M
Matt
Guest
ok, I have to admit, I'm no expert. But here is what I'm trying to do.
I have a 2003 solitary domain. It has a bunch of users. ok, so far so
good. Well I now have new XPe machines to add to this domain. the users of
the XPe machines are a different class of user than the existing users. I
want XPe users to log only into those machines, and the existing Domain Users
to not be able to long into the new machines at all.
so here is what i thought would work. i created a new OU. Linked a new GPO
to it. inside the OU i have the new XPe test units active directory computer
and a test user to log into this machine. both the computer and user are
member of a group called Sales Staff. and only that group.
outside of the OU, where all the original users exist, i have another test
user who belongs to Domain\Domain Users.
now the GPO. I've drilled down to Computer Config -> Windows Settings ->
Security Settings -> Local Policies -> User Rights Assignment. here i have
tried to both change the 'Deny Logon Locally' to 'Domain\Domain Users' and
also try setting 'Log On Locally' to 'Domain\Sales Staff'.
so far, I'm not getting any result. my test user that is part of Domain
Users can still log in. I know the GPO is getting applied as other changes i
make seem to work just fine.
Anyone have any great ideas? thanks so much for your time.
Matt
I have a 2003 solitary domain. It has a bunch of users. ok, so far so
good. Well I now have new XPe machines to add to this domain. the users of
the XPe machines are a different class of user than the existing users. I
want XPe users to log only into those machines, and the existing Domain Users
to not be able to long into the new machines at all.
so here is what i thought would work. i created a new OU. Linked a new GPO
to it. inside the OU i have the new XPe test units active directory computer
and a test user to log into this machine. both the computer and user are
member of a group called Sales Staff. and only that group.
outside of the OU, where all the original users exist, i have another test
user who belongs to Domain\Domain Users.
now the GPO. I've drilled down to Computer Config -> Windows Settings ->
Security Settings -> Local Policies -> User Rights Assignment. here i have
tried to both change the 'Deny Logon Locally' to 'Domain\Domain Users' and
also try setting 'Log On Locally' to 'Domain\Sales Staff'.
so far, I'm not getting any result. my test user that is part of Domain
Users can still log in. I know the GPO is getting applied as other changes i
make seem to work just fine.
Anyone have any great ideas? thanks so much for your time.
Matt