March 13, 2005
Restricting who can log on
By default, anyone in the Kerberos Realm can log on interactively at any machine in the active directory. To change this behavior, set the policy:
Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> User Rights Assignment -> Allow log on locally
To include the list of users/groups you wish to be able to log on at the computer console.
Posted by djc6 at March 13, 2005 02:20 PM
TrackBack URL for this entry: