Jump to content

Server 2003 - how do I keep users from logging on?


Recommended Posts

I'm still testing my 2003 setup, and I noticed that non-admins can log on. How can I stop that from happening? The "Administrators" group only contains the local administrator, plus the domain admins (which I control). As far as I can tell, all of the other group are clear, save for those odd entries that I probably shouldn't touch (like "NT Authority" in the users group).

Is there a way I can make it so that ONLY administrators can log on? That's because some of my offices are small, and the file server is in an open area amongst the desks and cubes (although the main office itself is secured). It sucks, but I have no choice there. So what can I do to make sure the server is locked down?

FYI -- after the installation is done, "Domain Users" is listed in the "Users" group. But I removed that...

Link to comment
Share on other sites


Click Start/Run and type 'gpedit.msc'

Under Local Computer Policy, explore to Computer Configuration - Windows Settings - Security Settings - Local Policies - User Rights Assignment - Deny Logon Locally and add 'Domain Users'

You might also consider placing users in a new group (DENY LOGON) and then add that group to Deny Logon Locally to make clearer to the other (and future) Doman Admins so there is no confusion ;)

DO consider the implication of putting users in this Deny Logon Locally group and ensure that the Domain Admins are not also members of Domain Users ('deny' usually overides 'allow').

Link to comment
Share on other sites

You could also do the same thing on a stand alone server that is not part of a domain.

Open the Local Security Policy from the Administrator's Tools menu

Open or expand Local Policies

Open or expand User Rights Assignment

Locate the setting for Deny log on locally

Add the user(s) or group(s) you want and save.

Good luck.

tguy

Link to comment
Share on other sites

  • 1 month later...

andrewpayne:

I finally got around to trying this, and it worked great. And once I checked out those security policies, I realized that I don't even need to do the "deny". I went into "Allow log on locally" and removed every entry except for administrators. I then tried logging on as admins and non-admins, and it worked perfectly.

Thanks! :thumbup

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...