In the ActiveDirectory domain, how do I set the user logon time permission?

Source: Internet
Author: User

ActiveDirectoryAllows administrators to create group accounts, allowing administrators to manage system security more effectively. In ActiveDirectoryDomainSet the User Logon Time Limit in? The specific content is as follows.

After you create a domain user account in the ActiveDirectory domain, the user automatically obtains some default permissions. In many cases, users' default permissions may not meet the management requirements of the network administrator. In the domain controller of the ActiveDirectory domain, you can perform very detailed settings on user permissions, such as user logon time, computer logon, and shared resource usage permissions.

The network administrator can set the time to allow users to log on to the domain in the domain controller DC to enhance the management of the ActiveDirectory domain.

To set the User Logon Time in ActiveDirectory, follow these steps:

Step 2: Activate the domain controller as a system administrator and open the "ActiveDirectory user and computer" window. In the left pane, click the Users container, and double-click the user name (such as ithanjiang) in the user list in the right pane to open the "ithanjiang properties" dialog box. Switch to the "Account" tab and click "Logon Time", as shown in 1.

Figure 1 click "Logon Time"

Step 2: Open the "ithanjiang Logon Time" dialog box. In the timeline area, each square in the horizontal axis represents one hour, and each square in the vertical axis represents one day. The blue square indicates the time allowed by the user, and the blank square indicates the time allowed by the user. By default, users are allowed to use it at any time. For example, if you want to enable ithanjiang to be used at to every day ~ At, log on to the domain. First, click the "all" button in the upper-left corner, and then select the "reject Logon" button. Select the time block in the corresponding range with the mouse, and select the "Allow Logon" option. Click OK to complete the settings, as shown in figure 2.

Figure 2 select the "Allow Logon" ticket

TIPS: When you log on to the domain within the allowed time period and continue to use the time period beyond the permitted time period, you can continue to maintain the connection and use it. However, a new connection is not allowed once the user logs out.

Summary:

Setting the user logon time permission in the ActiveDirectory domain facilitates the system administrator to manage the network and improves the network security of the system. More information about ActiveDirectory remains to be explored and learned by the system administrator.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.