baileyk9
2007-10-01 14:13:01 UTC
Is there a better way to do this:
We limit a set of user accounts to logging on to specific workstations by
using the "Logon Workstations" property of each of those user accounts.
Seeking advice on a more manageable solution - using GPOs, and/or
restructuring our OU's for these resources if necessary.
scenario: 15-20 user accounts, and 50-60 workstations that they can log on
to (10-20 per user account, but it would be OK to give them access to all
50-60 workstations, since they are at different locations and will never be
able to log on to those outside their site anyway). Managing this is a mess
as the list of PCs they can log on to changes (PCs are added to or removed
from service).
Seems like putting all the restricted users in one OU, with the restricted
computers that they can access in another OU, and limit their access via
group policy? I understand GPOs, but don't know what GPO to use/create or if
this is the best approach.
Any ideas greatly appreciated!!
<>
We limit a set of user accounts to logging on to specific workstations by
using the "Logon Workstations" property of each of those user accounts.
Seeking advice on a more manageable solution - using GPOs, and/or
restructuring our OU's for these resources if necessary.
scenario: 15-20 user accounts, and 50-60 workstations that they can log on
to (10-20 per user account, but it would be OK to give them access to all
50-60 workstations, since they are at different locations and will never be
able to log on to those outside their site anyway). Managing this is a mess
as the list of PCs they can log on to changes (PCs are added to or removed
from service).
Seems like putting all the restricted users in one OU, with the restricted
computers that they can access in another OU, and limit their access via
group policy? I understand GPOs, but don't know what GPO to use/create or if
this is the best approach.
Any ideas greatly appreciated!!
<>