Tech Support > Microsoft Windows > Windows Server > Is there a way of limiting access to a certain machine to specific users?
Is there a way of limiting access to a certain machine to specific users?
Posted by Sean on March 28th, 2007


Hi,

We have a computer that does a specific task, we would like to make it so
that only a specific group of people can utilise this machine. This group of
users will change regularly so ease of administration of this group is key.

The machine is Windows XP Pro and we have a Windows 2K Domain and utilise AD
and GP extensively.

Cheers for any help.

Sean


Posted by Dan Simpson - P1 on March 28th, 2007


Hi Sean,

I am presuming the machine is joined to the 2k domain.

Just create a new group in in AD (ensure it is a security group), and
add the current users you want to access the machine.

On the machine itself, R Click My Comuter - select Manage.

In users and groups, select groups.

Remove all instances of all user groups except administrator. Add
into the admin group -- domain admins,

Go into the users group and add in your newly created AD security
group.

Now only admins and members of the security group will be able to log
on.


Posted by Sean on March 28th, 2007


Cheers Dan,

Exactly what I was looking for.



Sean

"Dan Simpson - P1" <DSimpson1@gmail.com> wrote in message
news:1175085738.429700.232010@o5g2000hsb.googlegro ups.com...


Posted by RCCHS network admin on March 28th, 2007


Here's another way to do this, if the users that you want to deny
access to are all in a group. On the local computer that you want to
deny access to:
Go to Administrative Tools, Local Security Policy. Under Local
Policies, User rights assignment, there is a Deny Logon Locally
setting that you configure for that particular group.