Jump to content
Forum²

Recommended Posts

Posted
What does "Direct login" mean?

--------------------------------------------------------

Tu peux aussi crire en franais.

Du kannst auch auf Deutsch schreiben.

Puoi scrivere anche in italiano.

--------------------------------------------------------

Posted

Sorry but I still don't understand...

 

You said: "how to DISABLE login to Windows Server"

 

then: "User login to every WS but not to DC"

 

So you want to PERMIT user to login to DC or BLOCK user from login the the other stations?

When you say "LOGIN", you want to permit / block login from local pc (physical access), remote desktop or what else?

--------------------------------------------------------

Tu peux aussi crire en franais.

Du kannst auch auf Deutsch schreiben.

Puoi scrivere anche in italiano.

--------------------------------------------------------

Posted

Windows server has domain controller role. Users are stored in Active Directory. PC client stations are joined to domain. I want to deny access to Windows server - user will physically not be able to login to server.

 

SERVER

-------domain-------

| |

CLIENT_PC1 CLIENT_PC2

 

SERVER is domain controller, clients are joined to domain. Active Directory user will be able to login on computer client_pc1, client_pc2 but the same user will not be able to login on server (neither direcly nor remotely). How to do this?

Posted

Ok, now everything is clear :)

 

Basically Remote Desktop is permitted to Admin's only, so you have nothing to do. To block user from logging in do the following:

 

(on the server you want to block access):

 

start > run > gpedit.msc

Computer > Windows > Security > Local > User Right Assignment

 

Select the policy "ALLOW LOG ON LOCALLY". From there, you can remove what you don't need.

 

You can do the same thing by ADDING the group / user you don't want, on the policy "DENY LOG ON LOCALLY".

 

 

ATTENTION: do not change the policy "ACCESS THIS COMPUTER FROM THE NETWORK", this will prevent any connection to the server (domain, profiles and so on).

 

question: why your users are able to login physically? When you install a server, only admins, server op, and other "service account" are enabled...

--------------------------------------------------------

Tu peux aussi crire en franais.

Du kannst auch auf Deutsch schreiben.

Puoi scrivere anche in italiano.

--------------------------------------------------------

Posted
question: why your users are able to login physically? When you install a server, only admins, server op, and other "service account" are enabled...

Users don't have physicall access to server but it is cleaner and better to block everything I don't want or need.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...