Active Directory: Authentication

Gonzalo Secco 21 Reputation points
2020-09-11T13:44:06.28+00:00

I have a question:
In my organization we have a requirement for users of a certain OU. Those users should only be able to authenticate to the domain but not access its resources.
You only need to use active directory authentication to access certain web applications.

I have not found how to limit access, do you have any ideas?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

Answer accepted by question author
  1. Anonymous
    2020-09-15T01:14:07.627+00:00

    Hi,@Gonzalo Secco

    As Thameur said above if the requirement is that these users cannot log in to domain computers. We can just deploy a group policy :Deny logon locally and add the user to the deny scope .
    For example:
    Create a gpo and link it to the OU containing computers the users can't log to.
    Edit the GPO as following:
    24732-9151.jpg

    Please let us know if you would like further assistance.
    Best Regards,

    0 comments No comments

4 additional answers

Sort by: Most helpful
  1. Thameur-BOURBITA 36,491 Reputation points Moderator
    2020-09-13T22:03:37.98+00:00

    Hi,

    By default when you create a simple domain user, he will have only the read right on all active directory object , so he is unable to modify any object in domain.

    So, you don't need perform any action to limit user access. because he don't have any access by default.

    Please don't forget to mark this reply as answer if help you to fix your issue

    0 comments No comments

  2. Anonymous
    2020-09-14T00:46:09.333+00:00

    Hi,

    Based on my research, if you want to limit access to domain objects, you can consider use the delegation control on the domain or a OU:
    Add the users to a security group , and assign the permission what you want.
    24259-9142.jpg
    24285-9143.jpg
    If you want to limit access to the resource in from file servers or other resource, i'm afraid you have to limit the acce from the resource side (the share permission and the NTFS permission)

    Best Regards,

    0 comments No comments

  3. Gonzalo Secco 21 Reputation points
    2020-09-14T14:50:45.96+00:00

    One of the requirements is that these users cannot log in to domain computers. But they must be able to authenticate to the domain.
    The "Log On To" option is not functional for me.

    0 comments No comments

  4. Thameur-BOURBITA 36,491 Reputation points Moderator
    2020-09-14T20:18:41.063+00:00

    Hi,

    You can use set a GPO to be applied on domain computers to deny logon locally this user:

    deny-log-on-locally

    Please don't forget to mark this reply as answer if it help you to fix your issue

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.