"Domain Users" in local users group isn't appropriate for us. Can I safely remove it?


i understand "domain users" gets added local users group when machine joins ad.  isn't appropriate us, domain users group includes ids shouldn't log in machines.  can remove via gpo, i'd rather not happen in first place.  can done safely?

hello,

since want allow specific users logon on specific computers, can consider using these 2 parameters in group policies:

  • allow logon locally: http://technet.microsoft.com/en-us/library/cc756809%28v=ws.10%29.aspx
  • deny logon locally: http://technet.microsoft.com/en-us/library/cc728210%28v=ws.10%29.aspx

this posting provided "as is" no warranties or guarantees , , confers no rights.   

microsoft student partner 2010 / 2011
microsoft certified professional
microsoft certified systems administrator: security
microsoft certified systems engineer: security
microsoft certified technology specialist: windows server 2008 active directory, configuration
microsoft certified technology specialist: windows server 2008 network infrastructure, configuration
microsoft certified technology specialist: windows server 2008 applications infrastructure, configuration
microsoft certified technology specialist: windows 7, configuring
microsoft certified technology specialist: designing , providing volume licensing solutions large organizations
microsoft certified professional: enterprise administrator
microsoft certified professional: server administrator
microsoft certified trainer



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS