Block out user

Is it possible in Windows 2000 to block a user of a domain from using a certain machine. I currently have a 2000 Pro machine on a domain. Currently any domain user (which is over 1000 users) can log onto my machine.

Windows Networking 2246 This topic was started by ,


data/avatar/default/avatar11.webp

132 Posts
Location -
Joined 2000-02-02
Is it possible in Windows 2000 to block a user of a domain from using a certain machine.
 
I currently have a 2000 Pro machine on a domain. Currently any domain user (which is over 1000 users) can log onto my machine. Is there a way for me to not allow users other than myself to use this machine?
 
Thanks
 
Ancker Jade

Participate on our website and join the conversation

You have already an account on our website? Use the link below to login.
Login
Create a new user account. Registration is free and takes only a few seconds.
Register
This topic is archived. New comments cannot be posted and votes cannot be cast.

Responses to this topic


data/avatar/default/avatar19.webp

690 Posts
Location -
Joined 2000-05-21
Go to Programs -> Administrative Tools -> Local Security Policy (if you can't see administrative tools, go to Settings -> Taskbar & Start Menu and enable it).
 
GO to Local Policies -> User Rights Assignment and either add users to "Deny logon locally" or remove them from "Log on locally". Be careful not to remove your own account though (VERY VERY IMPORTANT!!)
 
--
Xiven
 
[This message has been edited by Xiven (edited 13 March 2001).]

data/avatar/default/avatar11.webp

132 Posts
Location -
Joined 2000-02-02
OP
OK thanks...it worked..
 
but i told me colleague that he should also restrict access...and he did just that..he locked himself(including local administrator) out of his machine..
 
what can be done??

data/avatar/default/avatar19.webp

690 Posts
Location -
Joined 2000-05-21
Oh dear, I did warn you AFAIK There's no easy way around it other than to use an emergency repair disk. Hope someone else has a better suggestion.

data/avatar/default/avatar36.webp

1207 Posts
Location -
Joined 2000-03-27
Although he has locked himself and local administrator out, has he locked 'Domain Admins' out?
By default the 'Domain Admins' group gets admin rights on workstations.

data/avatar/default/avatar11.webp

132 Posts
Location -
Joined 2000-02-02
OP
Actually there is a way around it..
 
it's actually pretty neat.
install Windows 2000 Server OR Pro Resource Kit.
(you must also have a win2k box(with admin rights networked to the machine messed up.)
 
from the command prompt where "ntrights" is type
c:\ntrights -m \\computer -u (user or group) -r SeDenyInteractiveLogonRight
 
worked like a charm.....
 
[This message has been edited by ancker (edited 15 March 2001).]

data/avatar/default/avatar19.webp

690 Posts
Location -
Joined 2000-05-21
Nice. I'll have to remember that one :):

data/avatar/default/avatar19.webp

690 Posts
Location -
Joined 2000-05-21
Hmmm.... couldn't find that ntrights thing you were talking about, tried installing every little thing hidden on the 2k server cd - still no joy.

data/avatar/default/avatar11.webp

132 Posts
Location -
Joined 2000-02-02
OP
It's on the Windows 2000 Resource Kit CD..not the windows 2000 CD
 
Ancker