Answer the question
In order to leave comments, you need to log in
How to restrict users from logging on to computers on a single domain network?
It was:
The situation is as follows (everything is organized on virtual machines):
We have the Main-First server (and the Main-Double server duplicating it) and we have a certain number of subdomain controllers on this server;
Everything is organized through Active Directory. The controllers are running Windows Server 2008 R2.
It is necessary:
1. To organize the possibility for administrators to create subdomain accounts for users/computers in subdomain controllers subject to them;
2. Deny the ability for users to log in from one subdomain to others, i.e. having the moskva.kontora.ru subdomain and the user Vasya Pupkin ([email protected]) in it, prohibit him and others like him from logging into computers (if he is physically present there) of the saratov.kontora.ru subdomain
3. Make it so that, if necessary, it is possible to manually allow such an entrance by the Administrator of the forest controller;
Answer the question
In order to leave comments, you need to log in
I'm not sure (nowhere to look - I have single-domain forests everywhere)
in the GPO Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Local Logon
Specifies users and groups that can log into the system. By default, there are local groups.
The composition of local groups can be controlled through Group Policy Preferences (on XP, an extension is required for support - on Vista and higher there is support)
If only users of this domain will be in local PC users in each domain, others will not be able to enter.
For users from other domains who need to be given access - you can add some additional group to local users in advance - you need to give access to enter the neighboring domain - added to the group, you need to pick it up - deleted it.
By default, forest administrators will always have access everywhere - and it's best not to touch this.
PS In general, if you are at the design stage - think about it - do you really need a multi-domain architecture?
Colleague, well, like the standard settings for rights, what's the difficulty? Sounds like it works by default.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question