Hi Yao Lu,
Thank you for posting in Q&A forum.
- May I confirm if your machine joined to domain? If the machine joined to domain, you need to go to the domain controller to set the GPO.
Put the workstations you mentioned into one OU.
Create one GPO and link this GPO to the OU above.
Edit the GPO for the setting "Network access: Restrict clients allowed to make remote calls to SAM".
If the machine did not join any domain, you just need to configure it in local group policy.
- Please check if the registry key has been settled as below on your client:
Registry location HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\RestrictRemoteSam
Registry type REG_SZ
Registry value A string that will contain the SDDL of the security descriptor to be deployed.
Possible values
- Not defined
- Defined, along with the security descriptor for users and groups who are allowed or denied to use SAMRPC to remotely access either the local SAM or Active Directory.
Hope the information above is helpful.
If you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.