Group PolicySystem Administrators are crucial. The following is a small skill in group policy. The specific content is as follows.
Microsoft's default Active Directory environment is very insecure. Many network administrators configure the network according to the security rules again. Note thatDomainAll accounts can log on to DCDomain ControllerWithout a doubt, this will bring great security risks to our enterprise information. To ensure the security of the entire network system and prevent the leakage of confidential files, we must use a group policy to specify the computers on which Domain Users are allowed to log on. What should we do? Here is the detailed method:
Setting method:
Assume that we only allow domain users to log on to their computers, rather than other computers. Of course, this method is not flexible, but it is the most effective.
In "start running", enter dsa. msc open ADUC Active Directory user and computer), select the target user to operate on, switch to the "Account" tab in the User Properties window, and select "log on ".
In the "LogonWorkstaions" window, select "all the following computers" in the "user logon to" area, and add the computer names used by this domain account to the computer list. For example
Suggestion:
Considering that many enterprise office platforms such as OA and wiki support ldap authentication, many IT administrators set up domain accounts to log on to these platforms to save management costs, in this case, we strongly recommend that you add the computer name of the DC Domain Controller to the computer list so that you cannot log on to other office platforms.
Of course, some may ask, does this reduce security? In fact, you can rest assured that in the security policy of the domain controller, the local logon is denied for common domain users, so these common users cannot log on to the DC Domain Controller.
Using group policies to restrict domain users to log on to their computers only, which undoubtedly maintains the network security of the system. I hope this article will be helpful to readers.