Hello Horacio,
GPOs can be applied to users or computers, NOT to security groups, located
in in the OU where the GPO is linked to.
To limit access to a computer you can use the account tab on the user account
properties in AD UC, There you will see a button "Lo on to" where you can
limit the machines where that user can logon to.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!!
http://www.blakjak.demon.co.uk/mul_crss.htm
> Hi all:
>
> I have this issue: in my domain i need restrict the use of one
> computer by
> some domain users. I tried resolve this situation creating a new
> separate
> OU, then create in it a new group wich contatins the user will allowed
> to
> work on the computer, then went to "Computer Configuration,
> Windows Settings, Security Settings, Local Policies, User Rights
> Assignment,
> Allow Logon locally" and i allowed user accounts created with a GPO
> for your
> machine.
> However, any user can login on the computer.
>
> Can you help me with this.
>
> Thanks in advance.
>
> Horacio
>