Denying logon to users - Auttomated and error-free ways


i have several ad accounts "generic" names (insted "mark", "david" or "anna" using "librarian", "consultant", "engineer" , on)

the accounts must exist no logon rights, no local logon, no vpn, existing user, "placeholder"

the procedure have error-free such possible

approach #1:

all "generic" users belonging global group , using gpo, global group wil have "deny logon locally" privilege. approach have disavantage of being subject errors, if reason, "generic" user has been (accidentaly) removed form group

there other approaches?

using "logon hours" ad attribute, effectivelly denying logon hours? (it´s hard automate in scripts, think)

using "log on to"  ad attribute, far know effective if client machine using netbios logon, so, maybe not best option

any other idea?

goal here configure google synch ad , i´m researching if "contact" ad object used

hi,

i agree gpo first option try out, note: test in lab or poc env.

or can use tool admodify set attributes desire.

https://admodify.codeplex.com/


regards, jim mscs - mcp disclaimer: posting provided no warranties or guarantees , , confers no rights. when see answers , helpful posts, please click vote helpful, propose answer, and/or mark answer



Windows Server  >  Directory Services



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file