Web Server forum
Back To The Forum Home!Search!Private Messaging System

This is Interesting: Free IT Magazines Now Free shipping to   
Web Server Talk Web Server Talk > Microsoft Windows software support > Windows 2000 General > Local Logon Prevention in W2K / XP




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    Local Logon Prevention in W2K / XP  
Fraser Dickson


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
03-19-04 05:33 PM

Have you tried to enable to the "Always wait for network
at computer startup and logon".

You can access it under Local Computer Policy - Admin
Templates - System - Logon

By default, Windows XP does not wait for the network to
be fully initialized at startup and logon. Existing users
are logged on using cached credentials, which results in
shorter logon times. Group Policy is applied in the
background once the network becomes available.

Regards,
Fraser - MCP


>-----Original Message-----
>Does anyone know of a way of preventing local logon to a
machine? Here is the scenario.
>
>The computers are networked and GPO policies are in
force which prevent access to certain portions of the
computer. However, if the user unplugs the network cable
the system lets them in after a couple of error messages
about roaming profiles. Once the logon procedure is
complete the users can do almost anything they want to
the local machine... remove software change administrator
accounts etc.
>
>I have edited the local policy to "Log off user if
roaming profile fails" as I thought this was the problem
but it is being ignored.
>
>I also tried "Deny logon locally" but then the domain
groups I denied cannot logon interactively whether the
network cable is unplugged or not.
>
>What I want to achieve is to deny local logon to any
user when the network cable is unplugged. So that they
are forced to authenticate through the network and hence
the GPO restrictions will be in place. Can this be done?
>
>Thanx in advance
>.
>





[ Post a follow-up to this message ]



FriedTurkey is offline     Re: Local Logon Prevention in W2K / XP  
FriedTurkey


View Ip Address Report This Message To A Moderator Edit/Delete Message


Click Here to See the Profile for FriedTurkey Click here to Send FriedTurkey a Private Message Find more posts by FriedTurkey Add FriedTurkey to your buddy list
 
01-24-05 08:37 PM

In Local Security Settings, under Security Settings/Local Policies/Security 
Options, find the policy:

 Interactive Logon: Number of previous logons to cache (in case a domain control
ler is not available).

Set this value to 0 to disable policy cacheing.

quote:
Originally posted by Fraser Dickson Have you tried to enable to the "Always wait for network at computer startup and logon". You can access it under Local Computer Policy - Admin Templates - System - Logon By default, Windows XP does not wait for the network to be fully initialized at startup and logon. Existing users are logged on using cached credentials, which results in shorter logon times. Group Policy is applied in the background once the network becomes available. Regards, Fraser - MCP >-----Original Message----- >Does anyone know of a way of preventing local logon to a machine? Here is the scenario. > >The computers are networked and GPO policies are in force which prevent access to certain portions of the computer. However, if the user unplugs the network cable the system lets them in after a couple of error messages about roaming profiles. Once the logon procedure is complete the users can do almost anything they want to the local machine... remove software change administrator accounts etc. > >I have edited the local policy to "Log off user if roaming profile fails" as I thought this was the problem but it is being ignored. > >I also tried "Deny logon locally" but then the domain groups I denied cannot logon interactively whether the network cable is unplugged or not. > >What I want to achieve is to deny local logon to any user when the network cable is unplugged. So that they are forced to authenticate through the network and hence the GPO restrictions will be in place. Can this be done? > >Thanx in advance >. >




[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 02:34 PM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 

Back To The Top
Home | Usercp | Faq | Register