advertisement
              © 2023 sistemITec. Designed by Cornel Caba.
              • sistemITec.com
              • cornelcaba.com

              Type above and press Enter to search. Press Esc to cancel.