Tuesday, April 21, 2009

Deny an account to log on interactively from ANY domain workstation

Open Group Policy Management Console (gpmc.msc)
Right-click on "Default Domain Policy" for the domain and click Edit
Open Computer Configuration > Windows Settings > Security Settings > Local Policies >
User Rights Assignment
Add the specified account to these policies:
- Deny log on locally
- Deny log on through Terminal Services

No comments:

Post a Comment