blondebier
Programmer
Hi Guys,
We have recently created a new domain using Windows Server 2008.
As part of this setup our infrastructure requires some application accounts to be configured in AD for running windows services, web services and other programs we have created.
We don't want these accounts to be able to log on to the domain.
I thought the "Deny log on locally" policy in group policy management would prevent this.
I implemented this by grouping all the application accounts in their own OU (Organisational unit) in AD.
I then created a GPO in this OU and set "Deny log on locally" to this group.
I thought that would work, but it hasn't done the job.
Does the "Deny log on locally" policy only apply to computers and not users?
Any ideas?
Cheers,
Blondebier
We have recently created a new domain using Windows Server 2008.
As part of this setup our infrastructure requires some application accounts to be configured in AD for running windows services, web services and other programs we have created.
We don't want these accounts to be able to log on to the domain.
I thought the "Deny log on locally" policy in group policy management would prevent this.
I implemented this by grouping all the application accounts in their own OU (Organisational unit) in AD.
I then created a GPO in this OU and set "Deny log on locally" to this group.
I thought that would work, but it hasn't done the job.
Does the "Deny log on locally" policy only apply to computers and not users?
Any ideas?
Cheers,
Blondebier