Denying logon to users - Auttomated and error-free ways
i have several ad accounts "generic" names (insted "mark", "david" or "anna" using "librarian", "consultant", "engineer" , on)
the accounts must exist no logon rights, no local logon, no vpn, existing user, "placeholder"
the procedure have error-free such possible
approach #1:
all "generic" users belonging global group , using gpo, global group wil have "deny logon locally" privilege. approach have disavantage of being subject errors, if reason, "generic" user has been (accidentaly) removed form group
there other approaches?
using "logon hours" ad attribute, effectivelly denying logon hours? (it´s hard automate in scripts, think)
using "log on to" ad attribute, far know effective if client machine using netbios logon, so, maybe not best option
any other idea?
goal here configure google synch ad , i´m researching if "contact" ad object used
hi,
i agree gpo first option try out, note: test in lab or poc env.
or can use tool admodify set attributes desire.
https://admodify.codeplex.com/
regards, jim mscs - mcp disclaimer: posting provided no warranties or guarantees , , confers no rights. when see answers , helpful posts, please click vote helpful, propose answer, and/or mark answer
Windows Server > Directory Services
Comments
Post a Comment