Home > Ask the Enterprise Desktop Experts > Questions & Answers > Group Policy Objects for Microsoft network security
Ask The Enterprise Desktop Expert: Questions & Answers
EMAIL THIS

Group Policy Objects for Microsoft network security

Wes Noonan EXPERT RESPONSE FROM: Wes Noonan

Pose a Question
Other Enterprise Desktop Categories
Meet all Enterprise Desktop Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 02 August 2007
I am trying to take a single machine on my Microsoft Windows network and give only specific users access to it for the sake of network security. It is impractical to assign every user specific machines to log onto and would be easier to only allow certain users access to this machine. How would I accomplish this?

>
EXPERT RESPONSE
Unfortunately, there is not an easy way to improve Microsoft network security this way. Based on your question, I'm guessing you discovered the "Log On To" button in the users properties and then realized you would need to make changes on every user account for every computer you wanted them to be able to log in with. Not a pleasant thought.

Another option is to try using Group Policy Objects (GPOs). Create an organizational unit (OU) for the computer in question, and then add the computer to said OU. Create a group in your Windows network for the users you want to have the ability to log into this computer and add the appropriate users to it. Do not add it to the OU.

Right click on the OU and bring up the properties. Select the Group tab, then create a new Group Policy Object by clicking on the New button. Name the GPO accordingly and click Edit.

Expand Computer Configuration, Windows Settings, Security Settings, Local Policies and click on User Rights Assignments. This will bring up the user rights in the right pane.

You are going to want to edit the following policies:

  • Access this computer from the network
  • Allow Logon through Terminal Services
  • Log on locally (may be named Allow log on locally)

You can do this by double clicking on the policy. Check the box "Define these policy settings" and click Add User or Group to add the group you previously defined. Keep in mind that you must grant administrators the right to log on locally (and, in fact, I recommend granting them all of the rights listed).


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts